##
Updated at UTC 2026-09-12T00:42:24.198493
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-90456 | 0 | 0.00% | 2 | 0 | 2026-09-11T22:16:47.993000 | An example environment-configuration file for a bundled inventory-management com | |
| CVE-2026-50013 | 7.5 | 0.00% | 2 | 0 | 2026-09-11T22:16:37.813000 | Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Ho | |
| CVE-2026-49846 | 7.5 | 0.00% | 2 | 0 | 2026-09-11T22:16:37.537000 | libks provides foundational support for signalwire C products. Prior to version | |
| CVE-2026-42018 | 7.5 | 0.35% | 7 | 0 | 2026-09-11T21:32:08 | JFrog Artifactory could return an internal anonymous-user token to an unauthenti | |
| CVE-2026-62112 | 7.6 | 0.00% | 2 | 0 | 2026-09-11T21:31:22 | Editor SQL Injection in Amelia <= 2.4.9 versions. | |
| CVE-2026-79393 | 7.5 | 0.00% | 2 | 0 | 2026-09-11T21:31:22 | A heap-based buffer overflow vulnerability in the WS-Addressing Action transform | |
| CVE-2026-84869 | 9.9 | 0.38% | 5 | 0 | 2026-09-11T21:31:17 | A condition in the ScreenConnect client may allow files to be transferred and ex | |
| CVE-2026-42016 | 8.1 | 0.27% | 7 | 0 | 2026-09-11T21:31:06 | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri | |
| CVE-2026-89060 | 7.7 | 0.24% | 2 | 0 | 2026-09-11T21:17:56.740000 | A cross-namespace authorization flaw in multicluster-observability-addon allows | |
| CVE-2026-77807 | 7.5 | 0.68% | 2 | 0 | 2026-09-11T21:17:16.053000 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution | |
| CVE-2026-89771 | 0 | 0.00% | 1 | 0 | 2026-09-11T20:20:08.460000 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer | |
| CVE-2026-79395 | 9.8 | 0.00% | 2 | 0 | 2026-09-11T20:18:54.030000 | An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) | |
| CVE-2026-54135 | 7.5 | 0.00% | 2 | 0 | 2026-09-11T20:17:14.330000 | AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan p | |
| CVE-2026-53952 | 9.8 | 0.00% | 2 | 0 | 2026-09-11T20:17:14.060000 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the | |
| CVE-2026-89262 | 7.5 | 0.00% | 2 | 0 | 2026-09-11T18:31:32 | MoguBlog through 6.2 contains an authorization bypass vulnerability in the comme | |
| CVE-2026-89260 | 7.5 | 0.00% | 2 | 0 | 2026-09-11T18:31:31 | MoguBlog through 6.2 contains an XML external entity injection vulnerability in | |
| CVE-2026-89177 | 8.8 | 0.23% | 2 | 0 | 2026-09-11T16:17:50.200000 | WeenyGenius, a computer lab management system by Howyar Technologies, has a Use | |
| CVE-2026-69827 | 8.1 | 0.53% | 2 | 0 | 2026-09-11T16:17:43.143000 | Concurrent execution using shared resource with improper synchronization ('race | |
| CVE-2026-57162 | 9.1 | 0.35% | 1 | 0 | 2026-09-11T15:51:10.693000 | PJSIP is a free and open source multimedia communication library written in C. P | |
| CVE-2026-80462 | 10.0 | 0.00% | 4 | 0 | 2026-09-11T15:32:48 | A vulnerability in the Chef Automate API gateway and identity validation path ma | |
| CVE-2026-84390 | 9.8 | 0.00% | 2 | 0 | 2026-09-11T15:32:48 | A inclusion of sensitive information in source code vulnerability in Fortinet Fo | |
| CVE-2026-47839 | None | 0.32% | 2 | 0 | 2026-09-11T15:32:40 | A vulnerability allows users authenticating through a federated OIDC provider to | |
| CVE-2026-21096 | 9.8 | 0.41% | 1 | 0 | 2026-09-11T15:32:35 | Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SM | |
| CVE-2026-87958 | 8.1 | 0.21% | 2 | 0 | 2026-09-11T15:17:07.097000 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a deni | |
| CVE-2026-80469 | 8.3 | 0.23% | 2 | 0 | 2026-09-11T15:17:04.913000 | An attacker may achieve arbitrary code execution on a target system by uploading | |
| CVE-2026-89212 | 8.6 | 0.00% | 2 | 0 | 2026-09-11T14:17:36.847000 | A flaw resulting in XML external entity (XXE) was found in Akana API Platform in | |
| CVE-2026-39821 | 9.6 | 0.69% | 1 | 0 | 2026-09-11T13:17:49.237000 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels t | |
| CVE-2026-67277 | 8.2 | 0.75% | 4 | 0 | 2026-09-11T12:52:29.533000 | RouterOS accepts a "related" btest connection before the corresponding primary s | |
| CVE-2026-86060 | 9.8 | 0.69% | 7 | 1 | 2026-09-11T12:52:16.507000 | RouterOS contains an argument-handling flaw in the SSH login path involving user | |
| CVE-2026-89259 | 9.8 | 0.00% | 2 | 0 | 2026-09-11T12:33:34 | Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under N | |
| CVE-2026-86781 | 5.3 | 0.12% | 2 | 0 | 2026-09-11T12:33:26 | The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin befor | |
| CVE-2026-89178 | 8.8 | 0.23% | 2 | 0 | 2026-09-11T09:31:31 | WeenyGenius, a computer lab management system by Howyar Technologies, has an Ori | |
| CVE-2026-89176 | 8.8 | 0.25% | 2 | 0 | 2026-09-11T09:31:31 | WeenyGenius, a computer lab management system developed by Howyar Technologies, | |
| CVE-2026-89174 | 7.5 | 0.38% | 2 | 0 | 2026-09-11T09:31:31 | Smart Video Intercom System developed by Kingdom Communication Associated has a | |
| CVE-2026-8778 | 9.8 | 0.62% | 2 | 0 | 2026-09-11T06:31:14 | The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout | |
| CVE-2026-19584 | 7.7 | 0.19% | 1 | 0 | 2026-09-11T04:17:34.343000 | Velociraptor allows for the creation of notebook backups in its default enabled | |
| CVE-2026-0310 | 0 | 0.34% | 8 | 0 | 2026-09-11T04:17:13.060000 | A buffer overflow vulnerability in the XML processing functionality of Palo Alto | |
| CVE-2026-82107 | 9.6 | 0.36% | 4 | 0 | 2026-09-11T00:31:23 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a | |
| CVE-2026-82100 | 9.6 | 0.40% | 4 | 0 | 2026-09-11T00:31:23 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a | |
| CVE-2026-81940 | 8.8 | 0.54% | 2 | 0 | 2026-09-11T00:31:23 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacke | |
| CVE-2026-84889 | 8.8 | 0.53% | 2 | 0 | 2026-09-11T00:31:23 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke | |
| CVE-2026-86093 | 7.5 | 0.47% | 2 | 0 | 2026-09-11T00:31:16 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker | |
| CVE-2026-19646 | 9.1 | 0.52% | 2 | 0 | 2026-09-11T00:31:12 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0 | |
| CVE-2026-88045 | 7.5 | 0.53% | 2 | 0 | 2026-09-10T22:45:14 | ## Summary In streamed multipart mode, `serve s3` passes the request's declared | |
| CVE-2026-89094 | 9.9 | 0.50% | 6 | 0 | 2026-09-10T21:31:46 | Forgejo before 16.0.4 allows remote code execution via a crafted template reposi | |
| CVE-2026-89054 | 8.2 | 0.35% | 2 | 0 | 2026-09-10T21:31:41 | A missing authorization vulnerability in OpenNMS Horizon allows configuration ch | |
| CVE-2026-89086 | 9.1 | 0.20% | 2 | 0 | 2026-09-10T21:31:41 | In the jose package before 0.11.0 for OCaml, library calls to validate an RSA si | |
| CVE-2026-87016 | 8.1 | 0.33% | 1 | 0 | 2026-09-10T21:23:26 | ## Summary On SQLite deployments, the lookup that maps an external identity to | |
| CVE-2026-88062 | None | 0.40% | 2 | 0 | 2026-09-10T21:22:13 | ## 2. Summary `POST /api/acp/agents` registers a custom ACP agent. The endpoint | |
| CVE-2026-87794 | 8.4 | 0.19% | 1 | 0 | 2026-09-10T19:58:20.507000 | bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in | |
| CVE-2026-88044 | 9.1 | 0.49% | 2 | 0 | 2026-09-10T19:54:25.810000 | rclone is a command-line program to sync files and directories to and from diffe | |
| CVE-2026-80352 | 9.8 | 0.33% | 2 | 0 | 2026-09-10T18:33:12 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apach | |
| CVE-2026-67593 | 9.1 | 0.46% | 1 | 0 | 2026-09-10T18:33:11 | A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause | |
| CVE-2026-89046 | 8.2 | 0.57% | 2 | 0 | 2026-09-10T18:33:05 | zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnera | |
| CVE-2026-81467 | 9.8 | 3.84% | 2 | 0 | 2026-09-10T18:33:04 | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutraliza | |
| CVE-2026-89042 | 9.1 | 0.27% | 2 | 0 | 2026-09-10T18:33:04 | passport-saml-encrypted through 0.1.13 makes SAML signature verification conditi | |
| CVE-2026-85228 | 9.1 | 0.38% | 2 | 0 | 2026-09-10T18:33:04 | An integer overflow in the tensor buffer validation component in Amazon Deep Jav | |
| CVE-2026-65638 | None | 3.20% | 3 | 0 | 2026-09-10T18:32:56 | Improper escaping of a request URL in ConfigServer Security & Firewall allows a | |
| CVE-2026-65639 | None | 1.61% | 2 | 0 | 2026-09-10T18:32:56 | OS command injection in the advanced-rule parser of ConfigServer Security & Fire | |
| CVE-2026-79322 | 8.6 | 0.28% | 1 | 0 | 2026-09-10T17:48:32.410000 | SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (magep | |
| CVE-2026-88889 | 7.8 | 0.62% | 2 | 0 | 2026-09-10T16:18:11.693000 | Renovate before 44.14.7 contains a command injection vulnerability in the Maven | |
| CVE-2026-88290 | 7.5 | 0.26% | 2 | 0 | 2026-09-10T16:18:10.767000 | GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare un | |
| CVE-2026-13745 | 0 | 0.30% | 2 | 0 | 2026-09-10T16:17:07.727000 | A vulnerability in the Gemini CLI and associated GitHub Action allowed an unpriv | |
| CVE-2026-87911 | 9.6 | 0.99% | 2 | 0 | 2026-09-10T15:53:23.707000 | An OS command injection weakness in the read-only enforcement of the SQL validat | |
| CVE-2026-88069 | 0 | 0.33% | 1 | 0 | 2026-09-10T15:43:03.760000 | Pandora contains a path traversal vulnerability in its archive extraction worker | |
| CVE-2026-88890 | 8.5 | 0.29% | 2 | 0 | 2026-09-10T15:33:28 | OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the | |
| CVE-2026-88887 | 8.6 | 0.30% | 2 | 0 | 2026-09-10T15:33:28 | Renovate is a dependency update automation tool. When listing tags/digests for a | |
| CVE-2026-88891 | 8.3 | 0.25% | 2 | 0 | 2026-09-10T15:33:27 | OpenPanel fails to enforce read-only project access level on 26 of 29 mutating p | |
| CVE-2026-73786 | 7.5 | 0.33% | 1 | 1 | 2026-09-10T15:33:12 | A vulnerability in the web-based management interface of CPPM could allow an una | |
| CVE-2026-82533 | 9.6 | 0.62% | 1 | 0 | 2026-09-10T15:32:56 | DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerab | |
| CVE-2026-87995 | 8.7 | 0.22% | 1 | 0 | 2026-09-10T15:10:20 | ## Summary Any authenticated user with access to a shared terminal server could | |
| CVE-2026-87996 | 7.7 | 0.21% | 1 | 0 | 2026-09-10T14:50:07.813000 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI plat | |
| CVE-2026-87011 | 7.5 | 0.34% | 1 | 0 | 2026-09-10T14:50:07.813000 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI plat | |
| CVE-2026-19490 | 9.8 | 5.60% | 4 | 2 | 2026-09-10T12:48:10.453000 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f | |
| CVE-2026-78082 | None | 0.49% | 2 | 0 | 2026-09-10T12:31:26 | Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Se | |
| CVE-2026-8323 | 9.3 | 0.25% | 2 | 0 | 2026-09-10T09:31:48 | URL redirection to untrusted site ('open redirect') vulnerability in Armiya Info | |
| CVE-2026-88289 | 7.5 | 0.33% | 2 | 0 | 2026-09-10T09:31:44 | GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variab | |
| CVE-2026-87931 | 9.6 | 0.45% | 1 | 0 | 2026-09-10T06:32:50 | A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral | |
| CVE-2026-0307 | None | 0.10% | 1 | 0 | 2026-09-10T06:31:54 | Multiple local privilege escalation vulnerabilities in the Palo Alto Networks Gl | |
| CVE-2026-15019 | 7.5 | 0.68% | 1 | 0 | 2026-09-10T06:31:51 | The Direct Download for WooCommerce plugin for WordPress is vulnerable to Direct | |
| CVE-2026-14873 | 8.0 | 0.24% | 1 | 0 | 2026-09-10T06:31:42 | The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalati | |
| CVE-2026-85103 | 9.8 | 0.36% | 9 | 0 | 2026-09-10T04:18:18.390000 | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unau | |
| CVE-2026-67401 | 9.9 | 0.96% | 3 | 3 | 2026-09-10T04:18:04.630000 | A vulnerability in cPanel allows a mail-enabled account to achieve remote code e | |
| CVE-2026-18351 | 9.8 | 0.77% | 1 | 2 | 2026-09-10T03:30:27 | The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulner | |
| CVE-2026-19583 | 9.9 | 0.60% | 1 | 0 | 2026-09-10T03:30:26 | Velociraptor allows some sensitive artifacts to be gated by additional permissio | |
| CVE-2026-15913 | 7.7 | 0.39% | 1 | 0 | 2026-09-10T00:30:34 | In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteF | |
