## Updated at UTC 2026-09-21T19:48:14.638761

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-93742 9.9 1.88% 3 0 2026-09-21T19:17:17.273000 A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected b
CVE-2026-86553 8.8 0.45% 4 1 2026-09-21T19:17:14.327000 SmartLife app dynamically generates fresh SmartLife application authentication p
CVE-2026-79920 9.9 0.00% 2 0 2026-09-21T19:17:11.323000 Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any
CVE-2026-68928 8.6 0.13% 1 0 2026-09-21T19:17:09.157000 Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7,
CVE-2026-94301 9.8 0.00% 2 0 2026-09-21T18:10:30.343000 The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - accept
CVE-2026-83621 8.1 0.00% 2 0 2026-09-21T17:19:08.590000 ntopng is a web-based network traffic monitoring application. Prior to 6.7.26071
CVE-2026-77560 8.1 0.00% 2 0 2026-09-21T17:18:52.770000 Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth
CVE-2026-93740 10.0 0.61% 2 0 2026-09-21T16:17:28.070000 A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected i
CVE-2026-82187 9.8 0.14% 2 0 2026-09-21T15:33:02 The Web to Print Online Designer WordPress plugin before 2.15.0 does not validat
CVE-2026-93993 8.8 0.60% 2 0 2026-09-21T15:17:37.247000 Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the
CVE-2026-92701 9.1 0.22% 2 1 2026-09-21T15:17:35.313000 Cocos AI is a confidential computing system for running AI workloads inside trus
CVE-2026-90817 9.8 0.57% 5 2 2026-09-21T15:17:34.560000 An unauthenticated Remote Code Execution vulnerability was found in the survey p
CVE-2026-87839 7.5 0.21% 2 0 2026-09-21T13:34:57.127000 The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, a
CVE-2026-87067 8.5 0.28% 2 0 2026-09-21T13:34:57.127000 The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which c
CVE-2026-85017 7.5 0.24% 2 0 2026-09-21T13:34:57.127000 The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not per
CVE-2026-82842 8.1 0.22% 4 0 2026-09-21T13:34:57.127000 The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the confi
CVE-2026-85574 8.0 0.19% 1 0 2026-09-21T13:34:57.127000 The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any au
CVE-2026-86814 8.1 0.23% 2 0 2026-09-21T13:34:57.127000 The UsersWP WordPress plugin before 1.5.10 does not verify that a social login
CVE-2026-87909 7.5 0.53% 3 0 2026-09-21T13:33:33.387000 The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-94015 7.3 0.26% 1 0 2026-09-21T13:33:33.387000 A vulnerability was identified in SourceCodester Drug Recommendation System 1.0.
CVE-2026-94129 8.8 0.12% 4 1 2026-09-21T13:33:33.387000 A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vul
CVE-2026-94096 9.9 1.65% 4 0 2026-09-21T13:33:33.387000 A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by thi
CVE-2026-84434 9.8 0.70% 3 1 template 2026-09-21T13:33:33.387000 The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in
CVE-2026-93962 8.3 0.53% 2 0 2026-09-21T13:33:33.387000 A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. T
CVE-2026-93741 10.0 0.64% 4 0 2026-09-21T13:33:33.387000 A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affec
CVE-2026-1255 7.5 0.29% 1 0 2026-09-21T13:33:33.387000 The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Expos
CVE-2026-4327 8.8 0.70% 1 0 2026-09-21T13:33:33.387000 The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution i
CVE-2026-85658 8.1 0.36% 1 0 2026-09-21T13:33:33.387000 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
CVE-2026-92229 9.1 0.40% 2 1 2026-09-21T13:33:33.387000 The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plug
CVE-2026-93739 9.9 0.49% 1 0 2026-09-21T13:33:33.387000 A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impac
CVE-2026-93031 8.8 0.58% 1 0 2026-09-21T13:33:33.387000 The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-B
CVE-2026-10747 10.0 0.52% 4 0 2026-09-21T13:17:07.147000 IBM MQ Appliance could allow a remote attacker to cause a denial of service or p
CVE-2026-94146 8.8 0.12% 2 0 2026-09-21T09:31:09 A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue aff
CVE-2026-94142 8.8 0.13% 4 0 2026-09-21T06:30:32 A security vulnerability has been detected in BioStar Temperature Monitor Utilit
CVE-2026-94128 8.8 0.12% 4 1 2026-09-21T03:30:29 A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500
CVE-2026-94099 9.9 1.69% 4 0 2026-09-21T03:30:27 A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This
CVE-2026-94101 9.9 0.45% 4 0 2026-09-21T03:30:27 A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246
CVE-2026-94100 9.9 0.46% 4 0 2026-09-21T03:30:23 A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted i
CVE-2026-94098 9.1 2.38% 2 0 2026-09-21T03:30:22 A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulne
CVE-2026-94097 10.0 1.99% 2 0 2026-09-21T00:30:33 A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affec
CVE-2026-94095 9.9 1.67% 2 1 2026-09-21T00:30:33 A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected b
CVE-2026-94089 10.0 0.98% 2 0 2026-09-20T21:31:45 A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects th
CVE-2026-94036 8.8 0.47% 2 1 2026-09-20T18:31:25 A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0
CVE-2026-87068 6.6 0.21% 2 0 2026-09-20T15:31:27 The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role v
CVE-2026-92965 3.7 0.15% 2 0 2026-09-20T14:17:00.423000 The TikTok WordPress plugin before 1.4.2 does not check that a request is author
CVE-2026-94106 8.8 1.66% 2 0 2026-09-20T12:30:37 getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out
CVE-2026-94107 8.1 0.42% 2 0 2026-09-20T12:30:35 NivoCart through 2.4.0 contains a predictable password reset token vulnerability
CVE-2026-94104 8.8 0.67% 2 0 2026-09-20T12:30:28 NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the Fi
CVE-2026-94003 10.0 0.61% 4 0 2026-09-20T12:30:28 A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the funct
CVE-2026-94109 8.8 0.92% 2 0 2026-09-20T12:17:06.620000 openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerabili
CVE-2026-93958 9.1 2.17% 4 1 2026-09-20T03:30:31 A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affec
CVE-2026-94083 9.4 0.40% 8 0 2026-09-20T03:30:29 Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free,
CVE-2026-94084 9.4 0.40% 8 0 2026-09-20T02:16:53.717000 Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transacti
CVE-2026-78030 9.8 0.73% 4 0 2026-09-20T01:16:30.017000 DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_ty
CVE-2026-94054 7.0 0.27% 2 0 2026-09-20T00:30:33 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled pro
CVE-2026-94056 7.5 0.24% 3 0 2026-09-20T00:30:32 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled pro
CVE-2026-93992 8.1 0.80% 2 0 2026-09-20T00:30:32 Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive e
CVE-2026-93990 7.5 0.35% 2 0 2026-09-20T00:30:31 Expat through 2.8.4 fails to validate low surrogates following high surrogates i
CVE-2026-93991 7.7 0.33% 2 0 2026-09-19T23:17:10.360000 Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vuln
CVE-2026-88824 8.8 0.28% 1 0 2026-09-19T15:32:24 The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on
CVE-2026-92404 7.5 0.26% 1 0 2026-09-19T15:31:26 The MgoSync WordPress plugin before 2.1.7 does not have authorization controls
CVE-2026-88926 8.6 0.26% 1 0 2026-09-19T15:31:25 The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4
CVE-2026-85680 8.8 0.28% 1 0 2026-09-19T15:31:24 The Ultimate Member WordPress plugin before 2.13.1 does not escape a value deri
CVE-2026-84750 6.5 0.27% 1 0 2026-09-19T15:31:24 The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not vali
CVE-2026-86591 9.8 0.37% 2 0 2026-09-19T15:31:23 The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation
CVE-2026-84082 9.8 0.40% 2 0 2026-09-19T15:17:05.647000 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-84078 9.9 0.28% 3 0 2026-09-19T15:17:05.430000 IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vuln
CVE-2026-84070 8.9 0.32% 3 0 2026-09-19T15:17:04.867000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84064 9.9 0.37% 2 0 2026-09-19T15:17:04.757000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-82967 9.8 0.43% 3 0 2026-09-19T15:17:04.430000 IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that
CVE-2026-82892 8.1 0.39% 2 0 2026-09-19T15:17:04.107000 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-82887 8.8 0.41% 2 0 2026-09-19T15:17:03.990000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-80441 9.8 0.38% 2 0 2026-09-19T15:17:02.430000 IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-ord
CVE-2026-61817 8.5 0.58% 2 0 2026-09-19T15:16:59.910000 pg_partman is a PostgreSQL extension that manages partitioned tables by time or
CVE-2026-17619 8.6 0.30% 2 0 2026-09-19T15:16:58.713000 IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send sp
CVE-2026-11726 8.1 0.46% 2 0 2026-09-19T15:16:57.777000 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac
CVE-2026-84241 8.1 0.30% 2 0 2026-09-19T14:17:00.260000 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-84239 7.6 0.41% 3 0 2026-09-19T14:17:00.143000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84108 8.1 0.40% 2 0 2026-09-19T14:17:00.037000 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-84085 8.1 0.32% 1 0 2026-09-19T14:16:59.587000 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-93985 9.9 0.48% 2 0 2026-09-19T12:32:19 OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerabi
CVE-2026-53266 8.8 0.28% 8 1 2026-09-19T04:17:53.580000 In the Linux kernel, the following vulnerability has been resolved: netfilter:
CVE-2026-92807 8.8 0.25% 2 0 2026-09-19T03:32:15 The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitra
CVE-2026-89274 9.1 0.38% 2 2 2026-09-19T03:32:09 The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Ex
CVE-2026-93923 8.8 0.41% 1 0 2026-09-19T00:32:50 SiYuan through 3.8.4 fails to escape heading style attributes when rendering out
CVE-2026-93922 8.8 0.54% 1 0 2026-09-19T00:16:57.913000 SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker
CVE-2026-75885 9.3 0.41% 2 0 2026-09-18T22:17:10.313000 A flaw was found in the OpenShift console. Unauthenticated access to the `/api/d
CVE-2026-93738 9.9 0.50% 1 0 2026-09-18T21:32:44 A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects th
CVE-2026-88097 8.1 0.22% 1 0 2026-09-18T21:32:43 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke
CVE-2026-93868 8.1 0.61% 1 0 2026-09-18T21:32:41 Cotonti through 1.0.0 derives password recovery validation tokens from md5(micro
CVE-2026-84077 8.1 0.19% 2 0 2026-09-18T21:32:40 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-93839 9.8 0.60% 1 0 2026-09-18T21:32:40 LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /p
CVE-2026-84089 7.8 0.11% 2 0 2026-09-18T21:32:39 IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated
CVE-2026-84075 9.9 0.35% 3 0 2026-09-18T21:32:39 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-84076 7.6 0.31% 2 0 2026-09-18T21:32:39 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84084 8.8 0.18% 1 0 2026-09-18T21:32:39 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-84031 9.0 0.33% 3 0 2026-09-18T21:32:38 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84074 8.9 0.32% 2 0 2026-09-18T21:32:38 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84083 7.8 0.11% 2 0 2026-09-18T21:32:38 IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation vi
CVE-2026-84105 7.7 0.35% 1 0 2026-09-18T21:32:38 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84081 8.1 0.20% 3 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass securi
CVE-2026-82896 7.6 0.36% 2 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84073 9.1 0.26% 2 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84034 8.8 0.25% 2 0 2026-09-18T21:32:37 IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulne
CVE-2026-82885 8.8 0.28% 2 0 2026-09-18T21:32:36 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-82832 9.6 0.38% 2 0 2026-09-18T21:32:36 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-82893 7.8 0.11% 2 0 2026-09-18T21:32:36 IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated
CVE-2026-75878 9.1 0.48% 2 0 2026-09-18T21:32:35 IBM Sterling File Gateway could allow a remote attacker to bypass authentication
CVE-2026-81656 8.8 0.29% 2 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability
CVE-2026-80442 9.9 0.63% 2 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command i
CVE-2026-82340 9.8 0.51% 2 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure dese
CVE-2026-11716 7.5 0.45% 2 0 2026-09-18T21:32:28 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac
CVE-2026-11727 8.1 0.61% 2 0 2026-09-18T21:32:28 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remo
CVE-2025-39682 7.1 1.20% 8 2 2026-09-18T21:31:33 In the Linux kernel, the following vulnerability has been resolved: tls: fix ha
CVE-2026-84106 8.9 0.32% 2 0 2026-09-18T21:18:44.520000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-71418 7.5 0.35% 1 0 2026-09-18T21:18:08.590000 Suricata is a network Intrusion Detection System, Intrusion Prevention System an
CVE-2026-61781 9.9 0.57% 2 0 2026-09-18T21:17:02.257000 pg_partman is a PostgreSQL extension that manages partitioned tables by time or
CVE-2026-92708 7.5 0.34% 1 0 2026-09-18T20:17:30.150000 Svelte devalue is a JavaScript library that serializes values into strings when
CVE-2026-81933 8.8 0.32% 2 0 2026-09-18T20:17:24.250000 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability
CVE-2026-81657 9.8 0.58% 2 0 2026-09-18T20:17:23.997000 IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker
CVE-2026-81626 8.6 0.27% 2 0 2026-09-18T20:17:23.723000 IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability
CVE-2026-81179 8.1 0.26% 2 0 2026-09-18T20:17:23.470000 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58,
CVE-2026-61714 7.8 0.14% 2 0 2026-09-18T20:17:18.270000 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. Fr
CVE-2026-58264 9.8 0.59% 2 0 2026-09-18T20:17:18.107000 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. Fr
CVE-2026-11725 8.8 0.40% 2 0 2026-09-18T20:17:03.167000 IBM MQ could allow an authenticated attacker to cause a denial of service or pot
CVE-2026-89308 0 2.97% 2 0 2026-09-18T19:24:36.593000 An unauthenticated OS command injection vulnerability exists in the ping.php end
CVE-2026-59569 8.1 0.12% 1 0 2026-09-18T19:08:02.707000 An improper input validation vulnerability in Zscaler Client Connector on Androi
CVE-2026-93748 7.5 0.40% 2 0 2026-09-18T18:32:07 http-cache-semantics through 4.2.0 fails to properly validate security-zeroed ca
CVE-2026-93759 8.6 0.24% 1 0 2026-09-18T18:32:04 Mongoid does not neutralize a string-typed query criterion supplied to its query
CVE-2026-93762 9.8 0.34% 2 0 2026-09-18T18:32:01 Mongoid contains an unsafe reflection weakness in the query path used for embedd
CVE-2026-10858 9.9 0.33% 2 0 2026-09-18T18:31:53 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac
CVE-2026-93749 7.5 0.35% 3 0 2026-09-18T18:18:33.480000 source-map-js through 1.2.1 fails to validate the per-section offset line value
CVE-2026-85058 7.5 0.27% 2 0 2026-09-18T18:17:17.447000 Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishW
CVE-2026-81180 8.8 0.36% 2 0 2026-09-18T18:17:15.930000 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61,
CVE-2026-69184 7.5 0.68% 2 0 2026-09-18T18:17:11.477000 c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse
CVE-2026-91127 8.2 0.24% 2 0 2026-09-18T17:19:44 ### Summary Before 2.3.1, the legacy `.doc` renderer emitted document hyperlink
CVE-2026-81916 4.3 0.20% 1 0 2026-09-18T15:31:47 Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry
CVE-2025-39964 3.3 0.79% 9 2 2026-09-18T15:31:06 In the Linux kernel, the following vulnerability has been resolved: crypto: af_
CVE-2026-20283 6.5 0.43% 2 0 2026-09-18T13:28:28.567000 A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authe
CVE-2026-85889 10.0 0.49% 2 0 2026-09-18T00:31:16 Missing authentication for critical function in Azure AI Foundry allows an unaut
CVE-2026-90426 None 0.20% 1 0 2026-09-17T18:33:37 In the Linux kernel, the following vulnerability has been resolved: iommu/tegra
CVE-2026-58704 8.8 0.21% 2 0 2026-09-17T04:17:54.930000 In Cellular Modem, there is a possible permission bypass due to a logic error in
CVE-2026-20306 9.1 1.37% 1 0 2026-09-17T04:17:40.777000 A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenti
CVE-2026-20305 9.1 1.37% 1 0 2026-09-17T04:17:40.540000 A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an
CVE-2026-76460 10.0 0.78% 5 1 2026-09-16T21:33:00 A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an
CVE-2026-20284 9.1 0.39% 2 0 2026-09-16T21:32:50 A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, r
CVE-2026-20282 4.9 0.56% 2 0 2026-09-16T21:32:50 A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ob
CVE-2026-27561 7.2 2.23% 2 0 2026-09-16T19:17:13.633000 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-27560 7.2 2.23% 2 0 2026-09-16T19:17:13.420000 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-92397 9.1 2.30% 2 0 2026-09-16T18:32:09 A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected
CVE-2026-92398 9.1 2.47% 2 0 2026-09-16T18:32:09 A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by th
CVE-2026-91843 9.8 0.50% 2 1 2026-09-16T15:31:14 A stack overflow during the unauthenticated login process may allow an attacker
CVE-2026-27562 7.2 2.23% 2 0 2026-09-16T09:30:34 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-77179 None 0.16% 1 1 2026-09-16T00:32:25 On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows
CVE-2026-76698 6.5 4.11% 2 0 2026-09-15T21:31:36 A command injection vulnerability exists in the web-based management interface o
CVE-2026-90703 9.1 2.80% 2 0 2026-09-15T18:19:38.113000 A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element i
CVE-2026-89267 4.3 0.19% 1 0 2026-09-15T17:17:36.800000 starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fi
CVE-2026-90439 6.5 0.26% 2 0 2026-09-15T15:32:20 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module
CVE-2026-90847 9.1 2.18% 2 0 2026-09-15T03:30:30 A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element i
CVE-2026-76461 9.8 2.01% 2 4 2026-09-14T21:32:49 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure
CVE-2026-81000 7.8 0.16% 1 2 2026-09-14T15:33:28 In the Linux kernel, the following vulnerability has been resolved: net: tun: b
CVE-2026-25687 8.1 0.23% 1 0 2026-09-14T15:32:56 A race condition in the ZPA tunnel handler of affected versions of Zscaler Clien
CVE-2026-89496 None 0.18% 1 0 2026-09-14T15:32:27 In the Linux kernel, the following vulnerability has been resolved: ocfs2: alwa
CVE-2026-80968 None 0.21% 1 0 2026-09-14T15:32:21 In the Linux kernel, the following vulnerability has been resolved: ALSA: mts64
CVE-2026-80949 None 0.18% 1 0 2026-09-14T15:32:21 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmf
CVE-2026-80930 None 0.18% 1 0 2026-09-14T15:32:20 In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2
CVE-2026-80994 7.8 0.16% 1 0 2026-09-14T13:18:54.043000 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-80990 0 0.20% 1 0 2026-09-14T13:18:53.787000 In the Linux kernel, the following vulnerability has been resolved: net: thunde
CVE-2026-80987 7.5 0.51% 1 0 2026-09-14T13:18:53.343000 In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_tr
CVE-2026-80984 0 0.20% 1 0 2026-09-14T13:18:53.227000 In the Linux kernel, the following vulnerability has been resolved: net/smc: do
CVE-2026-90702 9.1 2.80% 2 0 2026-09-14T12:31:44 A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system
CVE-2026-80937 8.8 0.32% 1 0 2026-09-13T09:32:11 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:
CVE-2026-80950 7.8 0.16% 2 0 2026-09-13T07:17:02.210000 In the Linux kernel, the following vulnerability has been resolved: i3c: renesa
CVE-2026-81913 None 0.59% 1 0 2026-09-11T21:31:32 Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via th
CVE-2026-80957 0 0.17% 1 0 2026-09-11T20:19:01.520000 In the Linux kernel, the following vulnerability has been resolved: dm-pcache:
CVE-2026-80942 0 0.17% 1 0 2026-09-11T20:18:59.660000 In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwi
CVE-2026-80934 0 0.17% 1 0 2026-09-11T20:18:57.280000 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:
CVE-2026-42945 8.1 68.05% 2 45 2026-09-10T13:20:09.723000 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo
CVE-2025-25249 8.1 2.40% 1 0 2026-09-09T21:30:27 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6
CVE-2025-20701 8.8 8.67% 2 2 2026-09-08T16:17:48.883000 In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth aud
CVE-2026-31431 7.8 99.91% 1 100 2026-09-08T15:13:07.273000 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-54218 0 0.34% 2 0 2026-09-07T14:16:53.357000 Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamD
CVE-2026-75925 9.6 0.67% 2 0 2026-09-05T00:31:10 Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.
CVE-2026-80844 0 0.19% 1 2 2026-09-04T16:18:13.023000 In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6:
CVE-2026-13348 0 0.31% 1 0 2026-09-01T20:52:39.973000 CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability
CVE-2026-74469 8.8 0.47% 1 2 2026-08-19T17:21:03.977000 In the Linux kernel, the following vulnerability has been resolved: sctp: preve
CVE-2026-68121 7.8 0.14% 1 2 2026-08-19T17:20:29.553000 In the Linux kernel, the following vulnerability has been resolved: pppoe: relo
CVE-2021-34473 9.8 100.00% 2 14 2026-08-10T18:30:39 Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is uni
CVE-2026-12495 None 0.17% 2 0 2026-07-27T12:32:01 Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http
CVE-2026-47065 9.8 0.50% 2 0 2026-07-22T19:10:00.120000 ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via j
CVE-2026-58138 9.8 9.26% 4 6 2026-07-14T22:17:26.797000 Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code ex
CVE-2026-55945 4.2 0.19% 1 0 2026-07-07T13:31:43.910000 Concurrent execution using shared resource with improper synchronization ('race
CVE-2026-20111 4.8 0.18% 2 0 2026-03-10T21:32:11 A vulnerability in the web-based management interface of Cisco Prime Infrastruct
CVE-2026-0628 8.8 6.63% 1 2 2026-01-07T15:31:20 Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7
CVE-2024-3400 9.8 100.00% 2 45 2025-10-22T00:34:06 A command injection vulnerability in the GlobalProtect feature of Palo Alto Netw
CVE-2026-92702 0 0.21% 2 1 N/A
CVE-2026-61721 0 0.15% 2 0 N/A
CVE-2026-61819 0 0.58% 2 0 N/A
CVE-2026-61818 0 0.41% 2 0 N/A
CVE-2026-61821 0 0.29% 2 0 N/A
CVE-2026-61820 0 0.58% 2 0 N/A
CVE-2026-84383 0 0.64% 1 0 N/A
CVE-2026-57228 0 0.56% 1 0 N/A
CVE-2026-57227 0 0.40% 1 0 N/A
CVE-2026-63447 0 0.36% 1 0 N/A
CVE-2026-63446 0 0.39% 1 0 N/A
CVE-2026-63452 0 0.36% 1 0 N/A