| CVE-2026-79324 | 7.5 | 0.32% | 1 | 0 | 2026-09-09T21:32:03 | Missing authorization in the Address Delete controller in Mageplaza GDPR for Mag | |
| CVE-2026-79323 | 7.5 | 0.33% | 1 | 0 | 2026-09-09T21:31:57 | Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL | |
| CVE-2026-87491 | 8.8 | 0.86% | 10 | 1 | 2026-09-09T21:31:35 | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo | |
| CVE-2026-20079 | 10.0 | 75.75% | 25 | 2 | template | 2026-09-09T21:31:33 | A vulnerability in the web interface of Cisco Secure Firewall Management Center |
| CVE-2026-75162 | 6.5 | 0.46% | 1 | 0 | 2026-09-09T21:31:17 | An information disclosure vulnerability in the opcua-configuration method of /cg | |
| CVE-2025-25249 | 8.1 | 2.40% | 6 | 0 | 2026-09-09T21:30:27 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6 | |
| CVE-2026-87929 | 9.8 | 0.29% | 1 | 0 | 2026-09-09T20:14:00.420000 | MaxSite CMS through 109.6 ships with a hardcoded session encryption key in appli | |
| CVE-2026-87927 | 8.2 | 0.34% | 1 | 0 | 2026-09-09T20:14:00.420000 | MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the a | |
| CVE-2026-87874 | 8.1 | 0.43% | 1 | 0 | 2026-09-09T18:32:11 | A flaw was found in the memcached cache plugin of the community.general Ansible | |
| CVE-2026-75165 | 6.5 | 0.41% | 1 | 0 | 2026-09-09T16:04:24.933000 | An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_ | |
| CVE-2026-17469 | 5.3 | 0.21% | 2 | 0 | 2026-09-09T16:00:50.560000 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause | |
| CVE-2026-73324 | 6.5 | 0.33% | 4 | 0 | 2026-09-09T15:35:16 | VLC media player copies an RTSP response line into a fixed buffer without guaran | |
| CVE-2026-56711 | 8.8 | 0.30% | 4 | 0 | 2026-09-09T15:35:15 | VLC media player computes the size of a picture buffer with 32-bit arithmetic an | |
| CVE-2026-85102 | 9.8 | 0.33% | 8 | 0 | 2026-09-09T15:35:15 | Improper certificate trust validation during VPN negotiation in Check Point Quan | |
| CVE-2026-17440 | 5.5 | 0.10% | 1 | 0 | 2026-09-09T14:12:06.967000 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0. | |
| CVE-2026-87795 | 8.2 | 0.34% | 1 | 0 | 2026-09-09T12:32:12 | zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters | |
| CVE-2026-86218 | 9.8 | 0.74% | 7 | 1 | 2026-09-09T05:18:19.490000 | N-central is vulnerable to a pre-auth remote code execution This issue affects N | |
| CVE-2026-81963 | 7.8 | 0.63% | 2 | 0 | 2026-09-09T05:18:17.173000 | Improper link resolution before file access ('link following') in Windows Update | |
| CVE-2026-67276 | 0 | 0.24% | 1 | 4 | 2026-09-09T05:17:28.130000 | RouterOS does not compare the complete RSA public key when matching an SSH authe | |
| CVE-2026-85880 | 7.8 | 0.57% | 4 | 0 | 2026-09-08T21:34:12 | Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev | |
| CVE-2026-75650 | 10.0 | 2.15% | 6 | 4 | 2026-09-08T21:33:09 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Use | |
| CVE-2026-85008 | 3.7 | 0.12% | 1 | 0 | 2026-09-08T19:07:52.113000 | undici's cache interceptor documents that only safe HTTP methods are cached, but | |
| CVE-2026-83991 | 5.5 | 0.34% | 1 | 2 | 2026-09-08T18:34:14 | Missing authentication for critical function in Windows Cloud Files Mini Filter | |
| CVE-2026-69730 | 9.8 | 1.05% | 1 | 0 | 2026-09-08T18:33:07 | Use after free in Windows DNS allows an unauthorized attacker to execute code ov | |
| CVE-2026-82067 | 8.1 | 0.28% | 1 | 0 | 2026-09-08T18:32:04 | Improper handling of case sensitivity in the configuration validation component | |
| CVE-2025-20701 | 8.8 | 7.77% | 1 | 2 | 2026-09-08T18:31:36 | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth aud | |
| CVE-2026-33197 | None | 0.12% | 1 | 0 | 2026-09-08T15:32:05 | AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause th | |
| CVE-2026-85046 | 8.8 | 1.26% | 3 | 7 | 2026-09-08T14:55:04.093000 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at | |
| CVE-2026-85637 | 5.3 | 0.43% | 1 | 0 | 2026-09-08T13:12:58.310000 | A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this | |
| CVE-2026-31431 | 7.8 | 99.91% | 1 | 100 | 2026-09-08T09:36:36 | In the Linux kernel, the following vulnerability has been resolved: crypto: alg | |
| CVE-2026-44756 | 10.0 | 0.32% | 4 | 0 | 2026-09-08T03:31:21 | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) pro | |
| CVE-2026-85704 | 3.7 | 0.27% | 1 | 0 | 2026-09-04T21:32:00 | A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3df | |
| CVE-2026-85703 | 6.5 | 0.33% | 1 | 0 | 2026-09-04T21:31:59 | A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca926 | |
| CVE-2026-75439 | None | 0.25% | 1 | 0 | 2026-09-04T21:31:53 | An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of servic | |
| CVE-2026-80903 | None | 0.16% | 1 | 0 | 2026-09-04T18:31:46 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: | |
| CVE-2026-80893 | None | 0.17% | 1 | 0 | 2026-09-04T18:31:46 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: | |
| CVE-2026-80905 | None | 0.15% | 1 | 0 | 2026-09-04T18:31:46 | In the Linux kernel, the following vulnerability has been resolved: net: tap: f | |
| CVE-2026-80892 | None | 0.17% | 1 | 0 | 2026-09-04T18:31:45 | In the Linux kernel, the following vulnerability has been resolved: erofs: cap | |
| CVE-2026-80884 | None | 0.16% | 1 | 0 | 2026-09-04T18:31:41 | In the Linux kernel, the following vulnerability has been resolved: ntb: Store | |
| CVE-2026-80873 | None | 0.15% | 1 | 0 | 2026-09-04T18:31:40 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: | |
| CVE-2026-17255 | 4.3 | 0.40% | 1 | 0 | 2026-09-04T18:31:40 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of | |
| CVE-2026-80872 | None | 0.15% | 1 | 0 | 2026-09-04T18:31:40 | In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/t | |
| CVE-2026-16660 | 5.3 | 0.36% | 1 | 0 | 2026-09-04T18:31:39 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a | |
| CVE-2026-80865 | None | 0.16% | 1 | 0 | 2026-09-04T18:31:34 | In the Linux kernel, the following vulnerability has been resolved: bpf: Add mi | |
| CVE-2026-80874 | 0 | 0.14% | 1 | 0 | 2026-09-04T17:16:59.390000 | In the Linux kernel, the following vulnerability has been resolved: arm64: dts: | |
| CVE-2026-69414 | 7.8 | 0.56% | 4 | 2 | 2026-09-03T22:18:19.793000 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-83548 | 10.0 | 4.67% | 1 | 3 | 2026-09-02T18:32:06 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla | |
| CVE-2026-82329 | 9.8 | 7.67% | 2 | 7 | template | 2026-09-02T18:31:57 | JFrog Artifactory contains an authentication weakness that, under default config |
| CVE-2026-82078 | 9.1 | 1.69% | 6 | 2 | 2026-09-01T04:18:02.160000 | An unsafe dynamic class loading vulnerability exists in the database connection | |
| CVE-2026-81578 | 9.8 | 1.62% | 6 | 2 | 2026-08-31T21:31:56 | An improper access control vulnerability exists in the web management interface | |
| CVE-2026-77236 | 7.3 | 0.11% | 1 | 0 | 2026-08-25T16:44:28.820000 | Missing minimum size validation in secure context allocation in FreeRTOS-Kernel | |
| CVE-2026-69836 | 10.0 | 1.55% | 1 | 2 | 2026-08-21T00:31:31 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a | |
| CVE-2026-19311 | 8.1 | 0.41% | 1 | 0 | 2026-08-12T21:31:44 | Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting p | |
| CVE-2025-14733 | 9.8 | 26.51% | 8 | 1 | 2026-08-10T21:33:00 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remot | |
| CVE-2026-20316 | 5.3 | 11.15% | 9 | 0 | 2026-08-01T05:16:55.973000 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2026-15409 | 10.0 | 84.54% | 4 | 6 | template | 2026-07-14T21:32:22 | A Server-side request forgery (SSRF) vulnerability has been identified in the SM |
| CVE-2026-54174 | 8.3 | 0.00% | 2 | 0 | 2026-07-10T21:43:06 | Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the | |
| CVE-2026-50553 | None | 0.38% | 1 | 0 | 2026-07-09T13:41:36 | ## Summary Note Mark validates book and note `slug` values with the OpenAPI/hum | |
| CVE-2026-49464 | 8.1 | 0.00% | 2 | 0 | 2026-07-08T21:12:01 | ## Impact In versions from 1.5.0 up to and including 3.0.0, any authenticated p | |
| CVE-2026-11387 | 9.8 | 2.21% | 2 | 2 | template | 2026-07-01T09:30:33 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart |
| CVE-2026-28576 | 5.5 | 0.15% | 2 | 1 | 2026-06-17T18:35:56 | In Contacts Provider, there is a possible way to access the contacts database du | |
| CVE-2019-0859 | 7.8 | 4.15% | 2 | 1 | 2026-06-17T02:09:03.317000 | An elevation of privilege vulnerability exists in Windows when the Win32k compon | |
| CVE-2026-43502 | 7.8 | 0.12% | 2 | 1 | 2026-06-01T18:31:32 | In the Linux kernel, the following vulnerability has been resolved: net/rds: ha | |
| CVE-2026-8510 | 7.5 | 0.21% | 2 | 0 | 2026-05-15T00:31:36 | Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 all | |
| CVE-2026-4800 | 8.1 | 2.76% | 1 | 2 | 2026-04-01T23:51:13 | ### Impact The fix for [CVE-2021-23337](https://github.com/advisories/GHSA-35jh | |
| CVE-2026-33671 | 7.5 | 0.40% | 1 | 1 | 2026-03-27T21:36:14 | ### Impact `picomatch` is vulnerable to Regular Expression Denial of Service (Re | |
| CVE-2026-33186 | 9.1 | 1.56% | 1 | 1 | 2026-03-25T18:12:09 | ### Impact _What kind of vulnerability is it? Who is impacted?_ It is an **Auth | |
| CVE-2026-0915 | 7.5 | 0.59% | 1 | 1 | 2026-01-20T18:31:56 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that spec | |
| CVE-2022-41352 | 9.8 | 95.48% | 2 | 4 | 2025-10-22T00:32:37 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacke | |
| CVE-2016-7255 | 7.8 | 80.97% | 2 | 5 | 2025-10-22T00:32:21 | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 | |
| CVE-2026-85706 | 0 | 0.00% | 30 | 5 | N/A | ||
| CVE-2026-61608 | 0 | 0.24% | 1 | 0 | N/A | ||
| CVE-2026-89066 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-71416 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-87719 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-87908 | 0 | 0.30% | 2 | 0 | N/A | ||
| CVE-2026-51990 | 0 | 0.00% | 2 | 1 | N/A | ||
| CVE-2026-73848 | 0 | 0.32% | 1 | 0 | N/A | ||
| CVE-2026-57166 | 0 | 0.44% | 1 | 0 | N/A | ||
| CVE-2026-16338 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-70416 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-63695 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-89049 | 0 | 0.36% | 4 | 0 | N/A | ||
| CVE-2026-88052 | 0 | 0.12% | 2 | 0 | N/A | ||
| CVE-2026-72898 | 0 | 94.22% | 2 | 8 | template | N/A | |
| CVE-2026-73453 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-84388 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-85012 | 0 | 1.06% | 1 | 0 | N/A | ||
| CVE-2026-77234 | 0 | 0.12% | 1 | 0 | N/A | ||
| CVE-2026-77237 | 0 | 0.13% | 1 | 0 | N/A | ||
| CVE-2026-77235 | 0 | 0.11% | 1 | 0 | N/A | ||
| CVE-2026-54694 | 0 | 0.28% | 1 | 0 | N/A |
updated 2026-09-11T22:16:47.993000
2 posts
CISA Malcolm (<=26.05.x) faces CRITICAL risk: CVE-2026-90456 allows admin takeover via default creds in inventory component if setup isn't run. Ensure unique passwords! https://radar.offseq.com/threat/cve-2026-90456-cwe-1392-use-of-default-credentials-in-cisa-malcolm-2141cfec27dc9c24 #OffSeq #CISAMalcolm #CVE202690456 #infosec
##CISA Malcolm (<=26.05.x) faces CRITICAL risk: CVE-2026-90456 allows admin takeover via default creds in inventory component if setup isn't run. Ensure unique passwords! https://radar.offseq.com/threat/cve-2026-90456-cwe-1392-use-of-default-credentials-in-cisa-malcolm-2141cfec27dc9c24 #OffSeq #CISAMalcolm #CVE202690456 #infosec
##updated 2026-09-11T22:16:37.813000
2 posts
🟠 CVE-2026-50013 - High (7.5)
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50013/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-50013 - High (7.5)
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50013/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T22:16:37.537000
2 posts
🟠 CVE-2026-49846 - High (7.5)
libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonica...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49846/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-49846 - High (7.5)
libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonica...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49846/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T21:32:08