CVE-2026-93742
(9.9 CRITICAL)

EPSS: 1.88%

updated 2026-09-21T19:17:17.273000

3 posts

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

hugovalters@mastodon.social at 2026-09-20T23:13:19.000Z ##

CVE-2026-93742 - Critical Command Injection in Totolink A3002MU router formWsc function. CVSS 9.9. Public exploit available. Isolate devices immediately. #CVE #Totolink #cybersecurity

valtersit.com/cve/CVE-2026-937

##

thehackerwire@mastodon.social at 2026-09-19T14:04:18.000Z ##

🔴 CVE-2026-93742 - Critical (9.9)

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T09:00:25.000Z ##

Totolink A3002MU routers suffer a CRITICAL (CVSS 9.4) command injection vuln (CVE-2026-93742) in formWsc (/boafrm/formWsc). Public exploit available — remote compromise risk. Restrict access, monitor devices, patch ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity

##

CVE-2026-86553
(8.8 HIGH)

EPSS: 0.45%

updated 2026-09-21T19:17:14.327000

4 posts

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered email address. By spoofing the application authentication information together wi

1 repos

https://github.com/minanagehsalalma/zte-smartlife-app-pwned

_r_netsec at 2026-09-21T16:43:05.231Z ##

ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553 minanagehsalalma.github.io/zte

##

thehackerwire@mastodon.social at 2026-09-20T06:03:10.000Z ##

🟠 CVE-2026-86553 - High (8.5)

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

_r_netsec@infosec.exchange at 2026-09-21T16:43:05.000Z ##

ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553 minanagehsalalma.github.io/zte

##

thehackerwire@mastodon.social at 2026-09-20T06:03:10.000Z ##

🟠 CVE-2026-86553 - High (8.5)

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79920
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-21T19:17:11.323000

2 posts

Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management authorization. InstallPlugin and UnInstallPlugin construct a pip package specification from unvalidated name and version fields, and the task worker invokes

thehackerwire@mastodon.social at 2026-09-21T18:01:21.000Z ##

🔴 CVE-2026-79920 - Critical (9.9)

Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management aut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T18:01:21.000Z ##

🔴 CVE-2026-79920 - Critical (9.9)

Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management aut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68928
(8.6 HIGH)

EPSS: 0.13%

updated 2026-09-21T19:17:09.157000

1 posts

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins/terminal/src/android/TerminalService.java does not verify the caller. Any installed Android application can bind the service and send MSG_EXEC with an a

thehackerwire@mastodon.social at 2026-09-18T22:03:20.000Z ##

🟠 CVE-2026-68928 - High (8.6)

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94301
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-21T18:10:30.343000

2 posts

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the  2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed a

cR0w at 2026-09-21T15:49:50.293Z ##

sev:CRIT bypass of CVE-2026-47065 in Apache MINA.

nvd.nist.gov/vuln/detail/cve-2

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.

##

cR0w@infosec.exchange at 2026-09-21T15:49:50.000Z ##

sev:CRIT bypass of CVE-2026-47065 in Apache MINA.

nvd.nist.gov/vuln/detail/cve-2

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.

##

CVE-2026-83621
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-21T17:19:08.590000

2 posts

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList for any authenticated user. The list_name, list_enabled, url, and list_update parameters allow a non-admin user to redirect threat-intelligence downloads

thehackerwire@mastodon.social at 2026-09-21T18:01:13.000Z ##

🟠 CVE-2026-83621 - High (8.1)

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T18:01:13.000Z ##

🟠 CVE-2026-83621 - High (8.1)

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77560
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-21T17:18:52.770000

2 posts

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to bypass per-app access controls with a differently cased hostname. The lookup in internal/service/access_controls_service.go through lookupStaticACLs and Get

thehackerwire@mastodon.social at 2026-09-21T18:01:33.000Z ##

🟠 CVE-2026-77560 - High (8.1)

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to byp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T18:01:33.000Z ##

🟠 CVE-2026-77560 - High (8.1)

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to byp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93740
(10.0 CRITICAL)

EPSS: 0.61%

updated 2026-09-21T16:17:28.070000

2 posts

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

hugovalters@mastodon.social at 2026-09-21T17:00:16.000Z ##

CVE-2026-93740: Totolink A3002MU buffer overflow in formWlEncrypt, CVSS 10, unpatched, remote exploit public. Patch or block now. valtersit.com/cve/CVE-2026-937 #CVE #infosec #Totolink

##

thehackerwire@mastodon.social at 2026-09-18T23:01:18.000Z ##

🔴 CVE-2026-93740 - Critical (10)

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82187
(9.8 CRITICAL)

EPSS: 0.14%

updated 2026-09-21T15:33:02

2 posts

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.

offseq at 2026-09-21T09:00:25.181Z ##

Web to Print Online Designer plugin (v1.7.0 – 2.14.9) hit by CRITICAL CVE-2026-82187: unauthenticated attackers can upload & execute arbitrary files (incl. PHP), leading to RCE. Upgrade to 2.15.0+ ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-21T09:00:25.000Z ##

Web to Print Online Designer plugin (v1.7.0 – 2.14.9) hit by CRITICAL CVE-2026-82187: unauthenticated attackers can upload & execute arbitrary files (incl. PHP), leading to RCE. Upgrade to 2.15.0+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202682187 #RCE

##

CVE-2026-93993
(8.8 HIGH)

EPSS: 0.60%

updated 2026-09-21T15:17:37.247000

2 posts

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.

thehackerwire@mastodon.social at 2026-09-20T00:02:41.000Z ##

🟠 CVE-2026-93993 - High (8.8)

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:02:41.000Z ##

🟠 CVE-2026-93993 - High (8.8)

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92701
(9.1 CRITICAL)

EPSS: 0.22%

updated 2026-09-21T15:17:35.313000

2 posts

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checkin

1 repos

https://github.com/muhammad-usama-sardar/intra-handshake-fail

thehackerwire@mastodon.social at 2026-09-21T00:01:18.000Z ##

🔴 CVE-2026-92701 - Critical (9.1)

trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote valid...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T00:01:18.000Z ##

🔴 CVE-2026-92701 - Critical (9.1)

trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote valid...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90817
(9.8 CRITICAL)

EPSS: 0.57%

updated 2026-09-21T15:17:34.560000

5 posts

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this co

2 repos

https://github.com/murrez/CVE-2026-90817

https://github.com/ExDev994/CVE-2026-90817

undercodenews@mastodon.social at 2026-09-21T05:56:39.000Z ##

Critical REDCap RCE Exposes Public Survey Attack Path: CVE-2026-90817 Raises Alarm for Research and Healthcare Systems + Video

A New Critical Vulnerability Lands in a High-Value Research Platform A newly disclosed vulnerability in Vanderbilt BaseFortify +1 The vulnerability was published on September 20, 2026, and is associated with REDCap's survey passthrough routing and Data Import processing logic. According to the CVE description, an attacker could manipulate HTTP…

undercodenews.com/critical-red

##

thehackerwire@mastodon.social at 2026-09-20T15:02:14.000Z ##

🔴 CVE-2026-90817 - Critical (9.8)

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended contr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-20T13:30:24.746Z ##

CVE-2026-90817: CRITICAL RCE in REDCap (13.3.0+). Unauth attackers can exploit improper code generation via survey hash for full server compromise. Restrict hash access & monitor systems. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T15:02:14.000Z ##

🔴 CVE-2026-90817 - Critical (9.8)

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended contr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T13:30:24.000Z ##

CVE-2026-90817: CRITICAL RCE in REDCap (13.3.0+). Unauth attackers can exploit improper code generation via survey hash for full server compromise. Restrict hash access & monitor systems. radar.offseq.com/threat/cve-20 #OffSeq #REDCap #infosec #RCE

##

CVE-2026-87839
(7.5 HIGH)

EPSS: 0.21%

updated 2026-09-21T13:34:57.127000

2 posts

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.

thehackerwire@mastodon.social at 2026-09-20T17:03:48.000Z ##

🟠 CVE-2026-87839 - High (7.5)

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T17:03:48.000Z ##

🟠 CVE-2026-87839 - High (7.5)

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87067
(8.5 HIGH)

EPSS: 0.28%

updated 2026-09-21T13:34:57.127000

2 posts

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Formina

thehackerwire@mastodon.social at 2026-09-20T16:01:30.000Z ##

🟠 CVE-2026-87067 - High (8.5)

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T16:01:30.000Z ##

🟠 CVE-2026-87067 - High (8.5)

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85017
(7.5 HIGH)

EPSS: 0.24%

updated 2026-09-21T13:34:57.127000

2 posts

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable ac

thehackerwire@mastodon.social at 2026-09-20T16:01:21.000Z ##

🟠 CVE-2026-85017 - High (7.5)

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T16:01:21.000Z ##

🟠 CVE-2026-85017 - High (7.5)

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82842
(8.1 HIGH)

EPSS: 0.22%

updated 2026-09-21T13:34:57.127000

4 posts

The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administ

thehackerwire@mastodon.social at 2026-09-20T16:01:11.000Z ##

🟠 CVE-2026-82842 - High (8.1)

The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-20T09:00:25.447Z ##

CVE-2026-82842 | CRITICAL: SAML Single Sign On WP plugin <6.0.0 fails to enforce SSO linking criteria, letting attackers with IDP control hijack any account, incl. admins. Upgrade to 6.0.0+ now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T16:01:11.000Z ##

🟠 CVE-2026-82842 - High (8.1)

The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T09:00:25.000Z ##

CVE-2026-82842 | CRITICAL: SAML Single Sign On WP plugin <6.0.0 fails to enforce SSO linking criteria, letting attackers with IDP control hijack any account, incl. admins. Upgrade to 6.0.0+ now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202682842 #SAML #infosec

##

CVE-2026-85574
(8.0 HIGH)

EPSS: 0.19%

updated 2026-09-21T13:34:57.127000

1 posts

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.

thehackerwire@mastodon.social at 2026-09-19T17:02:47.000Z ##

🟠 CVE-2026-85574 - High (8)

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86814
(8.1 HIGH)

EPSS: 0.23%

updated 2026-09-21T13:34:57.127000

2 posts

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.

thehackerwire@mastodon.social at 2026-09-19T15:03:14.000Z ##

🟠 CVE-2026-86814 - High (8.1)

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, includin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T07:30:23.000Z ##

UsersWP <1.5.10 is affected by CRITICAL privilege management flaw (CVE-2026-86814). Attackers can hijack any account — including admins — by abusing social login email validation. Update to 1.5.10+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202686814 #infosec

##

CVE-2026-87909
(7.5 HIGH)

EPSS: 0.53%

updated 2026-09-21T13:33:33.387000

3 posts

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. This makes it p

hugovalters@mastodon.social at 2026-09-21T15:40:01.000Z ##

CVE-2026-87909 RCE in WP Photo Album Plus, CVSS 7.5, unpatched. Subscribers can run code via the ImageMagick filename flaw. Disable or patch now. valtersit.com/cve/CVE-2026-879 #CVE #WordPress #infosec

##

hugovalters@mastodon.social at 2026-09-21T15:20:38.000Z ##

CVE-2026-87909 RCE in WP Photo Album Plus, CVSS 7.5, unpatched. Subscribers can run code via the ImageMagick filename flaw. Disable or patch now. valtersit.com/cve/CVE-2026-879 #CVE #WordPress #infosec

##

thehackerwire@mastodon.social at 2026-09-19T07:04:32.000Z ##

🟠 CVE-2026-87909 - High (7.5)

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94015
(7.3 HIGH)

EPSS: 0.26%

updated 2026-09-21T13:33:33.387000

1 posts

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file /drug_recommender/Admin/edit_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.

hugovalters@mastodon.social at 2026-09-21T11:03:05.000Z ##

CVE-2026-94015 - Remote SQLi in SourceCodester Drug Recommendation System 1.0. Public exploit available. CVSS 7.3. Restrict access immediately. #CVE #SQLi #infosec

valtersit.com/cve/CVE-2026-940

##

CVE-2026-94129
(8.8 HIGH)

EPSS: 0.12%

updated 2026-09-21T13:33:33.387000

4 posts

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-what-where condition. The attack needs to be approached locally. The exploit is now public and may be used. The vendor was contacted early about this dis

1 repos

https://github.com/lzty/CVE-2026-94129

thehackerwire@mastodon.social at 2026-09-21T03:02:10.000Z ##

🟠 CVE-2026-94129 - High (8.8)

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-21T03:00:26.558Z ##

CVE-2026-94129 (CRITICAL, CVSS 9.3) impacts BioStar VALKYRIE AURORA 2.10.2411.0800: local write-what-where in IOCTL Handler (BS_RVSIO64.sys) enables privilege escalation. No patch, public exploit exists. Limit local access. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-21T03:02:10.000Z ##

🟠 CVE-2026-94129 - High (8.8)

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-21T03:00:26.000Z ##

CVE-2026-94129 (CRITICAL, CVSS 9.3) impacts BioStar VALKYRIE AURORA 2.10.2411.0800: local write-what-where in IOCTL Handler (BS_RVSIO64.sys) enables privilege escalation. No patch, public exploit exists. Limit local access. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec

##

CVE-2026-94096
(9.9 CRITICAL)

EPSS: 1.65%

updated 2026-09-21T13:33:33.387000

4 posts

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this d

thehackerwire@mastodon.social at 2026-09-21T01:01:44.000Z ##

🔴 CVE-2026-94096 - Critical (9.9)

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-21T00:00:35.130Z ##

Netcore NBR200V2 (v1.3.241127.071246) hit by CRITICAL (CVSS 9.4) command injection (CVE-2026-94096) in /usr/bin/network_tools. Remote exploit is public, no patch. Isolate devices and monitor traffic. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-21T01:01:44.000Z ##

🔴 CVE-2026-94096 - Critical (9.9)

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-21T00:00:35.000Z ##

Netcore NBR200V2 (v1.3.241127.071246) hit by CRITICAL (CVSS 9.4) command injection (CVE-2026-94096) in /usr/bin/network_tools. Remote exploit is public, no patch. Isolate devices and monitor traffic. radar.offseq.com/threat/cve-20 #OffSeq #CVE202694096 #Netcore #Infosec

##

CVE-2026-84434
(9.8 CRITICAL)

EPSS: 0.70%

updated 2026-09-21T13:33:33.387000

3 posts

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a rejected file's intact upload state is later passed to upload_file() without re-v

Nuclei template

1 repos

https://github.com/murrez/CVE-2026-84434

beyondmachines1 at 2026-09-20T14:01:13.640Z ##

Critical Arbitrary File Upload Flaw in Gravity Forms Leads to Remote Code Execution

Gravity Forms patched a critical vulnerability (CVE-2026-84434) that allows unauthenticated attackers to upload executable files and gain remote code execution.

**If you use Gravity Forms on WordPress, update it to version 3.1.1 or later ASAP. If you can't update immediately, disable file upload fields on any public forms, then check your upload folders for unexpected PHP files and your logs for suspicious activity.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-20T14:01:13.000Z ##

Critical Arbitrary File Upload Flaw in Gravity Forms Leads to Remote Code Execution

Gravity Forms patched a critical vulnerability (CVE-2026-84434) that allows unauthenticated attackers to upload executable files and gain remote code execution.