7 posts
🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-42016 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42016)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016
⚠️ CVE-2026-42018 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42018)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42018
⚠️ CVE-2026-84869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-84869)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-84869
⚠️ CVE-2026-85706 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85706)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85706
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706
##CVE ID: CVE-2026-42018
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-11
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42018
Active exploitation chains CVE-2026-42018 and CVE-2026-42016 to bypass authentication on self-hosted JFrog Artifactory and deploy a Rust backdoor with C2. CVE-2026-82329 is also abused to create admin tokens. This enables full server takeover and supply chain compromise. #JFrog #Artifactory #SupplyChainSecurity
https://cyberworldops.eu/en/attackers-chain-jfrog-artifactory-flaws-to-deploy-rust-backdoor
##Attackers Exploit JFrog Flaws to Seize Admin Control
Cyber attackers have found a way to chain two JFrog Artifactory flaws, CVE-2026-42018 and CVE-2026-42016, to gain administrator control of self-hosted instances, putting your sensitive data at risk. This alarming exploit was recently reported by cloud security company Wiz.
#Jfrog #Artifactory #Cve202642018 #Cve202642016 #VulnerabilityChaining
##🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-42016 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42016)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016
⚠️ CVE-2026-42018 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42018)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42018
⚠️ CVE-2026-84869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-84869)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-84869
⚠️ CVE-2026-85706 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85706)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85706
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706
##CVE ID: CVE-2026-42018
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-11
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42018
Active exploitation chains CVE-2026-42018 and CVE-2026-42016 to bypass authentication on self-hosted JFrog Artifactory and deploy a Rust backdoor with C2. CVE-2026-82329 is also abused to create admin tokens. This enables full server takeover and supply chain compromise. #JFrog #Artifactory #SupplyChainSecurity
https://cyberworldops.eu/en/attackers-chain-jfrog-artifactory-flaws-to-deploy-rust-backdoor
##updated 2026-09-11T21:31:22
2 posts
🟠 CVE-2026-62112 - High (7.6)
Editor SQL Injection in Amelia <= 2.4.9 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62112/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-62112 - High (7.6)
Editor SQL Injection in Amelia <= 2.4.9 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62112/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T21:31:22
2 posts
🟠 CVE-2026-79393 - High (7.5)
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a deni...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-79393 - High (7.5)
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a deni...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T21:31:17
5 posts
🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-42016 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42016)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016
⚠️ CVE-2026-42018 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42018)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42018
⚠️ CVE-2026-84869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-84869)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-84869
⚠️ CVE-2026-85706 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85706)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85706
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706
##CVE ID: CVE-2026-84869
Vendor: ConnectWise
Product: ScreenConnect
Date Added: 2026-09-11
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84869
🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-42016 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42016)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016
⚠️ CVE-2026-42018 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42018)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42018
⚠️ CVE-2026-84869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-84869)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-84869
⚠️ CVE-2026-85706 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85706)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85706
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706
##CVE ID: CVE-2026-84869
Vendor: ConnectWise
Product: ScreenConnect
Date Added: 2026-09-11
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84869
ConnectWise ScreenConnect #zeroday CVE-2026-84869
Huntress article: https://www.huntress.com/blog/rogue-screenconnect-installations
Canadian Centre for Cyber Security: https://www.cyber.gc.ca/en/alerts-advisories/connectwise-security-advisory-av26-903
Open-source reporting indicates that CVE-2026-84869 is being exploited in the wild.
ConnectWise is silent on exploitation status: https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
##updated 2026-09-11T21:31:06
7 posts
🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-42016 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42016)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016
⚠️ CVE-2026-42018 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42018)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42018
⚠️ CVE-2026-84869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-84869)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-84869
⚠️ CVE-2026-85706 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85706)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85706
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706
##CVE ID: CVE-2026-42016
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-11
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42016
Active exploitation chains CVE-2026-42018 and CVE-2026-42016 to bypass authentication on self-hosted JFrog Artifactory and deploy a Rust backdoor with C2. CVE-2026-82329 is also abused to create admin tokens. This enables full server takeover and supply chain compromise. #JFrog #Artifactory #SupplyChainSecurity
https://cyberworldops.eu/en/attackers-chain-jfrog-artifactory-flaws-to-deploy-rust-backdoor
##Attackers Exploit JFrog Flaws to Seize Admin Control
Cyber attackers have found a way to chain two JFrog Artifactory flaws, CVE-2026-42018 and CVE-2026-42016, to gain administrator control of self-hosted instances, putting your sensitive data at risk. This alarming exploit was recently reported by cloud security company Wiz.
#Jfrog #Artifactory #Cve202642018 #Cve202642016 #VulnerabilityChaining
##🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-42016 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42016)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016
⚠️ CVE-2026-42018 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42018)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42018
⚠️ CVE-2026-84869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-84869)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-84869
⚠️ CVE-2026-85706 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85706)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85706
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706
##CVE ID: CVE-2026-42016
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-11
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42016
Active exploitation chains CVE-2026-42018 and CVE-2026-42016 to bypass authentication on self-hosted JFrog Artifactory and deploy a Rust backdoor with C2. CVE-2026-82329 is also abused to create admin tokens. This enables full server takeover and supply chain compromise. #JFrog #Artifactory #SupplyChainSecurity
https://cyberworldops.eu/en/attackers-chain-jfrog-artifactory-flaws-to-deploy-rust-backdoor
##updated 2026-09-11T21:17:56.740000
2 posts
Red Hat Advanced Cluster Management for Kubernetes 2 is affected by CVE-2026-89060 (HIGH, CVSS 7.7): managed-cluster identities may access hub Secrets outside their namespace due to authorization flaws. Monitor Red Hat and restrict permissions. https://radar.offseq.com/threat/cve-2026-89060-incorrect-behavior-order-authorization-before-parsing-and-canonicalization-in-red-hat-70cd9b74c8429f45 #OffSeq #Kubernetes #RedHat
##Red Hat Advanced Cluster Management for Kubernetes 2 is affected by CVE-2026-89060 (HIGH, CVSS 7.7): managed-cluster identities may access hub Secrets outside their namespace due to authorization flaws. Monitor Red Hat and restrict permissions. https://radar.offseq.com/threat/cve-2026-89060-incorrect-behavior-order-authorization-before-parsing-and-canonicalization-in-red-hat-70cd9b74c8429f45 #OffSeq #Kubernetes #RedHat
##updated 2026-09-11T21:17:16.053000
2 posts
🟠 CVE-2026-77807 - High (7.5)
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77807 - High (7.5)
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T20:20:08.460000
1 posts
🐧 SIGINT // Ubuntu Watch — 2026-09-12
Ring buffer race between subbuf resize and readers can corrupt trace data or crash the kernel. If you rely on ftrace or perf for debugging on your boxes, get this patched before it bites you mid-trace.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89771/
##updated 2026-09-11T20:18:54.030000
2 posts
🔴 CVE-2026-79395 - Critical (9.8)
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentica...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79395/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-79395 - Critical (9.8)
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentica...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79395/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T20:17:14.330000
2 posts
🟠 CVE-2026-54135 - High (7.5)
AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Den...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54135/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54135 - High (7.5)
AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Den...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54135/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T20:17:14.060000
2 posts
🔴 CVE-2026-53952 - Critical (9.8)
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a n...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53952/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-53952 - Critical (9.8)
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a n...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53952/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T18:31:32
2 posts
🟠 CVE-2026-89262 - High (7.5)
MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89262/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89262 - High (7.5)
MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89262/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T18:31:31
2 posts
🟠 CVE-2026-89260 - High (7.5)
MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89260/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89260 - High (7.5)
MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89260/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T16:17:50.200000
2 posts
🟠 CVE-2026-89177 - High (8.8)
WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89177/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89177 - High (8.8)
WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89177/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T16:17:43.143000
2 posts
MS selling "MDASH" as having fixed their TCP/IP stack, a day after a critical DNS CVE comes out without a fix.