**If you use Gravity Forms on WordPress, update it to version 3.1.1 or later ASAP. If you can't update immediately, disable file upload fields on any public forms, then check your upload folders for unexpected PHP files and your logs for suspicious activity.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

thehackerwire@mastodon.social at 2026-09-19T07:04:23.000Z ##

🔴 CVE-2026-84434 - Critical (9.8)

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93962
(8.3 HIGH)

EPSS: 0.53%

updated 2026-09-21T13:33:33.387000

2 posts

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Up

thehackerwire@mastodon.social at 2026-09-20T06:03:00.000Z ##

🟠 CVE-2026-93962 - High (8.3)

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T06:03:00.000Z ##

🟠 CVE-2026-93962 - High (8.3)

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93741
(10.0 CRITICAL)

EPSS: 0.64%

updated 2026-09-21T13:33:33.387000

4 posts

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

offseq at 2026-09-20T00:00:36.191Z ##

CVE-2026-93741: Totolink A3002MU (Hh-B20211125.1046) hit by CRITICAL buffer overflow in formWlWds (CVSS 10). Exploit is public; remote code exec risk. Isolate affected routers or block attacks at the network. radar.offseq.com/threat/cve-20

##

hugovalters@mastodon.social at 2026-09-19T23:09:02.000Z ##

CVE-2026-93741 - Critical CVSS 10 Buffer Overflow in Totolink A3002MU routers. Public exploit available for remote attacks. Isolate affected devices now. #CVE #Totolink #infosec

valtersit.com/cve/CVE-2026-937

##

offseq@infosec.exchange at 2026-09-20T00:00:36.000Z ##

CVE-2026-93741: Totolink A3002MU (Hh-B20211125.1046) hit by CRITICAL buffer overflow in formWlWds (CVSS 10). Exploit is public; remote code exec risk. Isolate affected routers or block attacks at the network. radar.offseq.com/threat/cve-20 #OffSeq #CVE202693741 #IoT #Exploit

##

thehackerwire@mastodon.social at 2026-09-19T07:03:14.000Z ##

🔴 CVE-2026-93741 - Critical (10)

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-1255
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-21T13:33:33.387000

1 posts

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email add

thehackerwire@mastodon.social at 2026-09-19T14:04:06.000Z ##

🟠 CVE-2026-1255 - High (7.5)

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-4327
(8.8 HIGH)

EPSS: 0.70%

updated 2026-09-21T13:33:33.387000

1 posts

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the use of eval() to execute user-supplied 'custom logic' code on the frontend. The AJAX handler at twiz-ajax.php verifies a nonce but performs no current_use

thehackerwire@mastodon.social at 2026-09-19T09:01:57.000Z ##

🟠 CVE-2026-4327 - High (8.8)

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85658
(8.1 HIGH)

EPSS: 0.36%

updated 2026-09-21T13:33:33.387000

1 posts

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authe

thehackerwire@mastodon.social at 2026-09-19T09:01:48.000Z ##

🟠 CVE-2026-85658 - High (8.1)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is du...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92229
(9.1 CRITICAL)

EPSS: 0.40%

updated 2026-09-21T13:33:33.387000

2 posts

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary sho

1 repos

https://github.com/murrez/CVE-2026-92229

thehackerwire@mastodon.social at 2026-09-19T07:03:24.000Z ##

🔴 CVE-2026-92229 - Critical (9.1)

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T04:30:23.000Z ##

CVE-2026-92229: CRITICAL code injection in wpmudev Forminator Forms plugin (≤1.57.2). Unauthenticated attackers can execute arbitrary shortcodes, risking full WordPress site compromise. Restrict or disable plugin now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202692229

##

CVE-2026-93739
(9.9 CRITICAL)

EPSS: 0.49%

updated 2026-09-21T13:33:33.387000

1 posts

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-09-18T23:01:09.000Z ##

🔴 CVE-2026-93739 - Critical (9.9)

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed fro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93031
(8.8 HIGH)

EPSS: 0.58%

updated 2026-09-21T13:33:33.387000

1 posts

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported f

thehackerwire@mastodon.social at 2026-09-18T21:02:33.000Z ##

🟠 CVE-2026-93031 - High (8.8)

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10747
(10.0 CRITICAL)

EPSS: 0.52%

updated 2026-09-21T13:17:07.147000

4 posts

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

censys at 2026-09-21T16:20:25.621Z ##

🚨 RAPID RESPONSE: IBM MQ Pre-Authentication RCE [CVE-2026-10747]

A critical heap buffer overflow in IBM MQ could allow remote code execution before authentication. CVSS: 10.0.

Censys ARC observes IBM MQ web consoles on 120 hosts and 149 web properties Internet-wide. These numbers indicate IBM MQ presence, not confirmed vulnerable systems.

IBM has released fixes for affected MQ Server and MQ Appliance versions. No public PoC or reported active exploitation is known at this time.

Read the full analysis for affected versions, Internet observations, and remediation guidance. censys.com/advisory/cve-2026-1

##

DailyCyberSecurity at 2026-09-20T19:21:35.987Z ##

Critical IBM MQ vulnerabilities allow remote code execution. Learn how CVE-2026-10747 and CVE-2026-10858 hit 10.0 CVSS and require urgent patching.

securityonline.info/ibm-mq-vul

##

censys@infosec.exchange at 2026-09-21T16:20:25.000Z ##

🚨 RAPID RESPONSE: IBM MQ Pre-Authentication RCE [CVE-2026-10747]

A critical heap buffer overflow in IBM MQ could allow remote code execution before authentication. CVSS: 10.0.

Censys ARC observes IBM MQ web consoles on 120 hosts and 149 web properties Internet-wide. These numbers indicate IBM MQ presence, not confirmed vulnerable systems.

IBM has released fixes for affected MQ Server and MQ Appliance versions. No public PoC or reported active exploitation is known at this time.

Read the full analysis for affected versions, Internet observations, and remediation guidance. censys.com/advisory/cve-2026-1

#CensysARC #IBMMQ #Cybersecurity #Vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-09-20T19:21:35.000Z ##

Critical IBM MQ vulnerabilities allow remote code execution. Learn how CVE-2026-10747 and CVE-2026-10858 hit 10.0 CVSS and require urgent patching.

#IBMMQ #CVE202610747 #CVE202610858 #Cybersecurity #Infosec

securityonline.info/ibm-mq-vul

##

CVE-2026-94146
(8.8 HIGH)

EPSS: 0.12%

updated 2026-09-21T09:31:09

2 posts

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosur

offseq at 2026-09-21T07:30:25.053Z ##

BioStar BIOS Update Utility 1.9.7.3 hit by CRITICAL CVE-2026-94146: local write-what-where bug in BSMEM64_W10.sys (IOCTL handler). Exploit public; vendor silent. Restrict local access immediately. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-21T07:30:25.000Z ##

BioStar BIOS Update Utility 1.9.7.3 hit by CRITICAL CVE-2026-94146: local write-what-where bug in BSMEM64_W10.sys (IOCTL handler). Exploit public; vendor silent. Restrict local access immediately. radar.offseq.com/threat/cve-20 #OffSeq #CVE202694146 #bios #infosec

##

CVE-2026-94142
(8.8 HIGH)

EPSS: 0.13%

updated 2026-09-21T06:30:32

4 posts

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argument PhysicalAddress leads to write-what-where condition. The attack needs to be performed locally. The exploit has been disclosed publicly and may be use

thehackerwire@mastodon.social at 2026-09-21T06:03:51.000Z ##

🟠 CVE-2026-94142 - High (8.8)

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argum...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-21T06:00:25.835Z ##

BioStar Temp Monitor Utility v1.2.1806.2200 hit by CRITICAL CVE-2026-94142 (CVSS 9.3): write-what-where flaw in IOCTL handler. Local attackers can write arbitrary memory. No patch — restrict access. Details: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-21T06:03:51.000Z ##

🟠 CVE-2026-94142 - High (8.8)

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argum...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-21T06:00:25.000Z ##

BioStar Temp Monitor Utility v1.2.1806.2200 hit by CRITICAL CVE-2026-94142 (CVSS 9.3): write-what-where flaw in IOCTL handler. Local attackers can write arbitrary memory. No patch — restrict access. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202694142 #infosec #vuln

##

CVE-2026-94128
(8.8 HIGH)

EPSS: 0.12%

updated 2026-09-21T03:30:29

4 posts

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where condition. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early abo

1 repos

https://github.com/lzty/CVE-2026-94128

offseq at 2026-09-21T04:30:23.921Z ##

BioStar VIVID LED DJ 4.0.2411.1500 hit by CRITICAL CVE-2026-94128: write-what-where in BS_LED64.sys allows local attackers arbitrary memory writes. No patch — restrict local access, monitor updates. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-21T03:02:01.000Z ##

🟠 CVE-2026-94128 - High (8.8)

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-21T04:30:23.000Z ##

BioStar VIVID LED DJ 4.0.2411.1500 hit by CRITICAL CVE-2026-94128: write-what-where in BS_LED64.sys allows local attackers arbitrary memory writes. No patch — restrict local access, monitor updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE202694128 #PrivilegeEscalation

##

thehackerwire@mastodon.social at 2026-09-21T03:02:01.000Z ##

🟠 CVE-2026-94128 - High (8.8)

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94099
(9.9 CRITICAL)

EPSS: 1.69%

updated 2026-09-21T03:30:27

4 posts

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was c

offseq at 2026-09-21T13:30:28.611Z ##

CVE-2026-94099 | Netcore NBR200V2 (1.3.241127.071246): CRITICAL command injection via restore.cgi (QUERY_STRING). Remote exploit, no patch, vendor silent. Isolate devices & monitor logs. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-21T02:03:39.000Z ##

🔴 CVE-2026-94099 - Critical (9.9)

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in comman...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-21T13:30:28.000Z ##

CVE-2026-94099 | Netcore NBR200V2 (1.3.241127.071246): CRITICAL command injection via restore.cgi (QUERY_STRING). Remote exploit, no patch, vendor silent. Isolate devices & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #Netcore #CVE202694099 #infosec

##

thehackerwire@mastodon.social at 2026-09-21T02:03:39.000Z ##

🔴 CVE-2026-94099 - Critical (9.9)

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in comman...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94101
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-09-21T03:30:27

4 posts

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did

offseq at 2026-09-21T12:00:26.710Z ##

Netcore NBR200V2 (v1.3.241127.071246) hit by CRITICAL CVE-2026-94101 buffer overflow in /usr/bin/routerd. Remote code exec possible. Public exploit, no patch. Restrict remote access ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-21T03:02:20.000Z ##

🔴 CVE-2026-94101 - Critical (9.9)

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-21T12:00:26.000Z ##

Netcore NBR200V2 (v1.3.241127.071246) hit by CRITICAL CVE-2026-94101 buffer overflow in /usr/bin/routerd. Remote code exec possible. Public exploit, no patch. Restrict remote access ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Netcore #RouterSecurity #Infosec

##

thehackerwire@mastodon.social at 2026-09-21T03:02:20.000Z ##

🔴 CVE-2026-94101 - Critical (9.9)

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94100
(9.9 CRITICAL)

EPSS: 0.46%

updated 2026-09-21T03:30:23

4 posts

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The v

thehackerwire@mastodon.social at 2026-09-21T02:03:21.000Z ##

🔴 CVE-2026-94100 - Critical (9.9)

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-21T01:30:23.825Z ##

Netcore NBR200V2 v1.3.241127.071246 has a CRITICAL buffer overflow (CVE-2026-94100) in WAN VLAN config. Remotely exploitable, public exploit out. Restrict access — no patch yet. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-21T02:03:21.000Z ##

🔴 CVE-2026-94100 - Critical (9.9)

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-21T01:30:23.000Z ##

Netcore NBR200V2 v1.3.241127.071246 has a CRITICAL buffer overflow (CVE-2026-94100) in WAN VLAN config. Remotely exploitable, public exploit out. Restrict access — no patch yet. radar.offseq.com/threat/cve-20 #OffSeq #Netcore #CVE202694100 #Infosec

##

CVE-2026-94098
(9.1 CRITICAL)

EPSS: 2.38%

updated 2026-09-21T03:30:22

2 posts

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this di

thehackerwire@mastodon.social at 2026-09-21T02:03:30.000Z ##

🔴 CVE-2026-94098 - Critical (9.1)

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T02:03:30.000Z ##

🔴 CVE-2026-94098 - Critical (9.1)

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94097
(10.0 CRITICAL)

EPSS: 1.99%

updated 2026-09-21T00:30:33

2 posts

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about t

thehackerwire@mastodon.social at 2026-09-21T01:01:54.000Z ##

🔴 CVE-2026-94097 - Critical (10)

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command inje...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T01:01:54.000Z ##

🔴 CVE-2026-94097 - Critical (10)

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command inje...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94095
(9.9 CRITICAL)

EPSS: 1.67%

updated 2026-09-21T00:30:33

2 posts

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacte

1 repos

https://github.com/HackSpeak/CVE-2026-94095

thehackerwire@mastodon.social at 2026-09-21T01:01:34.000Z ##

🔴 CVE-2026-94095 - Critical (9.9)

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument ur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T01:01:34.000Z ##

🔴 CVE-2026-94095 - Critical (9.9)

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument ur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94089
(10.0 CRITICAL)

EPSS: 0.98%

updated 2026-09-20T21:31:45

2 posts

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-09-20T22:02:07.000Z ##

🔴 CVE-2026-94089 - Critical (10)

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T22:02:07.000Z ##

🔴 CVE-2026-94089 - Critical (10)

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94036
(8.8 HIGH)

EPSS: 0.47%

updated 2026-09-20T18:31:25

2 posts

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.

1 repos

https://github.com/djzzlim/CVE-2026-94036

thehackerwire@mastodon.social at 2026-09-20T17:03:09.000Z ##

🟠 CVE-2026-94036 - High (8.8)

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T17:03:09.000Z ##

🟠 CVE-2026-94036 - High (8.8)

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87068
(6.6 MEDIUM)

EPSS: 0.21%

updated 2026-09-20T15:31:27

2 posts

The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who submits it. The same user is refused an identical form through both the ordinary form

offseq at 2026-09-20T07:30:24.117Z ##

CRITICAL: CVE-2026-87068 in Forminator Forms (<1.57.2.1) allows users with quiz import access to publish forms that assign admin roles. Upgrade to v1.57.2.1 now to prevent privilege escalation. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-20T07:30:24.000Z ##

CRITICAL: CVE-2026-87068 in Forminator Forms (<1.57.2.1) allows users with quiz import access to publish forms that assign admin roles. Upgrade to v1.57.2.1 now to prevent privilege escalation. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202687068 #infosec

##

CVE-2026-92965
(3.7 LOW)

EPSS: 0.15%

updated 2026-09-20T14:17:00.423000

2 posts

The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that merely resemble the expected one trigger it too, and the callback runs on every reques

offseq at 2026-09-20T10:30:24.375Z ##

HIGH severity: CVE-2026-92965 in TikTok WordPress plugin (1.2.0 – 1.4.2) allows any visitor to redeem sign-in codes via URL, risking ad platform abuse. Restrict or disable the plugin while awaiting a patch. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-20T10:30:24.000Z ##

HIGH severity: CVE-2026-92965 in TikTok WordPress plugin (1.2.0 – 1.4.2) allows any visitor to redeem sign-in codes via URL, risking ad platform abuse. Restrict or disable the plugin while awaiting a patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Security

##

CVE-2026-94106
(8.8 HIGH)

EPSS: 1.66%

updated 2026-09-20T12:30:37

2 posts

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.

thehackerwire@mastodon.social at 2026-09-20T15:02:23.000Z ##

🟠 CVE-2026-94106 - High (8.8)

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands execut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T15:02:23.000Z ##

🟠 CVE-2026-94106 - High (8.8)

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands execut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94107
(8.1 HIGH)

EPSS: 0.42%

updated 2026-09-20T12:30:35

2 posts

NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a password reset and predict the token to gain administrative account access without rate limiting or expiration.

thehackerwire@mastodon.social at 2026-09-20T15:02:33.000Z ##

🟠 CVE-2026-94107 - High (8.1)

NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a pas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T15:02:33.000Z ##

🟠 CVE-2026-94107 - High (8.1)

NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a pas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94104
(8.8 HIGH)

EPSS: 0.67%

updated 2026-09-20T12:30:28

2 posts

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office access can upload PHP files to the web-accessible image/data/ directory and execute them for remote code execution.

thehackerwire@mastodon.social at 2026-09-20T15:03:32.000Z ##

🟠 CVE-2026-94104 - High (8.8)

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T15:03:32.000Z ##

🟠 CVE-2026-94104 - High (8.8)

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94003
(10.0 CRITICAL)

EPSS: 0.61%

updated 2026-09-20T12:30:28

4 posts

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

thehackerwire@mastodon.social at 2026-09-20T15:03:22.000Z ##

🔴 CVE-2026-94003 - Critical (10)

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-20T12:00:24.645Z ##

CVE-2026-94003: CRITICAL stack buffer overflow in Comfast CF-N1-S (2.6.0.1). Flaw in get_css_path_from_uri (/cgi-bin/mbox-config) is remotely exploitable; public exploit exists. Restrict access & monitor closely. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T15:03:22.000Z ##

🔴 CVE-2026-94003 - Critical (10)

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T12:00:24.000Z ##

CVE-2026-94003: CRITICAL stack buffer overflow in Comfast CF-N1-S (2.6.0.1). Flaw in get_css_path_from_uri (/cgi-bin/mbox-config) is remotely exploitable; public exploit exists. Restrict access & monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE #IoTSecurity

##

CVE-2026-94109
(8.8 HIGH)

EPSS: 0.92%

updated 2026-09-20T12:17:06.620000

2 posts

openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions through collection summaries, dashboard portlets, or MIME templates to instantiate dangerous classes like freemarker.template.utility.Execute and invoke Runt

thehackerwire@mastodon.social at 2026-09-20T15:03:13.000Z ##

🟠 CVE-2026-94109 - High (8.8)

openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions thro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T15:03:13.000Z ##

🟠 CVE-2026-94109 - High (8.8)

openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions thro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93958
(9.1 CRITICAL)

EPSS: 2.17%

updated 2026-09-20T03:30:31

4 posts

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

1 repos

https://github.com/HackSpeak/CVE-2026-93958

offseq at 2026-09-20T06:00:23.952Z ##

CVE-2026-93958 (CRITICAL, CVSS 9.4): D-Link R95 BE9500_1.00.16 routers have an OS command injection flaw via the NTPServer argument in DHMAPI (/bin/ssi). Exploit is public, no patch yet — restrict access and monitor activity. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T03:02:11.000Z ##

🔴 CVE-2026-93958 - Critical (9.1)

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T06:00:23.000Z ##

CVE-2026-93958 (CRITICAL, CVSS 9.4): D-Link R95 BE9500_1.00.16 routers have an OS command injection flaw via the NTPServer argument in DHMAPI (/bin/ssi). Exploit is public, no patch yet — restrict access and monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #CVE202693958 #Vuln

##

thehackerwire@mastodon.social at 2026-09-20T03:02:11.000Z ##

🔴 CVE-2026-93958 - Critical (9.1)

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94083
(9.4 CRITICAL)

EPSS: 0.40%

updated 2026-09-20T03:30:29

8 posts

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.

cR0w at 2026-09-21T13:27:36.535Z ##

RE: infosec.exchange/@suricata/117

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

##

beyondmachines1 at 2026-09-21T08:01:12.990Z ##

Suricata Patches Flaws Allowing Network Monitoring Bypass

Suricata 8.0.7 fixes two vulnerabilities (CVE-2026-94084 and CVE-2026-94083) that allow unauthenticated attackers to crash the IDS/IPS engine. These flaws exploit the HTTP/2 and DoH2 parsers to create a monitoring blind spot for network bypass.