##MS selling "MDASH" as having fixed their TCP/IP stack, a day after a critical DNS CVE comes out without a fix.
##updated 2026-09-11T15:51:10.693000
1 posts
CVE-2026-57162: Stack buffer overflow in PJSIP SRTP/SDES when processing crafted crypto attributes during SDP negotiation. CVSS: N/A, unpatched. If you use SRTP with SDES keying, you are exposed. Patch immediately. Details: https://www.valtersit.com/cve/CVE-2026-57162/ #CVE #info
##updated 2026-09-11T15:32:48
4 posts
🔴 CVE-2026-80462 - Critical (10)
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80462/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL vuln (CVE-2026-80462) in Progress Chef Automate (4.13.516 – 4.13.519): API gateway auth bypass enables unauth’d privilege escalation. Restrict API access & review logs until patch confirmed. https://radar.offseq.com/threat/cve-2026-80462-cwe-306-missing-authentication-for-critical-function-in-progress-software-chef-automate-cfce7409b20e5b5f #OffSeq #ChefAutomate #vuln #CVE202680462
##🔴 CVE-2026-80462 - Critical (10)
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80462/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL vuln (CVE-2026-80462) in Progress Chef Automate (4.13.516 – 4.13.519): API gateway auth bypass enables unauth’d privilege escalation. Restrict API access & review logs until patch confirmed. https://radar.offseq.com/threat/cve-2026-80462-cwe-306-missing-authentication-for-critical-function-in-progress-software-chef-automate-cfce7409b20e5b5f #OffSeq #ChefAutomate #vuln #CVE202680462
##updated 2026-09-11T15:32:48
2 posts
Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line
Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.
**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/fortinet-patches-critical-authentication-bypass-and-proxy-flaws-across-product-line-t-c-t-4-1/gD2P6Ple2L
Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line
Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.
**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/fortinet-patches-critical-authentication-bypass-and-proxy-flaws-across-product-line-t-c-t-4-1/gD2P6Ple2L
updated 2026-09-11T15:32:40
2 posts
Cloud Foundry UAA hit by CRITICAL vuln (CVE-2026-47839, CVSS 9.2): OIDC users with wildcard group mapping can gain uaa.admin. Review configs, avoid wildcards, and monitor for patches. https://radar.offseq.com/threat/cve-2026-47839-vulnerability-in-cloud-foundry-foundation-uaa-fe07e0d8fe092d86 #OffSeq #CloudSecurity #CVE202647839 #Infosec
##Cloud Foundry UAA hit by CRITICAL vuln (CVE-2026-47839, CVSS 9.2): OIDC users with wildcard group mapping can gain uaa.admin. Review configs, avoid wildcards, and monitor for patches. https://radar.offseq.com/threat/cve-2026-47839-vulnerability-in-cloud-foundry-foundation-uaa-fe07e0d8fe092d86 #OffSeq #CloudSecurity #CVE202647839 #Infosec
##updated 2026-09-11T15:32:35
1 posts
CATTE OVERFLOW I REPEAT CATTE OVERFLOW THIS IS NOT A DRILL :catte:
https://nvd.nist.gov/vuln/detail/cve-2026-21096
##Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
updated 2026-09-11T15:17:07.097000
2 posts
🟠 CVE-2026-87958 - High (8.1)
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-87958 - High (8.1)
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87958/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T15:17:04.913000
2 posts
🟠 CVE-2026-80469 - High (8.3)
An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of
attacker-controlled code. User interaction is required.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80469/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80469 - High (8.3)
An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of
attacker-controlled code. User interaction is required.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80469/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T14:17:36.847000
2 posts
🟠 CVE-2026-89212 - High (8.6)
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (includ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89212/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89212 - High (8.6)
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (includ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89212/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T13:17:49.237000
1 posts
🔄 CSAF advisory updated (version 2.0.0)
VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)
Changes: corrected version
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2026-09-11T12:52:29.533000
4 posts
🚨 [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-67277 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-67277)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: https://mikrotik.com/supportsec/september-2026-vulnerability/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-67277
⚠️ CVE-2026-86060 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-86060)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-86060
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260910 #cisa20260910 #cve_2026_67277 #cve_2026_86060 #cve202667277 #cve202686060
##CVE ID: CVE-2026-67277
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67277
🚨 [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-67277 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-67277)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: https://mikrotik.com/supportsec/september-2026-vulnerability/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-67277
⚠️ CVE-2026-86060 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-86060)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-86060
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260910 #cisa20260910 #cve_2026_67277 #cve_2026_86060 #cve202667277 #cve202686060
##CVE ID: CVE-2026-67277
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67277
updated 2026-09-11T12:52:16.507000
7 posts
1 repos
MikroTik RouterOS Under Active Attack: CISA Sounds the Alarm Over a Critical Privilege-Escalation Flaw + Video
A Dangerous Warning for Network Defenders A critical security warning has landed for organizations running MikroTik RouterOS, and this is not a vulnerability that defenders can afford to leave in the ordinary patch queue. CISA has added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog after exploitation was observed in the wild, placing the flaw…
##Executive alert: CVE-2026-86060 actively threatens MikroTik RouterOS infrastructure. Review board-ready risk evaluation protocols, network asset integrity measures, and strategic remediation steps to protect your enterprise value today.
##🚨 [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-67277 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-67277)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: https://mikrotik.com/supportsec/september-2026-vulnerability/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-67277
⚠️ CVE-2026-86060 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-86060)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-86060
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260910 #cisa20260910 #cve_2026_67277 #cve_2026_86060 #cve202667277 #cve202686060
##CVE ID: CVE-2026-86060
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86060
Executive alert: CVE-2026-86060 actively threatens MikroTik RouterOS infrastructure. Review board-ready risk evaluation protocols, network asset integrity measures, and strategic remediation steps to protect your enterprise value today.
##🚨 [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-67277 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-67277)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: https://mikrotik.com/supportsec/september-2026-vulnerability/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-67277
⚠️ CVE-2026-86060 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-86060)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-86060
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260910 #cisa20260910 #cve_2026_67277 #cve_2026_86060 #cve202667277 #cve202686060
##CVE ID: CVE-2026-86060
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86060
updated 2026-09-11T12:33:34
2 posts
CVE-2026-89259 (CRITICAL): gohugoio Hugo <0.165.0 lets Node tools like TailwindCSS bypass security.exec.allow list, enabling file access outside project dirs. Upgrade to 0.165.0 or restrict exec.allow in hugo.toml. https://radar.offseq.com/threat/cve-2026-89259-execution-with-unnecessary-privileges-in-gohugoio-hugo-3319ecf718eb9ea0 #OffSeq #CVE #Hugo #InfoSec
##CVE-2026-89259 (CRITICAL): gohugoio Hugo <0.165.0 lets Node tools like TailwindCSS bypass security.exec.allow list, enabling file access outside project dirs. Upgrade to 0.165.0 or restrict exec.allow in hugo.toml. https://radar.offseq.com/threat/cve-2026-89259-execution-with-unnecessary-privileges-in-gohugoio-hugo-3319ecf718eb9ea0 #OffSeq #CVE #Hugo #InfoSec
##updated 2026-09-11T12:33:26
2 posts
CVE-2026-86781: SSL Zen plugin (<4.7.40) has a CRITICAL auth flaw — any WP user can download TLS private key & certs, risking site impersonation. Patch to 4.7.40+ now. https://radar.offseq.com/threat/cve-2026-86781-cwe-287-improper-authentication-in-ssl-zen-ssl-certificate-installer-https-redirects-fc40efb64c1b1964 #OffSeq #WordPress #Vuln #TLS
##CVE-2026-86781: SSL Zen plugin (<4.7.40) has a CRITICAL auth flaw — any WP user can download TLS private key & certs, risking site impersonation. Patch to 4.7.40+ now. https://radar.offseq.com/threat/cve-2026-86781-cwe-287-improper-authentication-in-ssl-zen-ssl-certificate-installer-https-redirects-fc40efb64c1b1964 #OffSeq #WordPress #Vuln #TLS
##updated 2026-09-11T09:31:31
2 posts
🟠 CVE-2026-89178 - High (8.8)
WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student compute...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89178/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89178 - High (8.8)
WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student compute...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89178/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T09:31:31
2 posts
🟠 CVE-2026-89176 - High (8.8)
WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can di...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89176/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89176 - High (8.8)
WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can di...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89176/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T09:31:31
2 posts
🟠 CVE-2026-89174 - High (7.5)
Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89174/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89174 - High (7.5)
Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89174/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T06:31:14
2 posts
CVE-2026-8778 (CRITICAL): MIPL Grouped Checkout Fields for WooCommerce ≤1.2.2 suffers from unrestricted file upload due to missing file type validation. Remote code execution possible by unauthenticated attackers. Restrict uploads & monitor! https://radar.offseq.com/threat/cve-2026-8778-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-mulika-mipl-grouped-checkout-a571f695f51796b8 #OffSeq #WordPress #CVE20268778
##CVE-2026-8778 (CRITICAL): MIPL Grouped Checkout Fields for WooCommerce ≤1.2.2 suffers from unrestricted file upload due to missing file type validation. Remote code execution possible by unauthenticated attackers. Restrict uploads & monitor! https://radar.offseq.com/threat/cve-2026-8778-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-mulika-mipl-grouped-checkout-a571f695f51796b8 #OffSeq #WordPress #CVE20268778
##updated 2026-09-11T04:17:34.343000
1 posts
🟠 CVE-2026-19584 - High (7.7)
Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19584/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T04:17:13.060000
8 posts
Palo-Alto are calling resellers and asking them to call customers to tell them to update their Palo-Alto PA and VM firewalls to cover CVE-2026-0310 - an unauthenticated XML parsing vulneraility which causes a buffer overflow leading to code execution, on the PA (physical) firewalls via the dataplane.
https://security.paloaltonetworks.com/CVE-2026-0310
HT @databeestje
##CVE-2026-0310: PAN-OS Buffer Overflow Can Enable Root RCE on PA-Series Firewalls
#CVE_2026_0310
https://socprime.com/blog/cve-2026-0310-analysis/
Palo-Alto are calling resellers and asking them to call customers to tell them to update their Palo-Alto PA and VM firewalls to cover CVE-2026-0310 - an unauthenticated XML parsing vulneraility which causes a buffer overflow leading to code execution, on the PA (physical) firewalls via the dataplane.
https://security.paloaltonetworks.com/CVE-2026-0310
HT @databeestje
##CVE-2026-0310: PAN-OS Buffer Overflow Can Enable Root RCE on PA-Series Firewalls
#CVE_2026_0310
https://socprime.com/blog/cve-2026-0310-analysis/
RE: https://infosec.exchange/@cR0w/117241961119105876
Seriously, maybe take a good look at CVE-2026-0310.
CVSS-BT: 7.2 / **CVSS-B: 9.2** (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red)
A new PAN-OS buffer overflow flaw, tracked as CVE-2026-0310, exposes firewalls to remote code execution. Patch your network devices immediately.
#PANOS #BufferOverflow #CVE20260310 #Cybersecurity #PaloAltoNetworks
##RE: https://infosec.exchange/@cR0w/117236916712662443
lol. lmao even.
##Broadcom has a long list of advisories today for high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom #Linux
Palo Alto:
Palo Alto has several advisories, one of them critical:
CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing https://security.paloaltonetworks.com/CVE-2026-0310
More: https://security.paloaltonetworks.com/
Cisco:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 @TalosSecurity #Cisco
Dell:
A Dell release that impacts multiple CVEs: Security Update for Dell PowerScale OneFS Multiple Third-Party Component Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000474822/dsa-2026-237-security-update-for-dell-powerscale-onefs-multiple-third-party-component-vulnerabilities #Dell
Posted yesterday:
Apple:
Several releases were posted yesterday https://support.apple.com/en-us/100100 #Apple #iOS
AMD:
AMD: Linux GPU Driver NULL Pointer Dereference https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6034.html #AMD
Adobe:
Adobe has a long list of updates here https://helpx.adobe.com/security/security-bulletin.html #Adobe #infosec #vulnerability
##updated 2026-09-11T00:31:23
4 posts
CVE-2026-82107: CRITICAL vuln in IBM DataStage on Cloud Pak for Data 5.4.0.0 (CVSS 9.6). Authenticated attackers can bypass authentication & access sensitive data. No patch — limit access & monitor for abuse. https://radar.offseq.com/threat/cve-2026-82107-cwe-287-improper-authentication-in-ibm-datastage-on-cloud-pak-for-data-adaefa5e3ef6716b #OffSeq #Vuln #IBM #InfoSec
##🔴 CVE-2026-82107 - Critical (9.6)
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82107/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-82107: CRITICAL vuln in IBM DataStage on Cloud Pak for Data 5.4.0.0 (CVSS 9.6). Authenticated attackers can bypass authentication & access sensitive data. No patch — limit access & monitor for abuse. https://radar.offseq.com/threat/cve-2026-82107-cwe-287-improper-authentication-in-ibm-datastage-on-cloud-pak-for-data-adaefa5e3ef6716b #OffSeq #Vuln #IBM #InfoSec
##🔴 CVE-2026-82107 - Critical (9.6)
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82107/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T00:31:23
4 posts
CVE-2026-82100: CRITICAL path traversal in IBM DataStage on Cloud Pak for Data 5.4.0.0 (CVSS 9.6). Remote authenticated attackers can cause denial of service via improper directory handling. Restrict access & monitor until patch confirmed. https://radar.offseq.com/threat/cve-2026-82100-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-2ededf9f5c4eff65 #OffSeq #CVE202682100 #IBM #infosec
##🔴 CVE-2026-82100 - Critical (9.6)
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82100/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-82100: CRITICAL path traversal in IBM DataStage on Cloud Pak for Data 5.4.0.0 (CVSS 9.6). Remote authenticated attackers can cause denial of service via improper directory handling. Restrict access & monitor until patch confirmed. https://radar.offseq.com/threat/cve-2026-82100-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-2ededf9f5c4eff65 #OffSeq #CVE202682100 #IBM #infosec
##🔴 CVE-2026-82100 - Critical (9.6)
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82100/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T00:31:23
2 posts
🟠 CVE-2026-81940 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81940 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T00:31:23
2 posts
🟠 CVE-2026-84889 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84889/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84889 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84889/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T00:31:16
2 posts
🟠 CVE-2026-86093 - High (7.5)
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86093/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86093 - High (7.5)
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86093/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-11T00:31:12
2 posts
CVE-2026-19646 (CRITICAL, CVSS 9.1) affects IBM Common Licensing 9.0.x & ART 9.0. Improper Host header validation enables remote redirection to attacker domains. No patch yet — monitor IBM guidance. https://radar.offseq.com/threat/cve-2026-19646-cwe-1149-sei-cert-oracle-secure-coding-standard-for-java-guidelines-15-platform-9a01f253f72c9218 #OffSeq #Vuln #IBM #InfoSec
##CVE-2026-19646 (CRITICAL, CVSS 9.1) affects IBM Common Licensing 9.0.x & ART 9.0. Improper Host header validation enables remote redirection to attacker domains. No patch yet — monitor IBM guidance. https://radar.offseq.com/threat/cve-2026-19646-cwe-1149-sei-cert-oracle-secure-coding-standard-for-java-guidelines-15-platform-9a01f253f72c9218 #OffSeq #Vuln #IBM #InfoSec
##updated 2026-09-10T22:45:14
2 posts
🟠 CVE-2026-88045 - High (7.5)
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88045/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-88045 - High (7.5)
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88045/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T21:31:46
6 posts
🚨 CVE-2026-89094: Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
CVSS: 9.9
Foregejo Update/Notes: https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/16.0.4.md
##A critical Forgejo remote code execution flaw, tracked as CVE-2026-89094, threatens Git servers. Patch this Forgejo remote code execution bug today.
#Forgejo #RemoteCodeExecution #CVE202689094 #Cybersecurity #DevSecOps
##RE: https://infosec.exchange/@cR0w/117247864965166656
CVE for this one:
https://nvd.nist.gov/vuln/detail/cve-2026-89094
sev:CRIT 9.9 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
##Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
🚨 CVE-2026-89094: Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
CVSS: 9.9
Foregejo Update/Notes: https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/16.0.4.md
##A critical Forgejo remote code execution flaw, tracked as CVE-2026-89094, threatens Git servers. Patch this Forgejo remote code execution bug today.
#Forgejo #RemoteCodeExecution #CVE202689094 #Cybersecurity #DevSecOps
##RE: https://infosec.exchange/@cR0w/117247864965166656
CVE for this one:
https://nvd.nist.gov/vuln/detail/cve-2026-89094
sev:CRIT 9.9 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
##Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
updated 2026-09-10T21:31:41
2 posts
🟠 CVE-2026-89054 - High (8.2)
A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @patch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89054/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89054 - High (8.2)
A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @patch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89054/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T21:31:41
2 posts
🔴 CVE-2026-89086 - Critical (9.1)
In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89086/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-89086 - Critical (9.1)
In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89086/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T21:23:26
1 posts
🟠 CVE-2026-87016 - High (8.1)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87016/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T21:22:13
2 posts
A critical CVSS 9.5 OmniRoute RCE flaw (CVE-2026-88062) has public PoC exploit code available. Upgrade your AI gateway immediately to prevent compromises.
##A critical CVSS 9.5 OmniRoute RCE flaw (CVE-2026-88062) has public PoC exploit code available. Upgrade your AI gateway immediately to prevent compromises.
##updated 2026-09-10T19:58:20.507000
1 posts
🟠 CVE-2026-87794 - High (8.4)
bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with cra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87794/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T19:54:25.810000
2 posts
🔴 CVE-2026-88044 - Critical (9.1)
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88044/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-88044 - Critical (9.1)
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88044/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T18:33:12
2 posts
Three critical Apache Camel K vulnerabilities, including CVE-2026-80352, allow code injection and eval injection. Patch these critical flaws immediately.
##Three critical Apache Camel K vulnerabilities, including CVE-2026-80352, allow code injection and eval injection. Patch these critical flaws immediately.
##updated 2026-09-10T18:33:11
1 posts
Critical Apache Artemis vulnerabilities, including CVE-2026-67593 and other ActiveMQ Artemis flaws, expose systems to denial of service and data exposure.
#ApacheArtemis #Cybersecurity #Vulnerabilities #ActiveMQ #CVE202667593
##updated 2026-09-10T18:33:05
2 posts
🟠 CVE-2026-89046 - High (8.2)
zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and rea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89046/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89046 - High (8.2)
zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and rea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89046/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T18:33:04
2 posts
Dell patched critical Dell ThinOS vulnerabilities, including CVE-2026-81467. Update your ThinOS clients now to stop remote code execution attacks.
##Dell patched critical Dell ThinOS vulnerabilities, including CVE-2026-81467. Update your ThinOS clients now to stop remote code execution attacks.
##updated 2026-09-10T18:33:04
2 posts
🔴 CVE-2026-89042 - Critical (9.1)
passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89042/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-89042 - Critical (9.1)
passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89042/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T18:33:04
2 posts
🔴 CVE-2026-85228 - Critical (9.1)
An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a de...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85228/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85228 - Critical (9.1)
An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a de...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85228/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T18:32:56
3 posts
Critical CSF Firewall Vulnerability Exposes Linux Servers to Unauthenticated Remote Code Execution + Video
A Dangerous Weakness in a Trusted Linux Security Tool A security tool designed to protect Linux servers has itself become a potential entry point for attackers. A critical vulnerability in ConfigServer Security & Firewall (CSF), tracked as CVE-2026-65638, can allow an unauthenticated remote attacker to execute arbitrary commands on vulnerable systems. The flaw…
##Two critical CSF plugin vulnerabilities, CVE-2026-65638 and CVE-2026-65639, allow remote code execution. Patch your ConfigServer firewall immediately.
#CSFPlugin #Cybersecurity #CVE202665639 #Vulnerabilities #InfoSec
##Two critical CSF plugin vulnerabilities, CVE-2026-65638 and CVE-2026-65639, allow remote code execution. Patch your ConfigServer firewall immediately.
#CSFPlugin #Cybersecurity #CVE202665639 #Vulnerabilities #InfoSec
##updated 2026-09-10T18:32:56
2 posts
Two critical CSF plugin vulnerabilities, CVE-2026-65638 and CVE-2026-65639, allow remote code execution. Patch your ConfigServer firewall immediately.
#CSFPlugin #Cybersecurity #CVE202665639 #Vulnerabilities #InfoSec
##Two critical CSF plugin vulnerabilities, CVE-2026-65638 and CVE-2026-65639, allow remote code execution. Patch your ConfigServer firewall immediately.