**If you run Suricata for network monitoring, update it to version 8.0.7 ASAP. Older versions can be crashed remotely, leaving your network unmonitored and your attack detection blind. Until you patch, closely monitor that the Suricata service is actually running, because an unexpected stop may mean someone is already attacking you.**

beyondmachines.net/event_detai

##

offseq at 2026-09-20T04:30:23.101Z ##

Suricata 8.0.0 – 8.0.6 affected by CRITICAL CVE-2026-94083: Type confusion in DoH2 (CWE-843) can trigger DoS via invalid free. Patch to 8.0.7+. No known exploits yet. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T03:02:19.000Z ##

🔴 CVE-2026-94083 - Critical (9.4)

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-09-21T13:27:36.000Z ##

RE: infosec.exchange/@suricata/117

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

##

beyondmachines1@infosec.exchange at 2026-09-21T08:01:12.000Z ##

Suricata Patches Flaws Allowing Network Monitoring Bypass

Suricata 8.0.7 fixes two vulnerabilities (CVE-2026-94084 and CVE-2026-94083) that allow unauthenticated attackers to crash the IDS/IPS engine. These flaws exploit the HTTP/2 and DoH2 parsers to create a monitoring blind spot for network bypass.

**If you run Suricata for network monitoring, update it to version 8.0.7 ASAP. Older versions can be crashed remotely, leaving your network unmonitored and your attack detection blind. Until you patch, closely monitor that the Suricata service is actually running, because an unexpected stop may mean someone is already attacking you.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-09-20T04:30:23.000Z ##

Suricata 8.0.0 – 8.0.6 affected by CRITICAL CVE-2026-94083: Type confusion in DoH2 (CWE-843) can trigger DoS via invalid free. Patch to 8.0.7+. No known exploits yet. radar.offseq.com/threat/cve-20 #OffSeq #Suricata #Vuln #BlueTeam

##

thehackerwire@mastodon.social at 2026-09-20T03:02:19.000Z ##

🔴 CVE-2026-94083 - Critical (9.4)

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94084
(9.4 CRITICAL)

EPSS: 0.40%

updated 2026-09-20T02:16:53.717000

8 posts

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

cR0w at 2026-09-21T13:27:36.535Z ##

RE: infosec.exchange/@suricata/117

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

##

beyondmachines1 at 2026-09-21T08:01:12.990Z ##

Suricata Patches Flaws Allowing Network Monitoring Bypass

Suricata 8.0.7 fixes two vulnerabilities (CVE-2026-94084 and CVE-2026-94083) that allow unauthenticated attackers to crash the IDS/IPS engine. These flaws exploit the HTTP/2 and DoH2 parsers to create a monitoring blind spot for network bypass.

**If you run Suricata for network monitoring, update it to version 8.0.7 ASAP. Older versions can be crashed remotely, leaving your network unmonitored and your attack detection blind. Until you patch, closely monitor that the Suricata service is actually running, because an unexpected stop may mean someone is already attacking you.**

beyondmachines.net/event_detai

##

thehackerwire@mastodon.social at 2026-09-20T03:02:29.000Z ##

🔴 CVE-2026-94084 - Critical (9.4)

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-20T03:00:23.655Z ##

CRITICAL use-after-free (CVE-2026-94084) in Suricata <8.0.7 🛡️. Exploitable via HTTP/2 rules with http.response_header. Risk: code execution, memory corruption. Patch by upgrading to 8.0.7+. radar.offseq.com/threat/cve-20

##

cR0w@infosec.exchange at 2026-09-21T13:27:36.000Z ##

RE: infosec.exchange/@suricata/117

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

##

beyondmachines1@infosec.exchange at 2026-09-21T08:01:12.000Z ##

Suricata Patches Flaws Allowing Network Monitoring Bypass

Suricata 8.0.7 fixes two vulnerabilities (CVE-2026-94084 and CVE-2026-94083) that allow unauthenticated attackers to crash the IDS/IPS engine. These flaws exploit the HTTP/2 and DoH2 parsers to create a monitoring blind spot for network bypass.

**If you run Suricata for network monitoring, update it to version 8.0.7 ASAP. Older versions can be crashed remotely, leaving your network unmonitored and your attack detection blind. Until you patch, closely monitor that the Suricata service is actually running, because an unexpected stop may mean someone is already attacking you.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

thehackerwire@mastodon.social at 2026-09-20T03:02:29.000Z ##

🔴 CVE-2026-94084 - Critical (9.4)

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T03:00:23.000Z ##

CRITICAL use-after-free (CVE-2026-94084) in Suricata <8.0.7 🛡️. Exploitable via HTTP/2 rules with http.response_header. Risk: code execution, memory corruption. Patch by upgrading to 8.0.7+. radar.offseq.com/threat/cve-20 #OffSeq #Suricata #Vuln #Infosec

##

CVE-2026-78030
(9.8 CRITICAL)

EPSS: 0.73%

updated 2026-09-20T01:16:30.017000

4 posts

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not consult @INC, so the attribute chooses the file that Perl loads and runs. The MLDBM::

thehackerwire@mastodon.social at 2026-09-20T02:02:25.000Z ##

🔴 CVE-2026-78030 - Critical (9.8)

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.

DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. requ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-20T01:30:24.159Z ##

DBD::DBM (<1.653) for Perl is affected by CVE-2026-78030 (CRITICAL, CVSS 9.8). Unvalidated dbm_type/dbm_mldbm allow arbitrary code execution if attacker controls input. Patch status unknown — sanitize attributes now! radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-20T02:02:25.000Z ##

🔴 CVE-2026-78030 - Critical (9.8)

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.

DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. requ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-20T01:30:24.000Z ##

DBD::DBM (<1.653) for Perl is affected by CVE-2026-78030 (CRITICAL, CVSS 9.8). Unvalidated dbm_type/dbm_mldbm allow arbitrary code execution if attacker controls input. Patch status unknown — sanitize attributes now! radar.offseq.com/threat/cve-20 #OffSeq #CVE202678030 #Perl #Infosec

##

CVE-2026-94054
(7.0 None)

EPSS: 0.27%

updated 2026-09-20T00:30:33

2 posts

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

DailyCyberSecurity at 2026-09-21T00:35:40.404Z ##

Exim 4.100.1 patches a serious Exim vulnerability set: Proxy Protocol heap flaws, a GnuTLS use-after-free, and SMTP smuggling (CVE-2026-94054). Upgrade now.

securityonline.info/exim-4-100

##

DailyCyberSecurity@infosec.exchange at 2026-09-21T00:35:40.000Z ##

Exim 4.100.1 patches a serious Exim vulnerability set: Proxy Protocol heap flaws, a GnuTLS use-after-free, and SMTP smuggling (CVE-2026-94054). Upgrade now.

#Exim #EximVulnerability #SMTPsmuggling #ProxyProtocol #MailServerSecurity #CVE202694054

securityonline.info/exim-4-100

##

CVE-2026-94056
(7.5 HIGH)

EPSS: 0.24%

updated 2026-09-20T00:30:32

3 posts

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

hugovalters@mastodon.social at 2026-09-20T11:06:58.000Z ##

CVE-2026-94056 - Info disclosure in Exim allows attackers to read uninitialized stack memory via Proxy-Protocol. CVSS 7.5. Update to 4.100.1 or later now. #CVE #Exim #infosec

valtersit.com/cve/CVE-2026-940

##

thehackerwire@mastodon.social at 2026-09-20T00:01:08.000Z ##

🟠 CVE-2026-94056 - High (7.5)

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:01:08.000Z ##

🟠 CVE-2026-94056 - High (7.5)

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93992
(8.1 HIGH)

EPSS: 0.80%

updated 2026-09-20T00:30:32

2 posts

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations when users download and extract archives with AutoExtract enabled.

thehackerwire@mastodon.social at 2026-09-20T00:02:29.000Z ##

🟠 CVE-2026-93992 - High (8.1)

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory tra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:02:29.000Z ##

🟠 CVE-2026-93992 - High (8.1)

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory tra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93990
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-20T00:30:31

2 posts

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

thehackerwire@mastodon.social at 2026-09-20T00:01:16.000Z ##

🟠 CVE-2026-93990 - High (7.5)

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:01:16.000Z ##

🟠 CVE-2026-93990 - High (7.5)

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93991
(7.7 HIGH)

EPSS: 0.33%

updated 2026-09-19T23:17:10.360000

2 posts

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec

thehackerwire@mastodon.social at 2026-09-20T00:01:26.000Z ##

🟠 CVE-2026-93991 - High (7.7)

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:01:26.000Z ##

🟠 CVE-2026-93991 - High (7.7)

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88824
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-19T15:32:24

1 posts

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.

thehackerwire@mastodon.social at 2026-09-19T15:03:24.000Z ##

🟠 CVE-2026-88824 - High (8.8)

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92404
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-19T15:31:26

1 posts

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.

thehackerwire@mastodon.social at 2026-09-19T17:02:37.000Z ##

🟠 CVE-2026-92404 - High (7.5)

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, fr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88926
(8.6 HIGH)

EPSS: 0.26%

updated 2026-09-19T15:31:25

1 posts

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-09-19T17:02:28.000Z ##

🟠 CVE-2026-88926 - High (8.6)

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85680
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-19T15:31:24

1 posts

The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that will execute when any visitor, including an administrator, views their profile.

thehackerwire@mastodon.social at 2026-09-19T18:00:33.000Z ##

🟠 CVE-2026-85680 - High (8.8)

The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unaut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84750
(6.5 MEDIUM)

EPSS: 0.27%

updated 2026-09-19T15:31:24

1 posts

The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form fields, and stores them at a predictable public path with the attacker-chosen extension intact, allowing unauthenticated users to upload arbitrary files. The PHP handler shipped by default with the Debian and Ubuntu Apache packages maps .phar to PHP a

offseq@infosec.exchange at 2026-09-19T12:00:24.000Z ##

Ultra Addons for Contact Form 7 (<3.5.51) is vulnerable (CVE-2026-84750, CRITICAL). Unrestricted file upload enables unauthenticated RCE on Debian/Ubuntu Apache (.phar) or stored XSS. Upgrade to 3.5.51+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #RCE

##

CVE-2026-86591
(9.8 CRITICAL)

EPSS: 0.37%

updated 2026-09-19T15:31:23

2 posts

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the si

thehackerwire@mastodon.social at 2026-09-19T15:03:04.000Z ##

🔴 CVE-2026-86591 - Critical (9.8)

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T10:30:24.000Z ##

CVE-2026-86591 | CRITICAL | Botiga Pro <1.6.5 allows unauthenticated attackers to modify WP options, inject persistent XSS, and trash posts due to missing REST API authorization. Immediate upgrade to 1.6.5+ is essential. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202686591

##

CVE-2026-84082
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-09-19T15:17:05.647000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

thehackerwire@mastodon.social at 2026-09-19T21:00:44.000Z ##

🔴 CVE-2026-84082 - Critical (9.8)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T21:00:44.000Z ##

🔴 CVE-2026-84082 - Critical (9.8)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84078
(9.9 CRITICAL)

EPSS: 0.28%

updated 2026-09-19T15:17:05.430000

3 posts

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T20:00:46.000Z ##

🔴 CVE-2026-84078 - Critical (9.9)

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T20:00:46.000Z ##

🔴 CVE-2026-84078 - Critical (9.9)

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84070
(8.9 HIGH)

EPSS: 0.32%

updated 2026-09-19T15:17:04.867000

3 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T22:01:23.000Z ##

🟠 CVE-2026-84070 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T22:01:23.000Z ##

🟠 CVE-2026-84070 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84064
(9.9 CRITICAL)

EPSS: 0.37%

updated 2026-09-19T15:17:04.757000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

thehackerwire@mastodon.social at 2026-09-19T22:01:14.000Z ##

🔴 CVE-2026-84064 - Critical (9.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T22:01:14.000Z ##

🔴 CVE-2026-84064 - Critical (9.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82967
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-09-19T15:17:04.430000

3 posts

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-20T01:01:37.000Z ##

🔴 CVE-2026-82967 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T01:01:37.000Z ##

🔴 CVE-2026-82967 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82892
(8.1 HIGH)

EPSS: 0.39%

updated 2026-09-19T15:17:04.107000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-19T23:01:23.000Z ##

🟠 CVE-2026-82892 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T23:01:23.000Z ##

🟠 CVE-2026-82892 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82887
(8.8 HIGH)

EPSS: 0.41%

updated 2026-09-19T15:17:03.990000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-20T03:03:20.000Z ##

🟠 CVE-2026-82887 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T03:03:20.000Z ##

🟠 CVE-2026-82887 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80441
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-09-19T15:17:02.430000

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T03:03:29.000Z ##

🔴 CVE-2026-80441 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T03:03:29.000Z ##

🔴 CVE-2026-80441 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61817
(8.5 HIGH)

EPSS: 0.58%

updated 2026-09-19T15:16:59.910000

2 posts

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_config.time_dncoder text value without identifier quoting into dynamic SQL. A role with the documented partman_user privileges can store SQL rather than a decoder fu

thehackerwire@mastodon.social at 2026-09-20T20:00:52.000Z ##

🟠 CVE-2026-61817 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_config.time_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T20:00:52.000Z ##

🟠 CVE-2026-61817 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_config.time_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17619
(8.6 HIGH)

EPSS: 0.30%

updated 2026-09-19T15:16:58.713000

2 posts

IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

thehackerwire@mastodon.social at 2026-09-20T22:04:07.000Z ##

🟠 CVE-2026-17619 - High (8.6)

IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T22:04:07.000Z ##

🟠 CVE-2026-17619 - High (8.6)

IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11726
(8.1 HIGH)

EPSS: 0.46%

updated 2026-09-19T15:16:57.777000

2 posts

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

thehackerwire@mastodon.social at 2026-09-20T23:01:12.000Z ##

🟠 CVE-2026-11726 - High (8.1)

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T23:01:12.000Z ##

🟠 CVE-2026-11726 - High (8.1)

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84241
(8.1 HIGH)

EPSS: 0.30%

updated 2026-09-19T14:17:00.260000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-18T21:03:06.000Z ##

🟠 CVE-2026-84241 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84239
(7.6 HIGH)

EPSS: 0.41%

updated 2026-09-19T14:17:00.143000

3 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T19:00:35.000Z ##

🟠 CVE-2026-84239 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T19:00:35.000Z ##

🟠 CVE-2026-84239 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84108
(8.1 HIGH)

EPSS: 0.40%

updated 2026-09-19T14:17:00.037000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-09-19T18:00:53.000Z ##

🟠 CVE-2026-84108 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T18:00:53.000Z ##

🟠 CVE-2026-84108 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84085
(8.1 HIGH)

EPSS: 0.32%

updated 2026-09-19T14:16:59.587000

1 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-09-19T14:05:01.000Z ##

🟠 CVE-2026-84085 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93985
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-09-19T12:32:19

2 posts

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.

thehackerwire@mastodon.social at 2026-09-19T14:03:52.000Z ##

🔴 CVE-2026-93985 - Critical (9.9)

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T13:30:23.000Z ##

CVE-2026-93985 (CVSS 9.4) in Openpanel-dev openpanel v0: Critical code injection via JS webhook template validator. Attackers with project write access can run arbitrary code in the worker process. Limit permissions & monitor. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #AppSec

##

CVE-2026-53266
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-19T04:17:53.580000

8 posts

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Aski

1 repos

https://github.com/suominen/CVE-2026-53266

thecybermind at 2026-09-21T18:47:53.003Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53266 – Linux Kernel Out-of-Bounds Write Vulnerability

Analyze the executive impact of CVE-2026-53266 with our strategic Linux CSUITE brief, covering kernel out-of-bounds write risks, compliance assurance, and board-level risk communication....

thecybermind.co/n7ln

##

cyberworldops at 2026-09-21T10:40:00.916Z ##

CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential.

cyberworldops.eu/en/three-expl

##

aj@techhub.social at 2026-09-21T08:10:03.000Z ##

CISA warns 3 CVEs are under active exploitation in the wild:
- CVE-2025-39964 Linux Kernel Race Condition Vulnerability
- CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability
- CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Warning about attacks on Linux vulnerabilities | heise online
heise.de/en/news/Warning-about

#linux #security #cve

##

netsecio@mastodon.social at 2026-09-20T17:13:15.000Z ##

📰 CISA: Three Linux Kernel Flaws Actively Exploited in the Wild

CISA adds 3 actively exploited Linux kernel vulnerabilities to its KEV catalog. The flaws (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) can lead to privilege escalation or DoS. Federal agencies must patch by Sept 21. #Linux #Cybersecurity #KEV

🔗 cyber.netsecops.io/articles/ci

##

beyondmachines1 at 2026-09-20T15:01:13.354Z ##

CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.

**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**

beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-09-21T18:47:53.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53266 – Linux Kernel Out-of-Bounds Write Vulnerability

Analyze the executive impact of CVE-2026-53266 with our strategic Linux CSUITE brief, covering kernel out-of-bounds write risks, compliance assurance, and board-level risk communication....

thecybermind.co/n7ln

##

cyberworldops@infosec.exchange at 2026-09-21T10:40:00.000Z ##

CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV

cyberworldops.eu/en/three-expl

##

beyondmachines1@infosec.exchange at 2026-09-20T15:01:13.000Z ##

CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.