#CSFPlugin #Cybersecurity #CVE202665639 #Vulnerabilities #InfoSec
##updated 2026-09-10T17:48:32.410000
1 posts
🟠 CVE-2026-79322 - High (8.6)
SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79322/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T16:18:11.693000
2 posts
🟠 CVE-2026-88889 - High (7.8)
Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inj...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88889/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-88889 - High (7.8)
Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inj...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88889/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T16:18:10.767000
2 posts
🟠 CVE-2026-88290 - High (7.5)
GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88290/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-88290 - High (7.5)
GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88290/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T16:17:07.727000
2 posts
CVE-2026-13745: CRITICAL vuln (CVSS 9.2) in Google Cloud Gemini CLI allows arbitrary code execution via untrusted .env files overriding GEMINI_CLI_HOME. Review .env file usage & restrict access. More info: https://radar.offseq.com/threat/cve-2026-13745-cwe-20-improper-input-validation-in-google-cloud-gemini-cli-2874a8a8cddc669d #OffSeq #GoogleCloud #Vulnerability #InfoSec
##CVE-2026-13745: CRITICAL vuln (CVSS 9.2) in Google Cloud Gemini CLI allows arbitrary code execution via untrusted .env files overriding GEMINI_CLI_HOME. Review .env file usage & restrict access. More info: https://radar.offseq.com/threat/cve-2026-13745-cwe-20-improper-input-validation-in-google-cloud-gemini-cli-2874a8a8cddc669d #OffSeq #GoogleCloud #Vulnerability #InfoSec
##updated 2026-09-10T15:53:23.707000
2 posts
CVE-2026-87911 (CVSS 9.6): CRITICAL OS command injection in AWS Labs postgres MCP Server (<1.1.7). Unauthenticated attackers can execute OS commands via crafted SQL. Upgrade to 1.1.7+ ASAP. https://radar.offseq.com/threat/cve-2026-87911-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-5896283731c57124 #OffSeq #AWS #PostgreSQL #Vuln
##🔴 CVE-2026-87911 - Critical (9.6)
An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-manage...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87911/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T15:43:03.760000
1 posts
CVE-2026-88069: Path traversal in pandora-analysis pandora (<=1.12.7) allows attackers to overwrite system/app files via crafted archives. Severity: CRITICAL (CVSS 9.3). No patch confirmed — monitor vendor updates. https://radar.offseq.com/threat/cve-2026-88069-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-87b56121b9b3446f #OffSeq #CVE202688069 #vuln #infosec
##updated 2026-09-10T15:33:28
2 posts
🟠 CVE-2026-88890 - High (8.5)
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88890/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-88890 - High (8.5)
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88890/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T15:33:28
2 posts
CRITICAL: CVE-2026-88887 in renovatebot renovate enables open redirect — malicious registries can steal credentials using crafted Link headers. Upgrade to 44.11.2+ ASAP. More info: https://radar.offseq.com/threat/cve-2026-88887-url-redirection-to-untrusted-site-open-redirect-in-renovatebot-renovate-875e981802aea06b #OffSeq #CVE202688887 #SupplyChain #ContainerSecurity
##CRITICAL: CVE-2026-88887 in renovatebot renovate enables open redirect — malicious registries can steal credentials using crafted Link headers. Upgrade to 44.11.2+ ASAP. More info: https://radar.offseq.com/threat/cve-2026-88887-url-redirection-to-untrusted-site-open-redirect-in-renovatebot-renovate-875e981802aea06b #OffSeq #CVE202688887 #SupplyChain #ContainerSecurity
##updated 2026-09-10T15:33:27
2 posts
🟠 CVE-2026-88891 - High (8.3)
OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedul...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88891/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-88891 - High (8.3)
OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedul...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88891/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T15:33:12
1 posts
1 repos
🟠 CVE-2026-73786 - High (7.5)
A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73786/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T15:32:56
1 posts
updated 2026-09-10T15:10:20
1 posts
🟠 CVE-2026-87995 - High (8.7)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-scripts an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87995/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T14:50:07.813000
1 posts
🟠 CVE-2026-87996 - High (7.7)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Pla...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87996/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T14:50:07.813000
1 posts
🟠 CVE-2026-87011 - High (7.5)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87011/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T12:48:10.453000
4 posts
2 repos
Safely detect Citrix NetScaler SAML auth bypass (CVE-2026-19490) https://github.com/BishopFox/CVE-2026-19490-check
##Safely detect Citrix NetScaler SAML auth bypass (CVE-2026-19490) https://github.com/BishopFox/CVE-2026-19490-check
##🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-25249 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-25249)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: https://fortiguard.fortinet.com/psirt/FG-IR-25-084 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-25249
⚠️ CVE-2026-19490 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19490)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-19490
⚠️ CVE-2026-20079 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20079)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20079
⚠️ CVE-2026-87491 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-87491)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-87491
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491
##CVE ID: CVE-2026-19490
Vendor: Citrix
Product: NetScaler
Date Added: 2026-09-09
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19490
updated 2026-09-10T12:31:26
2 posts
CVE-2026-78082: SP Property extension for Joomla v1.0.0-4.1.3 suffers CRITICAL SQL injection (CVSS 9.3). Unauthenticated attackers can extract DB data via blind injection. Patch status unknown — check vendor guidance. https://radar.offseq.com/threat/cve-2026-78082-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-in-b1e5ff60df4f2663 #OffSeq #Joomla #SQLi #Infosec
##CVE-2026-78082: SP Property extension for Joomla v1.0.0-4.1.3 suffers CRITICAL SQL injection (CVSS 9.3). Unauthenticated attackers can extract DB data via blind injection. Patch status unknown — check vendor guidance. https://radar.offseq.com/threat/cve-2026-78082-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-in-b1e5ff60df4f2663 #OffSeq #Joomla #SQLi #Infosec
##updated 2026-09-10T09:31:48
2 posts
🔴 CVE-2026-8323 - Critical (9.3)
URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data.
This issue affects Access Control System: before Versiyon 2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8323/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-8323 - Critical (9.3)
URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data.
This issue affects Access Control System: before Versiyon 2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8323/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T09:31:44
2 posts
🟠 CVE-2026-88289 - High (7.5)
GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88289/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-88289 - High (7.5)
GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88289/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T06:32:50
1 posts
CVE-2026-87931 | CRITICAL buffer overflow in Pavlok Behavioral Conditioning Wearable (Apple Notification Center Service Event Handler). Exploitable locally, no patch or vendor response. Limit device network access. Details: https://radar.offseq.com/threat/cve-2026-87931-buffer-overflow-in-behavioral-technology-group-pavlok-behavioral-conditioning-wearable-98a2d4c4edee7864 #OffSeq #CVE202687931 #IoTSecurity
##updated 2026-09-10T06:31:54
1 posts
updated 2026-09-10T06:31:51
1 posts
🟠 CVE-2026-15019 - High (7.5)
The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the content...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15019/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T06:31:42
1 posts
🟠 CVE-2026-14873 - High (8)
The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their detail...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14873/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-10T04:18:18.390000
9 posts
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/
##Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise. #CyberSecurity #CheckPoint #VPN #RCE
https://cyberworldops.eu/en/check-point-patches-two-critical-vpn-certificate-flaws-allowing
##Check Point Rushes to Patch Two Critical VPN Vulnerabilities With 98 CVSS Scores + Video
A Serious Warning for Security Gateway Operators Check Point has moved quickly to patch two critical vulnerabilities affecting its VPN certificate-processing technology, closing a potentially dangerous path that could allow an unauthenticated remote attacker to execute code on vulnerable security infrastructure. The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, were…
##Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/
##Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise. #CyberSecurity #CheckPoint #VPN #RCE
https://cyberworldops.eu/en/check-point-patches-two-critical-vpn-certificate-flaws-allowing
##[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510
Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.
#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability
##It has been :zero_percent: days since an ASN.1 decoding vuln.
It has been :zero_percent: days since an overflow vuln in a corp VPN.
It has been :zero_percent: days since a vuln with "Quantum" in the system name.
They are all the same vuln.
https://nvd.nist.gov/vuln/detail/cve-2026-85103
##A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103.
##CRITICAL CVE-2026-85103 in Check Point Quantum Security Gateway: Heap-based buffer overflow in VPN certificate ASN.1 decoding allows unauthenticated RCE. Patch pending — monitor vendor. https://radar.offseq.com/threat/cve-2026-85103-cwe-122-heap-based-buffer-overflow-in-checkpoint-quantum-security-gateway-769c0bcac8d0fa47 #OffSeq #CheckPoint #infosec #Vuln
##updated 2026-09-10T04:18:04.630000
3 posts
3 repos
https://github.com/axedos/CVE-2026-67401
https://github.com/jithinkrishnanrs/CVE-2026-67401-cPanel-EmailTrack-SQLi
📢 [VULN] Une faille cPanel distribue des accès root - CVE-2026-67401
Une injection SQL dans EmailTrack de cPanel permet à un client authentifié avec droits mail d'écrire des fichiers arbitraires et d'exécuter du code en root La CVE-2026-67401 obtient un score de 9,9 sur 10 car les dégâts débordent du compte d'entrée vers tous les sites hébergés sur le même serveur Aucune exploitation…
🔗 https://korben.info/cpanel-faille-prise-controle-compte-hebergement.html
💬 discussion : https://infosec.pub/post/52151269
#CVE #Cyberveille
I can't imagine trying to manage cPanel on the public Internet in 2026, especially on shared systems.
https://nvd.nist.gov/vuln/detail/cve-2026-67401
sev:CRIT 9.9 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
##A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
https://thecybersecguru.com/news/cve-2026-67401-cpanel-emailtrack/
##updated 2026-09-10T03:30:27
1 posts
2 repos
CVE-2026-18351 (CRITICAL): addonsorg Drag and Drop File Upload for Elementor Forms <=1.6.0 lets unauthenticated attackers upload arbitrary files — enabling RCE. Restrict or disable plugin use until remediation. https://radar.offseq.com/threat/cve-2026-18351-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-addonsorg-drag-and-drop-file-158dc74bccbdf605 #OffSeq #WordPress #Vuln #RCE
##updated 2026-09-10T03:30:26
1 posts
CVE-2026-19583: CRITICAL vuln in Rapid7 Velociraptor (<0.77.2) allows users w/ artifact scheduling rights to execute privileged artifacts like Linux.Sys.BashShell — risking full compromise. Restrict permissions, monitor activity. https://radar.offseq.com/threat/cve-2026-19583-cwe-732-incorrect-permission-assignment-for-critical-resource-in-rapid7-velociraptor-f6df828b1d19e549 #OffSeq #Vuln #Infosec
##updated 2026-09-10T00:30:34
1 posts
🟠 CVE-2026-15913 - High (7.7)
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15913/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-09T21:32:03
1 posts
🟠 CVE-2026-79324 - High (7.5)
Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by itera...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79324/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-09T21:31:57
1 posts
🟠 CVE-2026-79323 - High (7.5)
Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79323/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-09T21:31:35
10 posts
1 repos
https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter
🏆 New Achievement! Seventh Inning Slaughter!
CHANGELOG v2026.09.09 — Google Chrome (Unscheduled Hotfix #7)
FIXED: Nothing you did. ADDED: CVE-2026-87491, an out-of-bounds write in the V8 JavaScript and WebAssembly engine, actively exploited in the wild via crafted HTML pages. Remote attackers can execute arbitrary code inside your browser sandbox, corrupt the heap, expose sensitive data, or simply crash the party. This is the seventh actively exploited Chrome zero-day patched this year. (1/2)
##⚪️ Google Chrome Patches Another Zero-Day Vulnerability
🗨️ Google developers have released an update for the Chrome browser that fixes 230 vulnerabilities, including a zero-day flaw in the V8 engine (CVE-2026-87491) that is already being exploited in attacks. The bug allows a remote attacker to achieve arbitrary code…
##🏆 New Achievement! Seventh Inning Slaughter!
CHANGELOG v2026.09.09 — Google Chrome (Unscheduled Hotfix #7)
FIXED: Nothing you did. ADDED: CVE-2026-87491, an out-of-bounds write in the V8 JavaScript and WebAssembly engine, actively exploited in the wild via crafted HTML pages. Remote attackers can execute arbitrary code inside your browser sandbox, corrupt the heap, expose sensitive data, or simply crash the party. This is the seventh actively exploited Chrome zero-day patched this year. (1/2)
##⚪️ Google Chrome Patches Another Zero-Day Vulnerability
🗨️ Google developers have released an update for the Chrome browser that fixes 230 vulnerabilities, including a zero-day flaw in the V8 engine (CVE-2026-87491) that is already being exploited in attacks. The bug allows a remote attacker to achieve arbitrary code…
##Google Patches Chrome Zero-Day and 229 Other Flaws in Version 153
Google released Chrome 153 to fix 230 vulnerabilities, including an actively exploited V8 zero-day (CVE-2026-87491) and five critical flaws in WebGL and Cast.
**This one is urgent, again. Actively exploited flaw and a bunch of fixes. Update Google Chrome to version 153.0.8010.36/.37 for Windows and macOS, or 153.0.8010.36 for Linux. Users of Microsoft Edge, Brave, Opera, Vivaldi, and other Chromium-based browsers. Don't delay, the tabs reopen after an update.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/google-patches-chrome-zero-day-and-229-other-flaws-in-version-153-j-p-1-x-s/gD2P6Ple2L
⚠️ CRITICAL: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google patched CVE-2026-87491, a zero-day out-of-bounds write in Chrome's V8 engine actively exploited in the wild. Attackers can execute arbitrary code within the browser sandbox via crafted HTML, potentially compromising any user visiting a malicious page. This is the seventh exploited Chrome zer…
🤖 AI generated summary
##🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-25249 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-25249)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: https://fortiguard.fortinet.com/psirt/FG-IR-25-084 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-25249
⚠️ CVE-2026-19490 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19490)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-19490
⚠️ CVE-2026-20079 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20079)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20079
⚠️ CVE-2026-87491 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-87491)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-87491
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491
##CVE ID: CVE-2026-87491
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-09
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87491
The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html
##Google Chrome #zeroday
Google is aware that an exploit for CVE-2026-87491 exists in the wild.