**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-92807
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-19T03:32:15

2 posts

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`button_`/non-`email_` shortcode attribute verbatim into a custom options array without sanitization, allowlist enforcement, or capability checks, and `cr

thehackerwire@mastodon.social at 2026-09-19T07:03:34.000Z ##

🟠 CVE-2026-92807 - High (8.8)

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T06:00:26.000Z ##

CVE-2026-92807: HIGH severity (CVSS 8.8) code injection in pdfcrowd Save as PDF Plugin for WordPress (<=4.6.1). Contributor+ users can run arbitrary PHP — risking API credential leaks & server compromise. Restrict access, monitor for patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec

##

CVE-2026-89274
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-09-19T03:32:09

2 posts

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the `reviewBody` field, which is populated verbatim from the `comment_content` of app

2 repos

https://github.com/Polosss/By-Poloss..-.CVE-2026-89274

https://github.com/murrez/CVE-2026-89274

thehackerwire@mastodon.social at 2026-09-19T07:04:14.000Z ##

🔴 CVE-2026-89274 - Critical (9.1)

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-19T03:00:23.000Z ##

WP Recipe Maker <=10.8.1 hit by CVE-2026-89274: CRITICAL code injection via unsanitized shortcodes in comment ratings. Unauthenticated attackers can trigger arbitrary shortcode execution on recipe pages. Upgrade ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202689274 #Infosec

##

CVE-2026-93923
(8.8 HIGH)

EPSS: 0.41%

updated 2026-09-19T00:32:50

1 posts

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.

thehackerwire@mastodon.social at 2026-09-19T08:03:31.000Z ##

🟠 CVE-2026-93923 - High (8.8)

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style va...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93922
(8.8 HIGH)

EPSS: 0.54%

updated 2026-09-19T00:16:57.913000

1 posts

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.

thehackerwire@mastodon.social at 2026-09-19T08:03:23.000Z ##

🟠 CVE-2026-93922 - High (8.8)

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaSc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75885
(9.3 CRITICAL)

EPSS: 0.41%

updated 2026-09-18T22:17:10.313000

2 posts

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests withou

offseq@infosec.exchange at 2026-09-19T00:00:37.000Z ##

CVE-2026-75885: CRITICAL SSRF & DoS in Red Hat OpenShift Container Platform 4. Unauthenticated access to /api/devfile/ endpoints can expose internal services & cause resource exhaustion. No fix yet — restrict access & monitor advisories. radar.offseq.com/threat/cve-20 #OffSeq #OpenShift #SSRF

##

thehackerwire@mastodon.social at 2026-09-18T23:00:58.000Z ##

🔴 CVE-2026-75885 - Critical (9.3)

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93738
(9.9 CRITICAL)

EPSS: 0.50%

updated 2026-09-18T21:32:44

1 posts

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

thehackerwire@mastodon.social at 2026-09-18T22:01:34.000Z ##

🔴 CVE-2026-93738 - Critical (9.9)

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88097
(8.1 HIGH)

EPSS: 0.22%

updated 2026-09-18T21:32:43

1 posts

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

thehackerwire@mastodon.social at 2026-09-18T22:02:05.000Z ##

🟠 CVE-2026-88097 - High (8.1)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93868
(8.1 HIGH)

EPSS: 0.61%

updated 2026-09-18T21:32:41

1 posts

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and probe them against the passrecover authentication endpoint to reset any account pas

thehackerwire@mastodon.social at 2026-09-18T21:01:38.000Z ##

🟠 CVE-2026-93868 - High (8.1)

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84077
(8.1 HIGH)

EPSS: 0.19%

updated 2026-09-18T21:32:40

2 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

thehackerwire@mastodon.social at 2026-09-19T20:00:36.000Z ##

🟠 CVE-2026-84077 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T20:00:36.000Z ##

🟠 CVE-2026-84077 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93839
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-18T21:32:40

1 posts

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to int

cR0w@infosec.exchange at 2026-09-18T21:38:13.000Z ##

Go hack more LLM shit.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.

##

CVE-2026-84089
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-18T21:32:39

2 posts

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T14:05:11.000Z ##

🟠 CVE-2026-84089 - High (7.8)

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84075
(9.9 CRITICAL)

EPSS: 0.35%

updated 2026-09-18T21:32:39

3 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T19:00:47.000Z ##

🔴 CVE-2026-84075 - Critical (9.9)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T19:00:47.000Z ##

🔴 CVE-2026-84075 - Critical (9.9)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84076
(7.6 HIGH)

EPSS: 0.31%

updated 2026-09-18T21:32:39

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

thehackerwire@mastodon.social at 2026-09-19T19:00:59.000Z ##

🟠 CVE-2026-84076 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T19:00:59.000Z ##

🟠 CVE-2026-84076 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84084
(8.8 HIGH)

EPSS: 0.18%

updated 2026-09-18T21:32:39

1 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

thehackerwire@mastodon.social at 2026-09-19T08:03:40.000Z ##

🟠 CVE-2026-84084 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84031
(9.0 None)

EPSS: 0.33%

updated 2026-09-18T21:32:38

3 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T21:01:06.000Z ##

🔴 CVE-2026-84031 - Critical (9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T21:01:06.000Z ##

🔴 CVE-2026-84031 - Critical (9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84074
(8.9 HIGH)

EPSS: 0.32%

updated 2026-09-18T21:32:38

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-09-19T23:01:13.000Z ##

🟠 CVE-2026-84074 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T23:01:13.000Z ##

🟠 CVE-2026-84074 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84083
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-18T21:32:38

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute arbitrary commands as root, resulting in full compromise of the Collector appliance.

thehackerwire@mastodon.social at 2026-09-19T21:00:56.000Z ##

🟠 CVE-2026-84083 - High (7.8)

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T21:00:56.000Z ##

🟠 CVE-2026-84083 - High (7.8)

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84105
(7.7 HIGH)

EPSS: 0.35%

updated 2026-09-18T21:32:38

1 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

thehackerwire@mastodon.social at 2026-09-19T14:05:21.000Z ##

🟠 CVE-2026-84105 - High (7.7)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84081
(8.1 HIGH)

EPSS: 0.20%

updated 2026-09-18T21:32:37

3 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

infosecbot@mastodon.hofud.com at 2026-09-20T04:14:30.000Z ##

[1/3]

High‑impact security incidents ( CVSS ≥ 7 ) reported between 2026‑09‑18 and today

CVE‑2026‑84241
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker can bypass security restrictions because the product performs improper authorization checks.
thehackerwire.com/vulnerabilit

CVE‑2026‑84078
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• Missing authentication in the LoadBalanc… component allows unauthenticated remote code execution.
stemshop.top/cve/CVE-2026-84078

CVE‑2026‑84075
• 9.9 (Critical)
• IBM Guardium Data Protection 12.2
• The ChangeTrackerServlet lacks authentication, enabling a remote attacker to bypass all security controls.
thehackerwire.com/vulnerabilit

CVE‑2026‑84070
• 8.9 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code via improper input neutralisation during page generation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84031
• 9.0 (Critical)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can execute arbitrary code because of improper input sanitisation in web pages.
thehackerwire.com/vulnerabilit

CVE‑2026‑84089
• 7.8 (High)
• IBM Guardium Data Protection 12.2
• Local attacker can obtain elevated privileges due to flawed privilege‑management logic.
thehackerwire.com/vulnerabilit

CVE‑2026‑84081
• 8.1 (High)
• IBM Guardium Data Protection 12.2
• Remote attacker bypasses security restrictions because of improper certificate validation.
thehackerwire.com/vulnerabilit

CVE‑2026‑84239
• 7.6 (High)
• IBM Guardium Data Protection 12.2
• Authenticated remote attacker can harvest sensitive data; the flaw stems from improper neutralisation of special SQL elements.
thehackerwire.com/vulnerabilit

CVE‑2026‑82967
• 9.8 (Critical)
• IBM Guardium Data Protection 12.2
• Authentication bypass permits unauthenticated remote attackers to gain full access.
thehackerwire.com/vulnerabilit

#infosecnews

##

thehackerwire@mastodon.social at 2026-09-19T20:01:01.000Z ##

🟠 CVE-2026-84081 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T20:01:01.000Z ##

🟠 CVE-2026-84081 - High (8.1)

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82896
(7.6 HIGH)

EPSS: 0.36%

updated 2026-09-18T21:32:37

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

thehackerwire@mastodon.social at 2026-09-20T01:01:26.000Z ##

🟠 CVE-2026-82896 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T01:01:26.000Z ##

🟠 CVE-2026-82896 - High (7.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84073
(9.1 CRITICAL)

EPSS: 0.26%

updated 2026-09-18T21:32:37

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

thehackerwire@mastodon.social at 2026-09-19T23:01:04.000Z ##

🔴 CVE-2026-84073 - Critical (9.1)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T23:01:04.000Z ##

🔴 CVE-2026-84073 - Critical (9.1)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84034
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-18T21:32:37

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.

thehackerwire@mastodon.social at 2026-09-19T22:00:57.000Z ##

🟠 CVE-2026-84034 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthoriz...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T22:00:57.000Z ##

🟠 CVE-2026-84034 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthoriz...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82885
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-18T21:32:36

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

thehackerwire@mastodon.social at 2026-09-20T03:03:11.000Z ##

🟠 CVE-2026-82885 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T03:03:11.000Z ##

🟠 CVE-2026-82885 - High (8.8)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82832
(9.6 CRITICAL)

EPSS: 0.38%

updated 2026-09-18T21:32:36

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-09-20T02:02:45.000Z ##

🔴 CVE-2026-82832 - Critical (9.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T02:02:45.000Z ##

🔴 CVE-2026-82832 - Critical (9.6)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82893
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-18T21:32:36

2 posts

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

thehackerwire@mastodon.social at 2026-09-20T00:02:51.000Z ##

🟠 CVE-2026-82893 - High (7.8)

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T00:02:51.000Z ##

🟠 CVE-2026-82893 - High (7.8)

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75878
(9.1 CRITICAL)

EPSS: 0.48%

updated 2026-09-18T21:32:35

2 posts

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

thehackerwire@mastodon.social at 2026-09-20T18:01:11.000Z ##

🔴 CVE-2026-75878 - Critical (9.1)

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T18:01:11.000Z ##

🔴 CVE-2026-75878 - Critical (9.1)

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81656
(8.8 HIGH)

EPSS: 0.29%

updated 2026-09-18T21:32:35

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T18:00:51.000Z ##

🟠 CVE-2026-81656 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resultin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T18:00:51.000Z ##

🟠 CVE-2026-81656 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resultin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80442
(9.9 CRITICAL)

EPSS: 0.63%

updated 2026-09-18T21:32:35

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T17:03:57.000Z ##

🔴 CVE-2026-80442 - Critical (9.9)

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confiden...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T17:03:57.000Z ##

🔴 CVE-2026-80442 - Critical (9.9)

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confiden...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82340
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-18T21:32:35

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution in the Guardium appliance.

thehackerwire@mastodon.social at 2026-09-20T02:02:35.000Z ##

🔴 CVE-2026-82340 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T02:02:35.000Z ##

🔴 CVE-2026-82340 - Critical (9.8)

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11716
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-18T21:32:28

2 posts

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

thehackerwire@mastodon.social at 2026-09-20T23:01:21.000Z ##

🟠 CVE-2026-11716 - High (7.5)

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T23:01:21.000Z ##

🟠 CVE-2026-11716 - High (7.5)

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11727
(8.1 HIGH)

EPSS: 0.61%

updated 2026-09-18T21:32:28

2 posts

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.

thehackerwire@mastodon.social at 2026-09-20T22:04:17.000Z ##

🟠 CVE-2026-11727 - High (8.1)

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T22:04:17.000Z ##

🟠 CVE-2026-11727 - High (8.1)

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-39682
(7.1 HIGH)

EPSS: 1.20%

updated 2026-09-18T21:31:33

8 posts

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted

2 repos

https://github.com/khoatran107/cve-2025-39682

https://github.com/suominen/CVE-2025-39682

cyberworldops at 2026-09-21T10:40:00.916Z ##

CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential.

cyberworldops.eu/en/three-expl

##

aj@techhub.social at 2026-09-21T08:10:03.000Z ##

CISA warns 3 CVEs are under active exploitation in the wild:
- CVE-2025-39964 Linux Kernel Race Condition Vulnerability
- CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability
- CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Warning about attacks on Linux vulnerabilities | heise online
heise.de/en/news/Warning-about

#linux #security #cve

##

netsecio@mastodon.social at 2026-09-20T17:13:15.000Z ##

📰 CISA: Three Linux Kernel Flaws Actively Exploited in the Wild

CISA adds 3 actively exploited Linux kernel vulnerabilities to its KEV catalog. The flaws (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) can lead to privilege escalation or DoS. Federal agencies must patch by Sept 21. #Linux #Cybersecurity #KEV

🔗 cyber.netsecops.io/articles/ci

##

undercodenews@mastodon.social at 2026-09-20T16:59:04.000Z ##

CISA Adds Three Exploited Linux Kernel Vulnerabilities to Its KEV Catalog as Federal Patch Deadline Looms + Video

A New Linux Kernel Security Warning The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, placing fresh pressure on organizations to identify affected systems and deploy available fixes. The vulnerabilities are CVE-2025-39682, CVE-2025-39964, and…

undercodenews.com/cisa-adds-th

##

beyondmachines1 at 2026-09-20T15:01:13.354Z ##

CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.

**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**

beyondmachines.net/event_detai

##

Matchbook3469@mastodon.social at 2026-09-19T18:28:22.000Z ##

🔵 THREAT INTELLIGENCE

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

Vulnerability | CRITICAL
CVEs: CVE-2025-39682

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known...

Full analysis:
yazoul.net/news/article/cisa-f

by Yazoul AI

#ThreatIntel #SecurityNews #CyberNews

##

cyberworldops@infosec.exchange at 2026-09-21T10:40:00.000Z ##

CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV

cyberworldops.eu/en/three-expl

##

beyondmachines1@infosec.exchange at 2026-09-20T15:01:13.000Z ##

CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.

**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-84106
(8.9 HIGH)

EPSS: 0.32%

updated 2026-09-18T21:18:44.520000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

thehackerwire@mastodon.social at 2026-09-19T18:00:43.000Z ##

🟠 CVE-2026-84106 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-19T18:00:43.000Z ##

🟠 CVE-2026-84106 - High (8.9)

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71418
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-18T21:18:08.590000

1 posts

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame contents instead of clearing the internal buffer. Multiple DATA frames with the EndOfStream flag set can grow the buffer to its 65 KiB limit while causing al

thehackerwire@mastodon.social at 2026-09-18T22:02:15.000Z ##

🟠 CVE-2026-71418 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame cont...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61781
(9.9 CRITICAL)

EPSS: 0.57%

updated 2026-09-18T21:17:02.257000

2 posts

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with the documented partman_user INSERT and UPDATE privileges can store SQL rather than a function name. When pg_partman_

thehackerwire@mastodon.social at 2026-09-20T19:01:06.000Z ##

🔴 CVE-2026-61781 - Critical (9.9)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T19:01:06.000Z ##

🔴 CVE-2026-61781 - Critical (9.9)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92708
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-18T20:17:30.150000

1 posts

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing ArrayBuffer rather than only the view, so serializing a Node Buffer, whose backing store is a process-wide shared pool, discloses up to 64 KB of unrelated p

thehackerwire@mastodon.social at 2026-09-18T21:02:57.000Z ##

🟠 CVE-2026-92708 - High (7.5)

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing Arr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81933
(8.8 HIGH)

EPSS: 0.32%

updated 2026-09-18T20:17:24.250000

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T01:01:47.000Z ##

🟠 CVE-2026-81933 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T01:01:47.000Z ##

🟠 CVE-2026-81933 - High (8.8)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81657
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-09-18T20:17:23.997000

2 posts

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

thehackerwire@mastodon.social at 2026-09-20T18:01:01.000Z ##

🔴 CVE-2026-81657 - Critical (9.8)

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T18:01:01.000Z ##

🔴 CVE-2026-81657 - Critical (9.8)

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81626
(8.6 HIGH)

EPSS: 0.27%

updated 2026-09-18T20:17:23.723000

2 posts

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.

thehackerwire@mastodon.social at 2026-09-20T17:04:07.000Z ##

🟠 CVE-2026-81626 - High (8.6)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T17:04:07.000Z ##

🟠 CVE-2026-81626 - High (8.6)

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81179
(8.1 HIGH)

EPSS: 0.26%

updated 2026-09-18T20:17:23.470000

2 posts

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password reset link. An unauthenticated attacker can request a reset email whose link points to an attacker-controlled system, and a victim who follows that link

thehackerwire@mastodon.social at 2026-09-21T01:03:02.000Z ##

🟠 CVE-2026-81179 - High (8.1)

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T01:03:02.000Z ##

🟠 CVE-2026-81179 - High (8.1)

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61714
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-18T20:17:18.270000

2 posts

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active channels. The resulting out-of-bounds reads and writes invoke undefined behavior and may compromise confidentiality, integrity, o

thehackerwire@mastodon.social at 2026-09-20T21:01:11.000Z ##

🟠 CVE-2026-61714 - High (7.8)

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T21:01:11.000Z ##

🟠 CVE-2026-61714 - High (7.8)

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58264
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-09-18T20:17:18.107000

2 posts

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth channel. An out-of-range channel can therefore cause an out-of-bounds heap write, leading to denial of service or possible

thehackerwire@mastodon.social at 2026-09-20T21:01:01.000Z ##

🔴 CVE-2026-58264 - Critical (9.8)

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is writt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T21:01:01.000Z ##

🔴 CVE-2026-58264 - Critical (9.8)

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is writt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11725
(8.8 HIGH)

EPSS: 0.40%

updated 2026-09-18T20:17:03.167000

2 posts

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

thehackerwire@mastodon.social at 2026-09-20T22:04:27.000Z ##

🟠 CVE-2026-11725 - High (8.8)

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T22:04:27.000Z ##

🟠 CVE-2026-11725 - High (8.8)

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89308
(0 None)

EPSS: 2.97%

updated 2026-09-18T19:24:36.593000

2 posts

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

secdb at 2026-09-21T00:01:46.493Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-59569
(8.1 HIGH)

EPSS: 0.12%

updated 2026-09-18T19:08:02.707000

1 posts

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

hugovalters@mastodon.social at 2026-09-21T12:10:38.000Z ##

CVE-2026-59569: improper input validation in Zscaler Client Connector on Android and ChromeOS lets an attacker bypass Zscaler controls. CVSS 8.1, no patch yet. Check exposure and mitigate now. valtersit.com/cve/CVE-2026-595 #CVE #infosec #Zscaler

##

CVE-2026-93748
(7.5 HIGH)

EPSS: 0.40%

updated 2026-09-18T18:32:07

2 posts

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zero

thehackerwire@mastodon.social at 2026-09-20T23:01:32.000Z ##

🟠 CVE-2026-93748 - High (7.5)

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can reques...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T23:01:32.000Z ##

🟠 CVE-2026-93748 - High (7.5)

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can reques...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93759
(8.6 HIGH)

EPSS: 0.24%

updated 2026-09-18T18:32:04

1 posts

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field value

hugovalters@mastodon.social at 2026-09-21T10:40:01.000Z ##

CVE-2026-93759 Mongoid query builder passes string criteria as server-side JS, enabling unauthenticated RCE by injection. CVSS 8.6, no patch yet. Audit your query inputs now. valtersit.com/cve/CVE-2026-937 #CVE #infosec #Mongoid

##

CVE-2026-93762
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-09-18T18:32:01

2 posts

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.

DailyCyberSecurity at 2026-09-21T01:16:31.676Z ##

Critical MongoDB driver vulnerabilities, including CVE-2026-93762, expose systems to data loss and DoS. Learn about these flaws and patch immediately.

securityonline.info/mongodb-dr

##

DailyCyberSecurity@infosec.exchange at 2026-09-21T01:16:31.000Z ##

Critical MongoDB driver vulnerabilities, including CVE-2026-93762, expose systems to data loss and DoS. Learn about these flaws and patch immediately.