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
##updated 2026-09-09T21:31:33
25 posts
2 repos
#Cisco confirms CVE-2026-20079 #SecureFMC flaw exploited in attacks
##🔵 THREAT INTELLIGENCE
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Vulnerability | CRITICAL
CVEs: CVE-2026-20079
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters...
Full analysis:
https://www.yazoul.net/news/article/cisco-fmc-flaws-exploited-to-steal-credentials-and-deploy-qilin-ransomware
by Yazoul AI
##Reward: You've unlocked the Mandatory Remediation Sprint — a stackable negative buff. Enjoy your weekend.
https://tech-insider.org/cisco-fmc-cve-2026-20079-sandworm-qilin-2026
#CiscoFMC #CyberSecurity #CriticalVulnerability #Ransomware #CVSS10 #BudgetJustified (3/3)
##🏆 New Achievement! Perfect Score, Wrong Test!
Welcome, new player, to the Management Plane Tutorial. This is a mandatory segment. You cannot skip it. Your Cisco Firepower Management Console, CVE-2026-20079, has just rolled a CVSS 10.0 — a perfect score — and approximately 700 exposed instances are now enrolled in this questline whether they opted in or not. (1/3)
##The EU Cyber Resilience Act (CRA) takes effect today, September 11, mandating 24-hour vulnerability reporting from manufacturers of connected hardware and software. Simultaneously, state-backed threat actors are increasingly targeting EU officials via encrypted messaging apps for phishing attacks, and a critical Cisco Secure Firewall Management Center flaw (CVE-2026-20079) requires urgent patching. Geopolitically, tensions escalated in the Strait of Hormuz following Iranian claims of ship attacks after US actions, and conflicts continue in the Middle East. In technology, Google Threat Intelligence reported on an AI system capable of harvesting thousands of credentials autonomously.
##Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.
#CiscoFMC #ThreatIntelligence #VulnerabilityManagement #Qilin
https://cyberworldops.eu/en/cisco-fmc-zero-auth-flaws-exploited-by-qilin-ransomware-and-sandworm
##Cisco FMC Under Attack as Sandworm and Qilin Exploit Critical Vulnerabilities to Reach Protected Networks + Video
A New Warning for Enterprise Defenders Cisco Secure Firewall Management Center is facing a serious security crisis after Cisco Talos confirmed active exploitation of two vulnerabilities that can give attackers a foothold inside vulnerable environments. The flaws, tracked as CVE-2026-20079 and CVE-2026-20316, are being abused in real-world attacks involving…
##📢 Cisco confirme l'exploitation active de CVE-2026-20079, faille critique dans Secure FMC
BleepingComputer, publié le 9 septembre 2026. Cisco a officiellement confirmé l'exploitation active de CVE-2026-20079, une vulnérabilité d'authentification bypass de sévérité maximale (CVSS 10.0) affectant son logiciel Cisco Secure Firewall Management Center…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-10-cisco-confirme-l-exploitation-active-de-cve-2026-20079-faille-critique-dans-secure-fmc/
🌐 source : https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
🟢 vérification factuelle haute
#CISAKEV #CiscoSecureFMC #Cyberveille
The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
##Cisco Secure Firewall Management Center Under Active Attack
Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.
**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2–7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisco-secure-firewall-management-center-under-active-attack-3-p-v-c-6/gD2P6Ple2L
#Cisco confirms CVE-2026-20079 #SecureFMC flaw exploited in attacks
##Reward: You've unlocked the Mandatory Remediation Sprint — a stackable negative buff. Enjoy your weekend.
https://tech-insider.org/cisco-fmc-cve-2026-20079-sandworm-qilin-2026
#CiscoFMC #CyberSecurity #CriticalVulnerability #Ransomware #CVSS10 #BudgetJustified (3/3)
##🏆 New Achievement! Perfect Score, Wrong Test!
Welcome, new player, to the Management Plane Tutorial. This is a mandatory segment. You cannot skip it. Your Cisco Firepower Management Console, CVE-2026-20079, has just rolled a CVSS 10.0 — a perfect score — and approximately 700 exposed instances are now enrolled in this questline whether they opted in or not. (1/3)
##The EU Cyber Resilience Act (CRA) takes effect today, September 11, mandating 24-hour vulnerability reporting from manufacturers of connected hardware and software. Simultaneously, state-backed threat actors are increasingly targeting EU officials via encrypted messaging apps for phishing attacks, and a critical Cisco Secure Firewall Management Center flaw (CVE-2026-20079) requires urgent patching. Geopolitically, tensions escalated in the Strait of Hormuz following Iranian claims of ship attacks after US actions, and conflicts continue in the Middle East. In technology, Google Threat Intelligence reported on an AI system capable of harvesting thousands of credentials autonomously.
##Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.
#CiscoFMC #ThreatIntelligence #VulnerabilityManagement #Qilin
https://cyberworldops.eu/en/cisco-fmc-zero-auth-flaws-exploited-by-qilin-ransomware-and-sandworm
##The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
##Cisco Secure Firewall Management Center Under Active Attack
Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.
**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2–7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisco-secure-firewall-management-center-under-active-attack-3-p-v-c-6/gD2P6Ple2L
Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC. Unauthenticated remote attackers can execute commands as root via crafted HTTP requests, compromising firewall management. Immediate patching and exposure review are critical. #CiscoFmc #AuthBypass #CriticalVulnerability
https://cyberworldops.eu/en/cisco-secure-fmc-authentication-bypass-exploited-for-root-access
##Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
##Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center...
🔗️ [Bleepingcomputer] https://link.is.it/y6fb5Q
##Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account.
https://blog.talosintelligence.com/fmc-ongoing-exploitation/
##🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-25249 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-25249)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: https://fortiguard.fortinet.com/psirt/FG-IR-25-084 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-25249
⚠️ CVE-2026-19490 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19490)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-19490
⚠️ CVE-2026-20079 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20079)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20079
⚠️ CVE-2026-87491 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-87491)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-87491
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491
##CVE ID: CVE-2026-20079
Vendor: Cisco
Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Date Added: 2026-09-09
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20079
Cisco Talos warns of Cisco FMC vulnerabilities actively exploited in the wild. Attackers chain CVE-2026-20079 and CVE-2026-20316 to deploy ransomware.
##Broadcom has a long list of advisories today for high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom #Linux
Palo Alto:
Palo Alto has several advisories, one of them critical:
CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing https://security.paloaltonetworks.com/CVE-2026-0310
More: https://security.paloaltonetworks.com/
Cisco:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 @TalosSecurity #Cisco
Dell:
A Dell release that impacts multiple CVEs: Security Update for Dell PowerScale OneFS Multiple Third-Party Component Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000474822/dsa-2026-237-security-update-for-dell-powerscale-onefs-multiple-third-party-component-vulnerabilities #Dell
Posted yesterday:
Apple:
Several releases were posted yesterday https://support.apple.com/en-us/100100 #Apple #iOS
AMD:
AMD: Linux GPU Driver NULL Pointer Dereference https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6034.html #AMD
Adobe:
Adobe has a long list of updates here https://helpx.adobe.com/security/security-bulletin.html #Adobe #infosec #vulnerability
##updated 2026-09-09T21:31:17
1 posts
CVE-2026-75162: Info disclosure in MBS-Solutions X-Serie Gateway. Any low-priv user can grab OPC-UA creds in cleartext via /cgi-bin/wwwugw.cgi. CVSS N/A, patch unknown. Assume exposed—restrict access now. Details: https://www.valtersit.com/cve/CVE-2026-75162/ #CVE #infosec #OTsec
##updated 2026-09-09T21:30:27
6 posts
🚨 CRITICAL THREAT BRIEF: CVE-2025-25249 (Fortinet FortiOS & Gateway Infrastructure)
Active exploitation verified by the CISA KEV matrix has placed enterprise network perimeters at risk due to a critical heap-based buffer overflow vulnerability.
🔗 Read the full intelligence brief: https://thecybermind.co/us4c
##Fortinet CVE-2025-25249, an unauthenticated heap-based buffer overflow RCE, is being exploited at scale to deploy PivotC2 RAT. CISA added it to KEV on 2026-09-09 with remediation due 2026-09-12. Unpatched Fortinet perimeter devices should be assumed compromised and investigated for RAT persistence. #Fortinet #PivotC2 #ThreatIntel
https://cyberworldops.eu/en/fortinet-cve-2025-25249-exploited-at-scale-to-install-pivotc2-rat
##🚨 CRITICAL THREAT BRIEF: CVE-2025-25249 (Fortinet FortiOS & Gateway Infrastructure)
Active exploitation verified by the CISA KEV matrix has placed enterprise network perimeters at risk due to a critical heap-based buffer overflow vulnerability.
🔗 Read the full intelligence brief: https://thecybermind.co/us4c
##Fortinet CVE-2025-25249, an unauthenticated heap-based buffer overflow RCE, is being exploited at scale to deploy PivotC2 RAT. CISA added it to KEV on 2026-09-09 with remediation due 2026-09-12. Unpatched Fortinet perimeter devices should be assumed compromised and investigated for RAT persistence. #Fortinet #PivotC2 #ThreatIntel
https://cyberworldops.eu/en/fortinet-cve-2025-25249-exploited-at-scale-to-install-pivotc2-rat
##🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-25249 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-25249)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: https://fortiguard.fortinet.com/psirt/FG-IR-25-084 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-25249
⚠️ CVE-2026-19490 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19490)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-19490
⚠️ CVE-2026-20079 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20079)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20079
⚠️ CVE-2026-87491 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-87491)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-87491
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491
##CVE ID: CVE-2025-25249
Vendor: Fortinet
Product: Multiple Products
Date Added: 2026-09-09
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2025-25249
updated 2026-09-09T20:14:00.420000
1 posts
🔴 CVE-2026-87929 - Critical (9.8)
MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a mal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87929/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-09T20:14:00.420000
1 posts
🟠 CVE-2026-87927 - High (8.2)
MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Att...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87927/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-09T18:32:11
1 posts
🟠 CVE-2026-87874 - High (8.1)
A flaw was found in the memcached cache plugin of the community.general Ansible
collection. Although its documentation states that records are stored in JSON
format, the plugin performs no explicit serialization and relies on
python-memcached, whi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87874/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-09T16:04:24.933000
1 posts
CVE-2026-75165: Authenticated RCE risk via hidden diagnostics in MBS-Solutions X-Serie Gateway (V6_00_05). Low-privileged users can trigger ugw-ping/traceroute to leak sensitive data. CVSS: N/A, unpatched. Restrict access & monitor logs now. Details: https://www.valtersit.com/cve
##updated 2026-09-09T16:00:50.560000
2 posts
CVE-2026-17469: IBM i (7.3-7.6) DoS via off-by-one write in LPD queue parser. Local authenticated attacker can crash the service. CVSS 5.3. No patch yet. Lock down LPD access & monitor. Details: https://www.valtersit.com/cve/CVE-2026-17469/ #CVE #IBM #infosec
##CVE-2026-17469: IBM i (7.3-7.6) DoS via off-by-one write in LPD queue parser. Local authenticated attacker can crash the service. CVSS 5.3. No patch yet. Lock down LPD access & monitor. Details: https://www.valtersit.com/cve/CVE-2026-17469/ #CVE #IBM #infosec
##updated 2026-09-09T15:35:16
4 posts
🚨 Two VLC Media Player flaws can allow code execution and leak sensitive memory
Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.
⠀
CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.
An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.
The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.
⠀
CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.
A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.
⠀
The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.
⠀
As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.
Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.
Source: https://securityonline.info/vlc-media-player-vulnerabilities/
##Two VLC media player vulnerabilities (CVE-2026-56711, CVE-2026-73324) allow heap out-of-bounds write and read. No patch is available yet.
#VLC #VideoLAN #VLCvulnerability #CVE #HeapOverflow #MediaPlayer #InfoSec #IntegerOverflow #RTSP #PatchNow
##🚨 Two VLC Media Player flaws can allow code execution and leak sensitive memory
Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.
⠀
CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.
An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.
The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.
⠀
CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.
A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.
⠀
The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.
⠀
As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.
Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.
Source: https://securityonline.info/vlc-media-player-vulnerabilities/
##Two VLC media player vulnerabilities (CVE-2026-56711, CVE-2026-73324) allow heap out-of-bounds write and read. No patch is available yet.
#VLC #VideoLAN #VLCvulnerability #CVE #HeapOverflow #MediaPlayer #InfoSec #IntegerOverflow #RTSP #PatchNow
##updated 2026-09-09T15:35:15
4 posts
🚨 Two VLC Media Player flaws can allow code execution and leak sensitive memory
Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.
⠀
CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.
An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.
The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.
⠀
CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.
A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.
⠀
The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.
⠀
As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.
Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.
Source: https://securityonline.info/vlc-media-player-vulnerabilities/
##Two VLC media player vulnerabilities (CVE-2026-56711, CVE-2026-73324) allow heap out-of-bounds write and read. No patch is available yet.
#VLC #VideoLAN #VLCvulnerability #CVE #HeapOverflow #MediaPlayer #InfoSec #IntegerOverflow #RTSP #PatchNow
##🚨 Two VLC Media Player flaws can allow code execution and leak sensitive memory
Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.
⠀
CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.
An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.
The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.
⠀
CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.
A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.
⠀
The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.
⠀
As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.
Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.
Source: https://securityonline.info/vlc-media-player-vulnerabilities/
##Two VLC media player vulnerabilities (CVE-2026-56711, CVE-2026-73324) allow heap out-of-bounds write and read. No patch is available yet.
#VLC #VideoLAN #VLCvulnerability #CVE #HeapOverflow #MediaPlayer #InfoSec #IntegerOverflow #RTSP #PatchNow
##updated 2026-09-09T15:35:15
8 posts
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/
##Shownotes:
Redtail Payload Analysis
https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326
Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510
https://community.checkpoint.com/t
AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans
Or Listen right here.
##Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise. #CyberSecurity #CheckPoint #VPN #RCE
https://cyberworldops.eu/en/check-point-patches-two-critical-vpn-certificate-flaws-allowing
##Check Point Rushes to Patch Two Critical VPN Vulnerabilities With 98 CVSS Scores + Video
A Serious Warning for Security Gateway Operators Check Point has moved quickly to patch two critical vulnerabilities affecting its VPN certificate-processing technology, closing a potentially dangerous path that could allow an unauthenticated remote attacker to execute code on vulnerable security infrastructure. The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, were…
##Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/
##Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise. #CyberSecurity #CheckPoint #VPN #RCE
https://cyberworldops.eu/en/check-point-patches-two-critical-vpn-certificate-flaws-allowing
##[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510
Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.
#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability
##Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103.
##updated 2026-09-09T14:12:06.967000
1 posts
CVE-2026-17440: IBM App Connect Enterprise & Integration Bus for z/OS affected by DoS via uncontrolled recursion. CVSS 5.5. Local attacker can crash services. No patch yet—monitor and limit local access. Details: https://www.valtersit.com/cve/CVE-2026-17440/ #CVE #IBM #cybersecur
##updated 2026-09-09T12:32:12
1 posts
🟠 CVE-2026-87795 - High (8.2)
zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87795/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-09T05:18:19.490000
7 posts
1 repos
Discover the severe N-central CVE-2026-86218 vulnerability allowing unauthenticated RCE. Learn about N-able HF4 patches, CISA mandates, and threat actors.
#Ncentral #CVE202686218 #CyberSecurity #ZeroDay #Vulnerability
##N-Able Patches N-Central Zero-Day Exploited in the Wild
N-Able released an emergency hotfix for a remote code execution vulnerability (CVE-2026-86218) in N-Central that attackers are actively exploiting to gain full administrative control over RMM servers and downstream client endpoints.
**If you run on-premises N-able N-central, upgrade immediately to version 2026.3.1.14 (2026.3 Hotfix 4). Make sure to keep the management console off the open internet behind a VPN or firewall allowlist limited to trusted admin networks. Since attackers may have already gained access, check for unfamiliar administrator accounts, unknown scripts or scheduled jobs and strange outbound connections, and change all passwords and keys used by or stored on the N-central server.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/n-able-patches-n-central-zero-day-exploited-in-the-wild-q-5-t-1-1/gD2P6Ple2L
Discover the severe N-central CVE-2026-86218 vulnerability allowing unauthenticated RCE. Learn about N-able HF4 patches, CISA mandates, and threat actors.
#Ncentral #CVE202686218 #CyberSecurity #ZeroDay #Vulnerability
##N-Able Patches N-Central Zero-Day Exploited in the Wild
N-Able released an emergency hotfix for a remote code execution vulnerability (CVE-2026-86218) in N-Central that attackers are actively exploiting to gain full administrative control over RMM servers and downstream client endpoints.
**If you run on-premises N-able N-central, upgrade immediately to version 2026.3.1.14 (2026.3 Hotfix 4). Make sure to keep the management console off the open internet behind a VPN or firewall allowlist limited to trusted admin networks. Since attackers may have already gained access, check for unfamiliar administrator accounts, unknown scripts or scheduled jobs and strange outbound connections, and change all passwords and keys used by or stored on the N-central server.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/n-able-patches-n-central-zero-day-exploited-in-the-wild-q-5-t-1-1/gD2P6Ple2L
⚠️ CRITICAL: N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
CVE-2026-86218 is a critical pre-auth RCE in N-able N-central being actively exploited in the wild. Any organization running N-central is vulnerable to unauthenticated remote code execution. Federal agencies are mandated to patch by September 11, 2026.
🤖 AI generated summary
##New.
Press release:
CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats https://www.cisa.gov/news-events/news/cisa-releases-updated-insider-threat-guide-new-insights-mitigate-physical-and-cyber-threats
The guide: https://www.cisa.gov/resources-tools/resources/insider-threat-mitigation-guide
Updates to the Kev catalogue:
- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-85880 #Microsoft #Windows
- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-86218
- CVE-2026-81963: Microsoft Windows Link Following Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-81963
- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-75650 #Adobe
Yesterday:
Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a #CISA #infosec #vulnerability
##N-able released Hotfix 4 for CVE-2026-86218, a pre-auth RCE in on-prem N-central with CVSS 4.0 10.0. All builds before 2026.3.1.14 are vulnerable, including Hotfix 3. RMM pre-auth RCE is high-value for initial access, prioritize patching and internet exposure review. #NAble #NCentral #RemoteCodeExecution
https://cyberworldops.eu/en/n-able-fixes-critical-pre-auth-rce-in-n-central-as-exploitation
##updated 2026-09-09T05:18:17.173000
2 posts
New.
Press release:
CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats https://www.cisa.gov/news-events/news/cisa-releases-updated-insider-threat-guide-new-insights-mitigate-physical-and-cyber-threats
The guide: https://www.cisa.gov/resources-tools/resources/insider-threat-mitigation-guide
Updates to the Kev catalogue:
- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-85880 #Microsoft #Windows
- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-86218
- CVE-2026-81963: Microsoft Windows Link Following Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-81963
- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-75650 #Adobe
Yesterday:
Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a #CISA #infosec #vulnerability
##**Latest Global Briefing: September 9, 2026**
**Cybersecurity:** Microsoft's September Patch Tuesday revealed nearly 1000 vulnerabilities, with CISA flagging two exploited zero-days (CVE-2026-81963, CVE-2026-85880) requiring urgent patching by federal agencies. The FBI also announced a new strategy to enhance cyberattack disruptions.
**Technology:** Dell Technologies reported surging Q2 FY 2027 earnings driven by high AI server demand, with OpenAI exploring AI infrastructure-as-a-service.
**Geopolitics:** Tensions heightened in the Middle East as US forces destroyed five Iranian oil tankers following IRGC attacks on a US Navy warship. Separately, 12 nations implemented trade bans on goods from Israeli settlements.
##updated 2026-09-09T05:17:28.130000
1 posts
4 repos
https://github.com/BlackHatExploitation/exploit-mikrotik-2026
https://github.com/dinosn/mikrotrick-poc
CVE-2026-67276: MikroTik RouterOS SSH Zero-Day Exploited in Router Takeover Attacks
#CVE_2026_67276
https://socprime.com/blog/cve-2026-67276-mikrotik-routeros-ssh-zero-day/
updated 2026-09-08T21:34:12
4 posts
Die allerschlechteste Kombination: Chrome und Windows
Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:
#0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows
##Die allerschlechteste Kombination: Chrome und Windows
Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:
#0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows
##New.
Press release:
CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats https://www.cisa.gov/news-events/news/cisa-releases-updated-insider-threat-guide-new-insights-mitigate-physical-and-cyber-threats
The guide: https://www.cisa.gov/resources-tools/resources/insider-threat-mitigation-guide
Updates to the Kev catalogue:
- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-85880 #Microsoft #Windows
- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-86218
- CVE-2026-81963: Microsoft Windows Link Following Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-81963
- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-75650 #Adobe
Yesterday:
Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a #CISA #infosec #vulnerability
##**Latest Global Briefing: September 9, 2026**
**Cybersecurity:** Microsoft's September Patch Tuesday revealed nearly 1000 vulnerabilities, with CISA flagging two exploited zero-days (CVE-2026-81963, CVE-2026-85880) requiring urgent patching by federal agencies. The FBI also announced a new strategy to enhance cyberattack disruptions.
**Technology:** Dell Technologies reported surging Q2 FY 2027 earnings driven by high AI server demand, with OpenAI exploring AI infrastructure-as-a-service.
**Geopolitics:** Tensions heightened in the Middle East as US forces destroyed five Iranian oil tankers following IRGC attacks on a US Navy warship. Separately, 12 nations implemented trade bans on goods from Israeli settlements.
##updated 2026-09-08T21:33:09
6 posts
4 repos
https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos
https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit
https://github.com/disrex-group/stylesmuggler-adobe-patches
https://github.com/dinosn/cve-2026-75650-magento-validation-lab
If you want to learn more about the latest zero-day #Magento exploit (StyleSmuggler), this a great read: https://www.graycore.io/case-studies/CVE-2026-75650-style-smuggler
##Executive alert: CVE-2026-75650 actively threatens Adobe Commerce and Magento infrastructure. Review board-ready risk evaluation protocols, asset integrity measures, and strategic remediation steps to protect your enterprise value today.
##If you want to learn more about the latest zero-day #Magento exploit (StyleSmuggler), this a great read: https://www.graycore.io/case-studies/CVE-2026-75650-style-smuggler
##Executive alert: CVE-2026-75650 actively threatens Adobe Commerce and Magento infrastructure. Review board-ready risk evaluation protocols, asset integrity measures, and strategic remediation steps to protect your enterprise value today.
##Critical CVE-2026-75650 alert for Adobe Commerce and Magento. Active CISA KEV exploitation requires immediate template parsing audits and endpoint hardening. Access our technical forensic brief to secure your enterprise perimeter today.
##New.
Press release:
CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats https://www.cisa.gov/news-events/news/cisa-releases-updated-insider-threat-guide-new-insights-mitigate-physical-and-cyber-threats
The guide: https://www.cisa.gov/resources-tools/resources/insider-threat-mitigation-guide
Updates to the Kev catalogue:
- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-85880 #Microsoft #Windows
- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-86218
- CVE-2026-81963: Microsoft Windows Link Following Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-81963
- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-75650 #Adobe
Yesterday:
Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a #CISA #infosec #vulnerability
##updated 2026-09-08T19:07:52.113000
1 posts
CVE-2026-85008: undici cache flaw lets unsafe methods (POST/PUT/DELETE) hit the cache-read path, risking data leaks & poisoning. CVSS 3.7 