#MongoDB #Cybersecurity #Vulnerability #Infosec #CVE

securityonline.info/mongodb-dr

##

CVE-2026-10858
(9.9 CRITICAL)

EPSS: 0.33%

updated 2026-09-18T18:31:53

2 posts

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.

DailyCyberSecurity at 2026-09-20T19:21:35.987Z ##

Critical IBM MQ vulnerabilities allow remote code execution. Learn how CVE-2026-10747 and CVE-2026-10858 hit 10.0 CVSS and require urgent patching.

securityonline.info/ibm-mq-vul

##

DailyCyberSecurity@infosec.exchange at 2026-09-20T19:21:35.000Z ##

Critical IBM MQ vulnerabilities allow remote code execution. Learn how CVE-2026-10747 and CVE-2026-10858 hit 10.0 CVSS and require urgent patching.

#IBMMQ #CVE202610747 #CVE202610858 #Cybersecurity #Infosec

securityonline.info/ibm-mq-vul

##

CVE-2026-93749
(7.5 HIGH)

EPSS: 0.35%

updated 2026-09-18T18:18:33.480000

3 posts

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event loop blocking for extended periods, preventing the service from handling other requests.

hugovalters@mastodon.social at 2026-09-21T18:40:12.000Z ##

CVE-2026-93749: source-map-js thru 1.2.1 fails to validate section offset line values in indexed source maps. Crafted input blocks the event loop, causing DoS. CVSS 7.5. No patch yet. Update immediately or restrict valtersit.com/cve/CVE-2026-937 #CVE #infosec #cybersecurity

##

thehackerwire@mastodon.social at 2026-09-21T00:01:08.000Z ##

🟠 CVE-2026-93749 - High (7.5)

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event lo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T00:01:08.000Z ##

🟠 CVE-2026-93749 - High (7.5)

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event lo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85058
(7.5 HIGH)

EPSS: 0.27%

updated 2026-09-18T18:17:17.447000

2 posts

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths. When anonymous access is enabled and topic ACLs restrict writes, a remote client can set an ACL-protected topic as the Last Will Topic during CONNECT and perform

thehackerwire@mastodon.social at 2026-09-21T01:02:52.000Z ##

🟠 CVE-2026-85058 - High (7.5)

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths. When ano...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T01:02:52.000Z ##

🟠 CVE-2026-85058 - High (7.5)

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths. When ano...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81180
(8.8 HIGH)

EPSS: 0.36%

updated 2026-09-18T18:17:15.930000

2 posts

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can combine that behavior with a race involving GnuPG configuration files in temporary subdirectories to

thehackerwire@mastodon.social at 2026-09-21T06:04:18.000Z ##

🟠 CVE-2026-81180 - High (8.8)

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T06:04:18.000Z ##

🟠 CVE-2026-81180 - High (8.8)

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69184
(7.5 HIGH)

EPSS: 0.68%

updated 2026-09-18T18:17:11.477000

2 posts

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response containing a long descending pointer chain and many resource records whose NAME or RDATA fields refer to the chain, causing repeated decompression work that grows

thehackerwire@mastodon.social at 2026-09-21T06:04:28.000Z ##

🟠 CVE-2026-69184 - High (7.5)

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response containing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T06:04:28.000Z ##

🟠 CVE-2026-69184 - High (7.5)

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response containing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91127
(8.2 HIGH)

EPSS: 0.24%

updated 2026-09-18T17:19:44

2 posts

### Summary Before 2.3.1, the legacy `.doc` renderer emitted document hyperlink targets after HTML escaping but without a URL-scheme allowlist. A crafted `.doc` could therefore render a live `javascript:`, `vbscript:`, `data:`, or similarly unsafe link. Script could execute in the embedding origin if a viewer clicked it. ### Impact Applications rendering untrusted legacy `.doc` files with `@fil

thehackerwire@mastodon.social at 2026-09-21T01:02:43.000Z ##

🟠 CVE-2026-91127 - High (8.2)

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled hyperlink t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T01:02:43.000Z ##

🟠 CVE-2026-91127 - High (8.2)

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled hyperlink t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81916
(4.3 MEDIUM)

EPSS: 0.20%

updated 2026-09-18T15:31:47

1 posts

Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route. As a result, a user permitted to add entries to one Express object could create entries in a different Express object outside their authorization scope, potentially polluting protected datasets, triggering workfl

hugovalters@mastodon.social at 2026-09-20T11:50:02.000Z ##

CVE-2026-81916 Concrete CMS before 9.5.3: broken authorization lets users write to Express objects outside their scope, enabling data pollution and content injection. No CVSS or patch info yet. Update to valtersit.com/cve/CVE-2026-819 #CVE #infosec #ConcreteCMS

##

CVE-2025-39964
(3.3 LOW)

EPSS: 0.79%

updated 2026-09-18T15:31:06

9 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates

2 repos

https://github.com/n1k0oowang/CVE-2025-39964_EXP

https://github.com/suominen/CVE-2025-39964

thecybermind at 2026-09-21T12:02:57.249Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2025-39964 – Linux Kernel Race Condition Vulnerability

Analyze the mechanics of CVE-2025-39964 with our technical Linux TSUITE brief, covering AF_ALG race conditions, CrowdStrike CQL queries, and endpoint hardening....

thecybermind.co/dxag

##

cyberworldops at 2026-09-21T10:40:00.916Z ##

CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential.

cyberworldops.eu/en/three-expl

##

aj@techhub.social at 2026-09-21T08:10:03.000Z ##

CISA warns 3 CVEs are under active exploitation in the wild:
- CVE-2025-39964 Linux Kernel Race Condition Vulnerability
- CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability
- CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Warning about attacks on Linux vulnerabilities | heise online
heise.de/en/news/Warning-about

#linux #security #cve

##

netsecio@mastodon.social at 2026-09-20T17:13:15.000Z ##

📰 CISA: Three Linux Kernel Flaws Actively Exploited in the Wild

CISA adds 3 actively exploited Linux kernel vulnerabilities to its KEV catalog. The flaws (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) can lead to privilege escalation or DoS. Federal agencies must patch by Sept 21. #Linux #Cybersecurity #KEV

🔗 cyber.netsecops.io/articles/ci

##

undercodenews@mastodon.social at 2026-09-20T16:59:04.000Z ##

CISA Adds Three Exploited Linux Kernel Vulnerabilities to Its KEV Catalog as Federal Patch Deadline Looms + Video

A New Linux Kernel Security Warning The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, placing fresh pressure on organizations to identify affected systems and deploy available fixes. The vulnerabilities are CVE-2025-39682, CVE-2025-39964, and…

undercodenews.com/cisa-adds-th

##

beyondmachines1 at 2026-09-20T15:01:13.354Z ##

CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.

**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**

beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-09-21T12:02:57.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2025-39964 – Linux Kernel Race Condition Vulnerability

Analyze the mechanics of CVE-2025-39964 with our technical Linux TSUITE brief, covering AF_ALG race conditions, CrowdStrike CQL queries, and endpoint hardening....

thecybermind.co/dxag

##

cyberworldops@infosec.exchange at 2026-09-21T10:40:00.000Z ##

CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV

cyberworldops.eu/en/three-expl

##

beyondmachines1@infosec.exchange at 2026-09-20T15:01:13.000Z ##

CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities catalog, requiring immediate patching and review. These flaws allow for remote exploitation of kTLS and local privilege escalation through netfilter and cryptographic interfaces.

**Update your Linux systems to the fixed kernel version from your vendor (check their advisory, not `uname -r`) and reboot. Prioritise anything internet-facing or where untrusted or external code runs, such as Kubernetes nodes, CI runners, shared hosting and jump boxes. Because these flaws are already being exploited, also check those systems for signs of a break-in like unexpected privilege changes or unusual user namespace activity. If you can't patch, confirm the affected modules (kTLS, ebtables SNAT, AF_ALG) are unused and block them as a temporary measure.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-20283
(6.5 MEDIUM)

EPSS: 0.43%

updated 2026-09-18T13:28:28.567000

2 posts

A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system.&nbsp; This vulnerability is due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could exploit this vulnerability by sending crafted input to the IPsec Open API endpoint on an affected dev

cyberworldops at 2026-09-21T02:20:00.338Z ##

Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise.

cyberworldops.eu/en/cisco-fixe

##

cyberworldops@infosec.exchange at 2026-09-21T02:20:00.000Z ##

Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise. #CiscoSecurity #NetworkSecurity #VulnManagement

cyberworldops.eu/en/cisco-fixe

##

CVE-2026-85889
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-09-18T00:31:16

2 posts

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

security_crawler_carl at 2026-09-20T22:43:27.736Z ##

CVE-2026-85889 in Microsoft's Azure AI Foundry enabled unauthorized privilege escalation at the highest possible severity rating, discovered by researcher Rémy Marot and quietly fixed before a single attacker could find it in the wild.

The good news — and do write this down — no customer action is required. Microsoft has fully mitigated the issue on their end. This concludes the portion of the training where you feel relief. Please do not grow accustomed to it. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-20T22:43:27.000Z ##

CVE-2026-85889 in Microsoft's Azure AI Foundry enabled unauthorized privilege escalation at the highest possible severity rating, discovered by researcher Rémy Marot and quietly fixed before a single attacker could find it in the wild.

The good news — and do write this down — no customer action is required. Microsoft has fully mitigated the issue on their end. This concludes the portion of the training where you feel relief. Please do not grow accustomed to it. (2/3)

##

CVE-2026-90426(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-09-17T18:33:37

1 posts

In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq(). Tearing a VINTF down frees vintf0 and clears cmdqv->vintfs[0]. An error in that window makes tegra241_cmdqv_isr() read the stale slot and hand it to tegra241_vintf0_handle_error(), which

sigint@fosstodon.org at 2026-09-20T23:45:06.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-09-21

Another kernel fix rolling into Ubuntu's queue. With public root exploits already circulating for other recent kernel bugs, don't let these OSV entries pile up unpatched on your homelab boxes.

🔗 vulners.com/osv/OSV:UBUNTU-CVE

#Ubuntu #Linux #infosec

##

CVE-2026-58704
(8.8 HIGH)

EPSS: 0.21%

updated 2026-09-17T04:17:54.930000

2 posts

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

hackmag at 2026-09-21T15:30:23.819Z ##

⚪️ Google Patches Zero-Day Vulnerability in Pixel Devices

🗨️ Google has released September patches for Pixel smartphones, fixing 110 vulnerabilities. Among them is a zero-day flaw found in the cellular modem (CVE-2026-58704). The company warned that the issue is already being exploited by hackers in targeted attacks. CVE-2026-58704 has…

🔗 hackmag.com/news/pixel-0-day?u

##

hackmag@infosec.exchange at 2026-09-21T15:30:23.000Z ##

⚪️ Google Patches Zero-Day Vulnerability in Pixel Devices

🗨️ Google has released September patches for Pixel smartphones, fixing 110 vulnerabilities. Among them is a zero-day flaw found in the cellular modem (CVE-2026-58704). The company warned that the issue is already being exploited by hackers in targeted attacks. CVE-2026-58704 has…

🔗 hackmag.com/news/pixel-0-day?u

#news

##

CVE-2026-20306
(9.1 CRITICAL)

EPSS: 1.37%

updated 2026-09-17T04:17:40.777000

1 posts

A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit thi

security_crawler_carl@infosec.exchange at 2026-09-19T15:43:41.000Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

CVE-2026-20305
(9.1 CRITICAL)

EPSS: 1.37%

updated 2026-09-17T04:17:40.540000

1 posts

A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to&nbsp;root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker coul

security_crawler_carl@infosec.exchange at 2026-09-19T15:43:41.000Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

CVE-2026-76460
(10.0 CRITICAL)

EPSS: 0.78%

updated 2026-09-16T21:33:00

5 posts

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized acce

1 repos

https://github.com/S3v3n-JG/CVE-2026-76460

Analyst207@mastodon.social at 2026-09-21T14:50:00.000Z ##

Cisco Zero-Day Exploited in Active Attacks

Cisco is warning of a critical zero-day flaw in its Identity Services Engine (ISE) that's being actively exploited, allowing attackers to bypass authentication and gain unauthorized access with just a crafted request. This severe vulnerability, tracked as CVE-2026-76460, has been assigned a maximum CVSS score of 10.0.

osintsights.com/cisco-zero-day

#Cisco #ZeroDay #Cve202676460 #IdentityServicesEngine #Ise

##

threatnoir at 2026-09-20T05:15:05.721Z ##

2026-W38 — Weekly Threat Roundup

🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…

threatnoir.com/weekly/2026-w38

🤖 AI generated summary

##

tierrasapiens@mastodon.social at 2026-09-19T22:57:11.000Z ##

🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Cisco Zero-Day Highlights API Endpoint Authentication Issues
🔗 darkreading.com/vulnerabilitie

The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.

##

threatnoir@infosec.exchange at 2026-09-20T05:15:05.000Z ##

2026-W38 — Weekly Threat Roundup

🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…

threatnoir.com/weekly/2026-w38

#infosec #cybersecurity #threatintel

🤖 AI generated summary

##

security_crawler_carl@infosec.exchange at 2026-09-19T15:43:41.000Z ##

CVE-2026-76460 scores a perfect 10 out of 10 — which is, tragically, the only perfect score on this report card. Two companion command-injection flaws, CVE-2026-20306 and CVE-2026-20305, round out the disclosure. Active exploitation is confirmed. Attackers can delete their own footprints from the device, so the auditors won't find anything. Convenient for them. (2/3)

##

CVE-2026-20284
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-09-16T21:32:50

2 posts

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underl

cyberworldops at 2026-09-21T02:20:00.338Z ##

Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise.

cyberworldops.eu/en/cisco-fixe

##

cyberworldops@infosec.exchange at 2026-09-21T02:20:00.000Z ##

Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise. #CiscoSecurity #NetworkSecurity #VulnManagement

cyberworldops.eu/en/cisco-fixe

##

CVE-2026-20282
(4.9 MEDIUM)

EPSS: 0.56%

updated 2026-09-16T21:32:50

2 posts

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain write ac

cyberworldops at 2026-09-21T02:20:00.338Z ##

Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise.

cyberworldops.eu/en/cisco-fixe

##

cyberworldops@infosec.exchange at 2026-09-21T02:20:00.000Z ##

Cisco patched 20 CVEs in ISE (12 critical), 18 in FMC (8 critical) and 6 in Nexus Dashboard. Three ISE flaws CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 are exploited, allowing takeover of identity and firewall management. Patch immediately and hunt for compromise. #CiscoSecurity #NetworkSecurity #VulnManagement

cyberworldops.eu/en/cisco-fixe

##

CVE-2026-27561
(7.2 HIGH)

EPSS: 2.23%

updated 2026-09-16T19:17:13.633000

2 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

secdb at 2026-09-21T00:01:46.493Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-27560
(7.2 HIGH)

EPSS: 2.23%

updated 2026-09-16T19:17:13.420000

2 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.

secdb at 2026-09-21T00:01:46.493Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-92397
(9.1 CRITICAL)

EPSS: 2.30%

updated 2026-09-16T18:32:09

2 posts

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

secdb at 2026-09-21T00:01:46.493Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-92398
(9.1 CRITICAL)

EPSS: 2.47%

updated 2026-09-16T18:32:09

2 posts

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Name results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

secdb at 2026-09-21T00:01:46.493Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-91843
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-09-16T15:31:14

2 posts

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

1 repos

https://github.com/HORKimhab/CVE-2026-91843

threatnoir at 2026-09-20T05:15:05.721Z ##

2026-W38 — Weekly Threat Roundup

🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…

threatnoir.com/weekly/2026-w38

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-20T05:15:05.000Z ##

2026-W38 — Weekly Threat Roundup

🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…

threatnoir.com/weekly/2026-w38

#infosec #cybersecurity #threatintel

🤖 AI generated summary

##

CVE-2026-27562
(7.2 HIGH)

EPSS: 2.23%

updated 2026-09-16T09:30:34

2 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.

secdb at 2026-09-21T00:01:46.493Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-77179(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-09-16T00:32:25

1 posts

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

1 repos

https://github.com/HORKimhab/CVE-2026-77179

_r_netsec@infosec.exchange at 2026-09-19T06:28:04.000Z ##

CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes) accomplish.ai/blog/escaping-do

##

CVE-2026-76698
(6.5 MEDIUM)

EPSS: 4.11%

updated 2026-09-15T21:31:36

2 posts

A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could exploit this vulnerability through specially crafted input. Successful exploitation, under certain conditions, could result in the execution of arbitrary commands with elevated privileges or a denial-of-s

secdb at 2026-09-21T00:01:46.493Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-90703
(9.1 CRITICAL)

EPSS: 2.80%

updated 2026-09-15T18:19:38.113000

2 posts

A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

secdb at 2026-09-21T00:01:46.493Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-89267
(4.3 MEDIUM)

EPSS: 0.19%

updated 2026-09-15T17:17:36.800000

1 posts

starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.

hugovalters@mastodon.social at 2026-09-19T21:50:23.000Z ##

CVE-2026-89267: Starlette-Admin 0.16.1-0.17.1 ignores empty searchable_fields allowlists, letting authenticated users query excluded columns via the where parameter. CVSS 4.3, patch status unknown. Audit valtersit.com/cve/CVE-2026-892 #CVE #infosec #cybersecurity

##

CVE-2026-90439
(6.5 MEDIUM)

EPSS: 0.26%

updated 2026-09-15T15:32:20

2 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker proc

fosserytech@social.linux.pizza at 2026-09-20T10:45:37.000Z ##

(more Linux and FOSS news in previous posts of thread)

Zed v1.20 adds Markdown previews and custom window titles:
alternativeto.net/news/2026/9/

Rune (IDE with AI capabilities) Goes Open Source, Looks to Share Revenue With Contributors:
feed.itsfoss.com/link/24361/17

Microsoft’s open-source CLI text editor adds syntax highlighting:
omgubuntu.co.uk/2026/09/micros

Java 27 brings major post-quantum security leap, G1 garbage collector by default, and more:
alternativeto.net/news/2026/9/

Swift 6.4 brings better interoperability, faster performance, and Swift Build by default:
alternativeto.net/news/2026/9/

MariaDB 13.0.2 Now Stable: DuckDB Engine and What Changes:
linuxcompatible.org/story/mari

Laravel MCP 1.0 brings searchable tools to agents:
alternativeto.net/news/2026/9/

Mojo 1.1 Released, Now Accepting Community Contributions To The Compiler:
phoronix.com/news/Mojo-1.1-Rel

Rust Issues Warning Over Key Developers Being Targeted For Compromise:
phoronix.com/news/Rust-Develop

Rustls 0.23.45 Released To Fix Two Year Old Security Issue:
phoronix.com/news/Rustls-0.23.

NGINX 1.30.5 and 1.31.6 Released: Patch for HTTP/3 Buffer Overflow (CVE-2026-90439):
linuxcompatible.org/story/ngin

Nextcloud Hub 26 Summer adds Teams workspaces and brings Euro-Office to desktop:
alternativeto.net/news/2026/9/

GrapheneOS Isn't Happy With Google Over Pixel's Widening Head Start:
feed.itsfoss.com/link/24361/17

VirtualBox 7.2.18 Released with Linux 7.3 Fixes, Support for RHEL 10.3 Kernel:
9to5linux.com/virtualbox-7-2-1

Valve Quietly Open-Sources Its Android Compatibility Layer:
feed.itsfoss.com/link/24361/17

SDL3 Ported To HarmonyOS / OpenHarmony:
phoronix.com/news/SDL3-Ported-

#WeeklyNews #OpenSource #FOSSNews #FOSS #OpenSourceNews #News #Zed #RuneIDE #IDE #TextEditor #Java #Swift #MariaDB #Laravel #LaravelMCP #Mojo #Rust #Rustls #NGINX #Nextcloud #NextcloudHub #GrapheneOS #VirtualBox #Lepton #SDL #SDL3 #HarmonyOS #OpenHarmony #Programming #Development #Coding #ProgrammingLanguage #CustomRom #OS #Dev #FosseryTech

##

fosserytech@social.linux.pizza at 2026-09-20T10:45:37.000Z ##

(more Linux and FOSS news in previous posts of thread)

Zed v1.20 adds Markdown previews and custom window titles:
alternativeto.net/news/2026/9/

Rune (IDE with AI capabilities) Goes Open Source, Looks to Share Revenue With Contributors:
feed.itsfoss.com/link/24361/17

Microsoft’s open-source CLI text editor adds syntax highlighting:
omgubuntu.co.uk/2026/09/micros

Java 27 brings major post-quantum security leap, G1 garbage collector by default, and more:
alternativeto.net/news/2026/9/

Swift 6.4 brings better interoperability, faster performance, and Swift Build by default:
alternativeto.net/news/2026/9/

MariaDB 13.0.2 Now Stable: DuckDB Engine and What Changes:
linuxcompatible.org/story/mari

Laravel MCP 1.0 brings searchable tools to agents:
alternativeto.net/news/2026/9/

Mojo 1.1 Released, Now Accepting Community Contributions To The Compiler:
phoronix.com/news/Mojo-1.1-Rel

Rust Issues Warning Over Key Developers Being Targeted For Compromise:
phoronix.com/news/Rust-Develop

Rustls 0.23.45 Released To Fix Two Year Old Security Issue:
phoronix.com/news/Rustls-0.23.

NGINX 1.30.5 and 1.31.6 Released: Patch for HTTP/3 Buffer Overflow (CVE-2026-90439):
linuxcompatible.org/story/ngin

Nextcloud Hub 26 Summer adds Teams workspaces and brings Euro-Office to desktop:
alternativeto.net/news/2026/9/

GrapheneOS Isn't Happy With Google Over Pixel's Widening Head Start:
feed.itsfoss.com/link/24361/17

VirtualBox 7.2.18 Released with Linux 7.3 Fixes, Support for RHEL 10.3 Kernel:
9to5linux.com/virtualbox-7-2-1

Valve Quietly Open-Sources Its Android Compatibility Layer:
feed.itsfoss.com/link/24361/17

SDL3 Ported To HarmonyOS / OpenHarmony:
phoronix.com/news/SDL3-Ported-

#WeeklyNews #OpenSource #FOSSNews #FOSS #OpenSourceNews #News #Zed #RuneIDE #IDE #TextEditor #Java #Swift #MariaDB #Laravel #LaravelMCP #Mojo #Rust #Rustls #NGINX #Nextcloud #NextcloudHub #GrapheneOS #VirtualBox #Lepton #SDL #SDL3 #HarmonyOS #OpenHarmony #Programming #Development #Coding #ProgrammingLanguage #CustomRom #OS #Dev #FosseryTech

##

CVE-2026-90847
(9.1 CRITICAL)

EPSS: 2.18%

updated 2026-09-15T03:30:30

2 posts

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

secdb at 2026-09-21T00:01:46.493Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-76461
(9.8 CRITICAL)

EPSS: 2.01%

updated 2026-09-14T21:32:49

2 posts

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that cont

4 repos

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

https://github.com/0xBlackash/CVE-2026-76461

https://github.com/S3v3n-JG/CVE-2026-76461

https://github.com/HORKimhab/CVE-2026-76461

8bitsecurity@mastodon.social at 2026-09-21T07:05:00.000Z ##

🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and…

Also tracked this week: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping · Check Point, Kaspersky, Tanium…

nexus8.8bitsecurity.com/entity

##

8bitsecurity@mastodon.social at 2026-09-21T07:05:00.000Z ##

🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and…

Also tracked this week: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping · Check Point, Kaspersky, Tanium…

nexus8.8bitsecurity.com/entity

##

CVE-2026-81000
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T15:33:28

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the re

2 repos

https://github.com/0xBlackash/CVE-2026-81000

https://github.com/HORKimhab/CVE-2026-81000

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

CVE-2026-25687
(8.1 HIGH)

EPSS: 0.23%

updated 2026-09-14T15:32:56

1 posts

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.

hugovalters@mastodon.social at 2026-09-21T14:10:01.000Z ##

CVE-2026-25687 Zscaler ZCC race condition, heap corruption, possible RCE. CVSS 8.1. No patch yet, so isolate or update the moment one lands. valtersit.com/cve/CVE-2026-256 #CVE #infosec #Zscaler

##

CVE-2026-89496(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-09-14T15:32:27

1 posts

In the Linux kernel, the following vulnerability has been resolved: ocfs2: always run deallocs on copy-on-write completion Local fuzzing of 6.12.94 has found the following memory leak caused by doing 'copy_file_range()' within the same filesystem: unreferenced object 0xffff88812192c980 (size 32): comm "syz.0.49", pid 12095, jiffies 4294964143 hex dump (first 32 bytes): 00 00 00 00 00 00

hugovalters@mastodon.social at 2026-09-19T18:40:01.000Z ##

CVE-2026-89496 Linux kernel ocfs2 memory leak via copy_file_range, local fuzzing found it, patch status unknown. Patch now. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80968(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-09-14T15:32:21

1 posts

In the Linux kernel, the following vulnerability has been resolved: ALSA: mts64: Check card index validity at probe Although mts64 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when bound via sysfs. This may lead to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/cor

hugovalters@mastodon.social at 2026-09-20T15:00:02.000Z ##

CVE-2026-80968: Linux kernel ALSA mts64 driver skips negative card index check at probe, enabling OOB access. No CVSS assigned, patch status unpatched/unknown. Update immediately. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80949(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-09-14T15:32:21

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() The memory allocated for buf is not freed in some of the error paths in brcmf_sdio_read_control(). Fix that by adding vfree() calls. [arend: rework as suggested by Johannes]

hugovalters@mastodon.social at 2026-09-20T04:00:01.000Z ##

CVE-2026-80949 Linux kernel brcmfmac memory leak in brcmf_sdio_read_control() error paths. CVSS N/A, unpatched. Patch now. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80930(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-09-14T15:32:20

1 posts

In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout i2c_nuvoton_wait_for_stat() enables the IRQ before waiting for the interrupt handler to report a status change. If the wait times out, or is interrupted before the handler runs, the function returns without balancing the enable_irq() call. Disable the IRQ before leaving the fail

hugovalters@mastodon.social at 2026-09-20T07:10:01.000Z ##

CVE-2026-80930: Linux kernel tpm_i2c_nuvoton IRQ imbalance on wait timeout lets a failed wait return with IRQs left enabled. CVSS N/A, patch status unknown. Update your kernel. valtersit.com/cve/CVE-2026-809 #CVE #infosec #LinuxKernel

##

CVE-2026-80994
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T13:18:54.043000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix flow mask use-after-free on flow deletion The commit in the Fixes tag below made so flow->mask free is scheduled via RCU right after it is removed from the flow table. The pointer stays in the flow structure and it can be accessible while in the same RCU critical section. This is done to avoid requiring o

hugovalters@mastodon.social at 2026-09-20T13:30:02.000Z ##

CVE-2026-80994 Linux kernel openvswitch use-after-free on flow deletion. No CVSS assigned, patch status unknown. If you run OVS, treat as urgent. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80990
(0 None)

EPSS: 0.20%

updated 2026-09-14T13:18:53.787000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Release the Rx HopID that was handed out on mismatch tb_xdomain_alloc_in_hopid() passes the wanted HopID to ida_alloc_range() as the lower bound, so a taken id is not an error there: the allocator returns the next free one above it. tbnet_connected_work() asks for the peer's transmit path, treats any other id a

hugovalters@mastodon.social at 2026-09-20T04:20:02.000Z ##

CVE-2026-80990 Linux kernel thunderbolt net driver leaks Rx HopID on mismatch, leading to resource exhaustion over time. CVSS N/A, no patch confirmed. Update your kernel now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80987
(7.5 HIGH)

EPSS: 0.51%

updated 2026-09-14T13:18:53.343000

1 posts

In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Reject oversized TX buffers ntb_process_tx() handles an oversized buffer by calling tx_handler() with a NULL data pointer and returning success. ntb_netdev therefore neither frees the skb in its completion callback nor takes its enqueue error path, leaking it. Reject oversized buffers in ntb_transport_tx_enq

hugovalters@mastodon.social at 2026-09-20T16:40:16.000Z ##

CVE-2026-80987 Linux kernel NTB transport skb leak via oversized TX buffers. No CVSS assigned, patch status unclear. Update your kernel. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80984
(0 None)

EPSS: 0.20%

updated 2026-09-14T13:18:53.227000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: do not dereference an unset send buffer on the SMC-D teardown path smc_close_stream_wait() calls smc_tx_prepared_sends() from inside its sk_wait_event() condition, and sk_wait_event() evaluates that condition once with the socket lock released. smcd_buf_detach() clears conn->sndbuf_desc from smc_conn_kill() under lock_s

hugovalters@mastodon.social at 2026-09-20T18:10:01.000Z ##

CVE-2026-80984: Linux kernel NULL deref in net/smc teardown crashes the kernel. No CVSS or patch yet. Track it and update immediately. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-90702
(9.1 CRITICAL)

EPSS: 2.80%

updated 2026-09-14T12:31:44

2 posts

A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.

secdb at 2026-09-21T00:01:46.493Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-21T00:01:46.000Z ##

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0916 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0918 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89308 - 2.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90702 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90703 - 2.80 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92398 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-92397 - 2.30 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27560 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27561 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27562 - 2.22 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-90847 - 2.18 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-80937
(8.8 HIGH)

EPSS: 0.32%

updated 2026-09-13T09:32:11

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy mt7915_mcu_get_eeprom() copies a fixed EFUSE block into the driver's dev->mt76.eeprom.data buffer at the offset reported by the MCU response (res->addr, a device-controlled __le32) without checking it against the buffer size. A malicious or malfunctioning

hugovalters@mastodon.social at 2026-09-20T05:40:01.000Z ##

CVE-2026-80937: OOB write in Linux kernel mt76 mt7915 EFUSE copy, device-controlled address, 16-byte overflow. CVSS N/A, unpatched. Patch now if you use mt7915 wifi. valtersit.com/cve/CVE-2026-809 #CVE #LinuxKernel #infosec

##

CVE-2026-80950
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T07:17:02.210000

2 posts

In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Check that the transfer is valid before accessing it The Renesas I3C driver uses an asynchronous model to transfer data. It prepares a struct renesas_i3c_xfer, enqueues it, and waits for completion. The interrupt handler dequeues the transfer, updates/uses it, and signals the waiting thread. If the completion time

hugovalters@mastodon.social at 2026-09-20T08:50:02.000Z ##

CVE-2026-80950 Linux kernel Renesas I3C driver use-after-free from async transfer race, potential RCE. CVSS N/A, patch status unknown. Patch or update now if exposed. valtersit.com/cve/CVE-2026-809 #CVE #infosec #LinuxKernel

##

hugovalters@mastodon.social at 2026-09-20T08:50:02.000Z ##

CVE-2026-80950 Linux kernel Renesas I3C driver use-after-free from async transfer race, potential RCE. CVSS N/A, patch status unknown. Patch or update now if exposed. valtersit.com/cve/CVE-2026-809 #CVE #infosec #LinuxKernel

##

CVE-2026-81913(CVSS UNKNOWN)

EPSS: 0.59%

updated 2026-09-11T21:31:32

1 posts

Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilitating phishing and credential theft. The same handling is present in the registration flow, giving a second entry point on sites with registration enab

hugovalters@mastodon.social at 2026-09-20T10:20:19.000Z ##

CVE-2026-81913: Concrete CMS 9.5.0-9.5.2 open redirect via rcURL parameter. Crafted links can send authenticated users to phishing sites, enabling credential theft. No CVSS published, patch status unknown. valtersit.com/cve/CVE-2026-819 #CVE #infosec #ConcreteCMS

##

CVE-2026-80957
(0 None)

EPSS: 0.17%

updated 2026-09-11T20:19:01.520000

1 posts

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: detect a cycle in the last-kset chain during replay cache_replay() follows the on-media last-kset chain by next_cache_seg_id with no cond_resched(). A forged chain that points back into a segment it has already visited makes the replay loop follow it forever. Cap the last-kset hops at cache->n_segs; a valid chain vis

hugovalters@mastodon.social at 2026-09-20T04:00:32.000Z ##

CVE-2026-80957 Linux kernel dm-pcache infinite loop via forged last-kset chain during replay, DoS on mount. No CVSS yet, unpatched. Update now: valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80942
(0 None)

EPSS: 0.17%

updated 2026-09-11T20:18:59.660000

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subsequent error paths in rtl92du_init_sw_vars(). Fix that by adding a call to rtl92du_deinit_shared_data() in the error path.

hugovalters@mastodon.social at 2026-09-20T04:31:00.000Z ##

CVE-2026-80942 Linux rtlwifi rtl8192du: memory leak in error paths of rtl92du_init_sw_vars(), unfixed. No CVSS assigned. Patch status unknown, update now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80934
(0 None)

EPSS: 0.17%

updated 2026-09-11T20:18:57.280000

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames mt7996/mt7992 hand the firmware a HW MAC-TXP for AddBA req action frames (MT_TXD7_MAC_TXD, set in mt7996_mac_write_txwi_80211()), but are otherwise FW-TXP devices. On tx free mt76_connac_txp_skb_unmap() therefore decodes the per-frame txp as a struct mt76_connac_fw

hugovalters@mastodon.social at 2026-09-19T20:10:03.000Z ##

CVE-2026-80934 Linux kernel mt76 mt7996 TX DMA mapping leak. No CVSS or patch yet. Update now if you run mt7996 wifi. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-42945
(8.1 HIGH)

EPSS: 68.05%

updated 2026-09-10T13:20:09.723000

2 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond it

45 repos

https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945

https://github.com/RedCrazyGhost/CVE-2026-42945

https://github.com/MateusVerass/nGixshell

https://github.com/nanwinata/nginxrift-CVE-2026-42945

https://github.com/josephfelix/CVE-2026-42945-nginx-rift

https://github.com/byezero/nginx-cve-2026-42945-check

https://github.com/azilRababe/CVE-2026-42945

https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit

https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc

https://github.com/iammerrida-source/nginx-rift-detect

https://github.com/tal7aouy/nginx-cve-2026-42945

https://github.com/oseasfr/Scanner_CVE_2026-42945

https://github.com/jelasin/CVE-2026-42945

https://github.com/dinosn/cve-2026-42945-nginx32-lab

https://github.com/Kentox493/CVE-2026-42945_NginxRift

https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift

https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab

https://github.com/yusufdalbudak/CVE-2026-42945

https://github.com/chenqin231/CVE-2026-42945

https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945

https://github.com/sec-sys/CVE-2026-42945-Reverse-Shell-POC

https://github.com/realityone/cve-2026-42945-scan

https://github.com/imSre9/CVE-2026-42945

https://github.com/nu0l/NGINX-Rift

https://github.com/hulina9900-boop/DIY-CVE-2026-42945-POC

https://github.com/hnytgl/CVE-2026-42945

https://github.com/strivepan/Nginx_cve-2026-42945-scanner-gui

https://github.com/simota/nginx-rift-scanner

https://github.com/forxiucn/nginx-cve-2026-42945-poc

https://github.com/quantumworld-dpdns-io/CVE-2026-42945

https://github.com/edgecases-PurpleHax/cve-images

https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945

https://github.com/ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945

https://github.com/BarAppTeam/nginx-cve-fix

https://github.com/limo57640-crypto/nginx-rift-detector

https://github.com/CynepMyx/nginx-rift-check

https://github.com/fkj-src/fix_nginx_cve_2026_42945

https://github.com/0xBlackash/CVE-2026-42945

https://github.com/rheodev/CVE-2026-42945

https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script

https://github.com/aratane/CVE-2026-42945

https://github.com/sibersan/web-server-audit_CVE-2026-42945

https://github.com/FranklinF25/cve-2026-42945

https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC

https://github.com/cipherspy/CVE-2026-42945-POC

kubesploit@learnk8s.news at 2026-09-21T19:16:02.000Z ##

Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives
The README lists affected and fixed versions

ku.bz/PQSlZ7Khl

##

kubesploit@learnk8s.news at 2026-09-21T19:16:02.000Z ##

Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives
The README lists affected and fixed versions

ku.bz/PQSlZ7Khl

##

CVE-2025-25249
(8.1 HIGH)

EPSS: 2.40%

updated 2026-09-09T21:30:27

1 posts

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSASE 25.2.b, FortiSASE 25.1.a.2, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted p

undercodenews@mastodon.social at 2026-09-20T13:52:17.000Z ##

CISA Adds Fortinet CVE-2025-25249 to KEV as Active Exploitation Raises the Pressure on Defenders + Video

CISA Adds Fortinet CVE-2025-25249 to KEV as Active Exploitation Raises the Pressure on Defenders A Fortinet Vulnerability Moves Into a Higher-Risk Category A serious Fortinet vulnerability has entered a more urgent phase after the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2025-25249 to its Known Exploited Vulnerabilities, or KEV, Catalog. The…

undercodenews.com/cisa-adds-fo

##

CVE-2025-20701
(8.8 HIGH)

EPSS: 8.67%

updated 2026-09-08T16:17:48.883000

2 posts

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

2 repos

https://github.com/x0jac0b0x/skullcandy-dime3-cve-2025-20701

https://github.com/SpiritualMachines/buds-audit

dec23k@mastodon.ie at 2026-09-20T11:14:43.000Z ##

@inpc
"The vulnerability is linked to CVE-2025-20701, previously reported in Airoha Bluetooth audio SDK implementations. The affected Dime 3 earbuds identify their Bluetooth chipset vendor as Airoha Technology Corp., associated with Bluetooth SIG company ID 0x0094."

CVE-2025-20701 affected headphones and earbuds with Airoha chips. It was worse than this one: it was possible to steal authentication keys from the audio device, and use them to jump to the paired phone (which was also in range).

##

dec23k@mastodon.ie at 2026-09-20T11:14:43.000Z ##

@inpc
"The vulnerability is linked to CVE-2025-20701, previously reported in Airoha Bluetooth audio SDK implementations. The affected Dime 3 earbuds identify their Bluetooth chipset vendor as Airoha Technology Corp., associated with Bluetooth SIG company ID 0x0094."

CVE-2025-20701 affected headphones and earbuds with Airoha chips. It was worse than this one: it was possible to steal authentication keys from the audio device, and use them to jump to the paired phone (which was also in range).

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 99.91%

updated 2026-09-08T15:13:07.273000

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

100 repos

https://github.com/tgies/copy-fail-c

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/sgkdev/ptrace_may_dream

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/sudoytang/copyfail-arm64

https://github.com/gagaltotal/cve-2026-31431-copy-fail

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/rootsecdev/cve_2026_31431

https://github.com/cs8425/copy-fail-go

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/ncmprbll/copy-fail-rs

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/Smarttfoxx/copyfail

https://github.com/desultory/CVE-2026-31431

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/0xShe/CVE-2026-31431

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/wesmar/CVE-2026-31431

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/badsectorlabs/copyfail-go

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/malwarekid/CVE-2026-31431

https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4

https://github.com/sammwyy/copyfail-rs

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/cyber-joker/copy-fail-python

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH

https://github.com/Juguitos/copy-fail

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/sgkdev/page_inject

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/luotian2/CVE-2026-31431

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/diemoeve/copyfail-rs

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/Huchangzhi/autorootlinux

https://github.com/atgreen/block-copyfail

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/cozystack/copy-fail-blocker

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/povzayd/CVE-2026-31431

https://github.com/pyroceper/copy-fail-CVE-2026-31431

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/mrunalp/block-copyfail

https://github.com/xeloxa/copyfail-exploit

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/wgnet/wg.copyfail.patch

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/Boos4721/copyfail-rs

https://github.com/Qengineering/RK35xx-CopyFail-Hotfix

https://github.com/samanzamani/copy-fail-checker

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/b5null/CVE-2026-31431-C

https://github.com/nisec-eric/cve-2026-31431

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/rvzsec/CVE-2026-31431

https://github.com/pedromizz/copy-fail

sigint@fosstodon.org at 2026-09-21T00:30:11.000Z ##

🐧 SIGINT // Linux Watch — 2026-09-21

CVE-2026-31431: a tiny buffer bug in the kernel's crypto subsystem, full root. Ubuntu 24.04 LTS and Amazon Linux both on the guest list — patch before the weekend, not after.

🔗 forkast.news/732-bytes-to-root

#Linux #OpenSource #FOSS

##

CVE-2026-54218
(0 None)

EPSS: 0.34%

updated 2026-09-07T14:16:53.357000

2 posts

Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various files using only obfuscation. Any user with access to the server’s file system, or who can otherwise extract files from the server (see vulnerability “Random File Read”), can potentially obtain affected users’ passwords. This issue a

nyanbinary at 2026-09-20T13:35:50.157Z ##

CVE-2026-54218 is also interesting in that it appears to be plaintext/weak-crypto password storage, based on the reference, instead of actually hardcoded

##

nyanbinary@infosec.exchange at 2026-09-20T13:35:50.000Z ##

CVE-2026-54218 is also interesting in that it appears to be plaintext/weak-crypto password storage, based on the reference, instead of actually hardcoded

##

CVE-2026-75925
(9.6 CRITICAL)

EPSS: 0.67%

updated 2026-09-05T00:31:10

2 posts

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface

certvde at 2026-09-21T14:13:08.282Z ##

🔒 New CSAF advisory published

VDE-2026-089
Lenze: VPN Client Remote Code Execution in combination with Lenze x500 IoT Gateway
CVE-2026-75925

The Lenze VPN client is vulnerable to a Remote Code Execution. The vulnerability would allow an attacker to perform a remote code execution on the computer running the client with elevated privile…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: lenze.csaf-tp.certvde.com/.wel

##

certvde@infosec.exchange at 2026-09-21T14:13:08.000Z ##

🔒 New CSAF advisory published

VDE-2026-089
Lenze: VPN Client Remote Code Execution in combination with Lenze x500 IoT Gateway
CVE-2026-75925

The Lenze VPN client is vulnerable to a Remote Code Execution. The vulnerability would allow an attacker to perform a remote code execution on the computer running the client with elevated privile…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: lenze.csaf-tp.certvde.com/.wel

#OT #Advisory

##

CVE-2026-80844
(0 None)

EPSS: 0.19%

updated 2026-09-04T16:18:13.023000

1 posts

In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of addresses described by the routing header's hdrlen field. That assumption does not hold for raw IPv6 HDRINCL packets.

2 repos

https://github.com/HORKimhab/CVE-2026-80844

https://github.com/0xBlackash/CVE-2026-80844

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

CVE-2026-13348
(0 None)

EPSS: 0.31%

updated 2026-09-01T20:52:39.973000

1 posts

CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.

cyberworldops@infosec.exchange at 2026-09-18T22:40:00.000Z ##

Schneider Electric disclosed CVE-2026-13348 (CWE-307) in PowerChute Serial Shutdown, allowing unrestricted authentication attempts. Successful brute-forcing enables account takeover with impact on UPS management and operational continuity. #SchneiderElectric #PowerChute #BruteForce

cyberworldops.eu/en/powerchute

##

CVE-2026-74469
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-19T17:21:03.977000

1 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload, then copies one sockaddr_storage for every entry in t

2 repos

https://github.com/0xBlackash/CVE-2026-74469

https://github.com/HORKimhab/CVE-2026-74469

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

CVE-2026-68121
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-19T17:20:29.553000

1 posts

In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is

2 repos

https://github.com/0xBlackash/CVE-2026-68121

https://github.com/HORKimhab/CVE-2026-68121

cyberworldops@infosec.exchange at 2026-09-19T04:30:00.000Z ##

Researcher Asim Manizada released working local root exploits for four Linux kernel flaws: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Public code lowers exploitation barrier for unpatched hosts, increasing post-compromise privilege escalation risk. #LinuxSecurity #PrivilegeEscalation #KernelSecurity

cyberworldops.eu/en/four-publi

##

1337core@social.1337core.de at 2026-09-20T16:03:04.000Z ##

Ungepatchte Exchange-Server mit kritischer Sicherheitslücke
CVE-2021-34473: "Microsoft Exchange Server Remote Code Execution Vulnerability"
Volkshochschule in Amberg, Landkreis Merzig-Wadern und mehreren Stadtverwaltungen: Bernsdorf, Bleckede, Dachau, Erkner, Heilbald Heiligenstadt, Klötze, Mölln, Plauen, Rendsburg, Sassnitz, Stadtbergen, Sulzbach Saar, Vellmar und im Exchange-Server im Theater in Freiburg, ...

#Hacks

c't Artikel: heise.de/news/Verwundbare-Exch

##

1337core@social.1337core.de at 2026-09-20T16:03:04.000Z ##

Ungepatchte Exchange-Server mit kritischer Sicherheitslücke
CVE-2021-34473: "Microsoft Exchange Server Remote Code Execution Vulnerability"
Volkshochschule in Amberg, Landkreis Merzig-Wadern und mehreren Stadtverwaltungen: Bernsdorf, Bleckede, Dachau, Erkner, Heilbald Heiligenstadt, Klötze, Mölln, Plauen, Rendsburg, Sassnitz, Stadtbergen, Sulzbach Saar, Vellmar und im Exchange-Server im Theater in Freiburg, ...

#Hacks

c't Artikel: heise.de/news/Verwundbare-Exch

##

CVE-2026-12495(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-07-27T12:32:01

2 posts

Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration se

CVE-2026-47065
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-07-22T19:10:00.120000

2 posts

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which perform

cR0w at 2026-09-21T15:49:50.293Z ##

sev:CRIT bypass of CVE-2026-47065 in Apache MINA.

nvd.nist.gov/vuln/detail/cve-2

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.

##

cR0w@infosec.exchange at 2026-09-21T15:49:50.000Z ##

sev:CRIT bypass of CVE-2026-47065 in Apache MINA.

nvd.nist.gov/vuln/detail/cve-2

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.

##

CVE-2026-58138
(9.8 CRITICAL)

EPSS: 9.26%

updated 2026-07-14T22:17:26.797000

4 posts

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or

6 repos

https://github.com/0xBlackash/CVE-2026-58138

https://github.com/BiiTts/CVE-2026-58138-Conductor-Unauth-RCE

https://github.com/seqra/cve-2026-58138

https://github.com/Procjevt/CVE-2026-58138

https://github.com/Ch4120N/CVE-2026-58138

https://github.com/0xgh057r3c0n/CVE-2026-58138

beyondmachines1 at 2026-09-20T10:01:13.554Z ##

Critical Pre-Auth RCE in Orkes Conductor Under Active Exploitation

Orkes Conductor versions prior to 3.30.2 are vulnerable to a critical unauthenticated remote code execution flaw (CVE-2026-58138) that allows attackers to run arbitrary OS commands via malicious workflow definitions.

**If you run Orkes Conductor or Conductor OSS versions 3.21.21 through 3.30.1 (check your `conductoross/conductor` container images and Helm charts), update to 3.30.2 or later immediately. Working exploit code is public and attacks are already underway. Until you can patch, take the Conductor API off the internet, put it behind a reverse proxy that requires authentication and limit workflow endpoints to trusted internal networks only.**

beyondmachines.net/event_detai

##

threatnoir at 2026-09-20T04:05:50.702Z ##

⚠️ CRITICAL: Critical Orkes Conductor Vulnerability Exploited in Attacks

Orkes Conductor versions below 3.30.2 have an unauthenticated remote code execution vulnerability (CVE-2026-58138) that is actively being exploited. Attackers can execute arbitrary system commands by injecting malicious JavaScript or Python into workflow definitions. Any organization running Conduc…

threatnoir.com/focus

🤖 AI generated summary

##

beyondmachines1@infosec.exchange at 2026-09-20T10:01:13.000Z ##

Critical Pre-Auth RCE in Orkes Conductor Under Active Exploitation

Orkes Conductor versions prior to 3.30.2 are vulnerable to a critical unauthenticated remote code execution flaw (CVE-2026-58138) that allows attackers to run arbitrary OS commands via malicious workflow definitions.

**If you run Orkes Conductor or Conductor OSS versions 3.21.21 through 3.30.1 (check your `conductoross/conductor` container images and Helm charts), update to 3.30.2 or later immediately. Working exploit code is public and attacks are already underway. Until you can patch, take the Conductor API off the internet, put it behind a reverse proxy that requires authentication and limit workflow endpoints to trusted internal networks only.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-09-20T04:05:50.000Z ##

⚠️ CRITICAL: Critical Orkes Conductor Vulnerability Exploited in Attacks

Orkes Conductor versions below 3.30.2 have an unauthenticated remote code execution vulnerability (CVE-2026-58138) that is actively being exploited. Attackers can execute arbitrary system commands by injecting malicious JavaScript or Python into workflow definitions. Any organization running Conduc…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-55945
(4.2 MEDIUM)

EPSS: 0.19%

updated 2026-07-07T13:31:43.910000

1 posts

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

sayzard@mastodon.sayzard.org at 2026-09-20T13:42:06.000Z ##

BragJack attacks hijack AI browser agents through malicious extensions

Forever Security의 Gal Weizman이 악성 Chromium 확장 프로그램 하나로 브라우저 내 AI 에이전트를 탈취하는 ‘BragJack’ 공격을 공개했다. Google Chrome Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, Claude in Chrome 등 5개 대상에서 재현됐으며, Chrome의 CVE-2026-0628과 Edge의 CVE-2026-55945를 포...

bleepingcomputer.com/news/secu

##

CVE-2026-20111
(4.8 MEDIUM)

EPSS: 0.18%

updated 2026-03-10T21:32:11

2 posts

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability

nyanbinary at 2026-09-20T13:28:38.280Z ##

@cR0w hold a second, what the fuck is this vulnerability: db.gcve.eu/vuln/CVE-2026-20111

This CWE and description absolutely dont fucking match, what the fuck, cisco

##

nyanbinary@infosec.exchange at 2026-09-20T13:28:38.000Z ##

@cR0w hold a second, what the fuck is this vulnerability: db.gcve.eu/vuln/CVE-2026-20111

This CWE and description absolutely dont fucking match, what the fuck, cisco

##

CVE-2026-0628
(8.8 HIGH)

EPSS: 6.63%

updated 2026-01-07T15:31:20

1 posts

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

2 repos

https://github.com/fevar54/CVE-2026-0628-POC

https://github.com/sastraadiwiguna-purpleeliteteaming/Dissecting-CVE-2026-0628-Chromium-Extension-Privilege-Escalation

sayzard@mastodon.sayzard.org at 2026-09-20T13:42:06.000Z ##

BragJack attacks hijack AI browser agents through malicious extensions

Forever Security의 Gal Weizman이 악성 Chromium 확장 프로그램 하나로 브라우저 내 AI 에이전트를 탈취하는 ‘BragJack’ 공격을 공개했다. Google Chrome Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, Claude in Chrome 등 5개 대상에서 재현됐으며, Chrome의 CVE-2026-0628과 Edge의 CVE-2026-55945를 포...

bleepingcomputer.com/news/secu

##

CVE-2024-3400
(9.8 CRITICAL)

EPSS: 100.00%

updated 2025-10-22T00:34:06

2 posts

A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Fixes for PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 are in development and are expected to be released by April 14, 2024. Cloud NG

45 repos

https://github.com/andrelia-hacks/CVE-2024-3400

https://github.com/P4rC3L/Global-Protect_VPN_Vuln

https://github.com/Chocapikk/CVE-2024-3400

https://github.com/ak1t4/CVE-2024-3400

https://github.com/marconesler/CVE-2024-3400

https://github.com/wa6n3r/CVE-2024-3400

https://github.com/Yafiah-Darwesh/cs50-cyber-paloalto-oauth

https://github.com/terminalJunki3/CVE-2024-3400-Checker

https://github.com/CyberBibs/SOC274---Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400-

https://github.com/index2014/CVE-2024-3400-Checker

https://github.com/MrR0b0t19/CVE-2024-3400

https://github.com/codeblueprint/CVE-2024-3400

https://github.com/hashdr1ft/SOC274-Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400

https://github.com/AdaniKamal/CVE-2024-3400

https://github.com/Ravaan21/CVE-2024-3400

https://github.com/0x0d3ad/CVE-2024-3400

https://github.com/HackingLZ/panrapidcheck

https://github.com/ivan-n0v/cve-2024-3400

https://github.com/MurrayR0123/CVE-2024-3400-Compromise-Checker

https://github.com/Zedocun/PAN-OS-CVE-2024-3400-Command-Injection-Investigation

https://github.com/ihebski/CVE-2024-3400

https://github.com/h4x0r-dz/CVE-2024-3400

https://github.com/0xr2r/CVE-2024-3400-Palo-Alto-OS-Command-Injection

https://github.com/ZephrFish/CVE-2024-3400-Canary

https://github.com/sxyrxyy/CVE-2024-3400-Check

https://github.com/Yuvvi01/CVE-2024-3400

https://github.com/SimoesCTT/-CTT-PAN-OS-EXPLOIT-CVE-2024-340

https://github.com/LoanVitor/CVE-2024-3400-

https://github.com/razureink/cve-2024-3400-panos_rce_reproduction

https://github.com/tfrederick74656/cve-2024-3400-poc

https://github.com/CerTusHack/CVE-2024-3400-PoC

https://github.com/retkoussa/CVE-2024-3400

https://github.com/FoxyProxys/CVE-2024-3400

https://github.com/CyprianAtsyor/letsdefend-cve2024-3400-case-study

https://github.com/workshop748/CVE-2024-3400

https://github.com/GhassanSabir/CVE-2024-3400-poc

https://github.com/schooldropout1337/CVE-2024-3400

https://github.com/pwnj0hn/CVE-2024-3400

https://github.com/momika233/CVE-2024-3400

https://github.com/zam89/CVE-2024-3400-pot

https://github.com/hahasagined/CVE-2024-3400

https://github.com/W01fh4cker/CVE-2024-3400-RCE-Scan

https://github.com/Kr0ff/cve-2024-3400

https://github.com/swaybs/CVE-2024-3400

https://github.com/CONDITIONBLACK/CVE-2024-3400-POC

hugovalters@mastodon.social at 2026-09-21T03:20:03.000Z ##

GET /api/v1/cve/CVE-2024-3400 returns CVSS, affected vendors, and known exploit references in one call. No key juggling, no separate lookups. Metered per request. valtersit.com/cve/pricing/

##

hugovalters@mastodon.social at 2026-09-20T11:00:21.000Z ##

GET /api/v1/cve/CVE-2024-3400 returns CVSS, affected vendors, CPEs, and known exploits in one call. No joins, no scraping. Metered keys at valtersit.com/cve/pricing/

##

thehackerwire@mastodon.social at 2026-09-21T00:01:27.000Z ##

🔴 CVE-2026-92702 - Critical (9.1)

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-21T00:01:27.000Z ##

🔴 CVE-2026-92702 - Critical (9.1)

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61721
(0 None)

EPSS: 0.15%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-20T21:01:21.000Z ##

🟠 CVE-2026-61721 - High (8)

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T21:01:21.000Z ##

🟠 CVE-2026-61721 - High (8)

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61819
(0 None)

EPSS: 0.58%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-20T20:01:12.000Z ##

🟠 CVE-2026-61819 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verbatim insid...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T20:01:12.000Z ##

🟠 CVE-2026-61819 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verbatim insid...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61818
(0 None)

EPSS: 0.41%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-20T20:01:02.000Z ##

🟠 CVE-2026-61818 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically executed SEL...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T20:01:02.000Z ##

🟠 CVE-2026-61818 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically executed SEL...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61821
(0 None)

EPSS: 0.29%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-20T19:00:56.000Z ##

🟠 CVE-2026-61821 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept any nonempty sch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T19:00:56.000Z ##

🟠 CVE-2026-61821 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept any nonempty sch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61820
(0 None)

EPSS: 0.58%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-20T19:00:46.000Z ##

🟠 CVE-2026-61820 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with double quotes without escaping embedded do...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-20T19:00:46.000Z ##

🟠 CVE-2026-61820 - High (8.5)

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with double quotes without escaping embedded do...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84383
(0 None)

EPSS: 0.64%

1 posts

N/A

e_nomem@hachyderm.io at 2026-09-19T17:15:33.000Z ##

@paul @arda AVIF is a specific profile/subtype of HEIF. Mastodon uses libvips to handle images and libvips uses libheif to handle both HEIF and AVIF.

libheif was disabled in mastodon 4.7.2 due to unspecified security issues but it's probably because of CVE-2026-84383

##

CVE-2026-57228
(0 None)

EPSS: 0.56%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T23:02:48.000Z ##

🟠 CVE-2026-57228 - High (8.2)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57227
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T23:02:37.000Z ##

🟠 CVE-2026-57227 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63447
(0 None)

EPSS: 0.36%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T23:02:21.000Z ##

🟠 CVE-2026-63447 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63446
(0 None)

EPSS: 0.39%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T22:03:40.000Z ##

🟠 CVE-2026-63446 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63452
(0 None)

EPSS: 0.36%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-18T22:03:30.000Z ##

🟠 CVE-2026-63452 - High (7.5)

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli comp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites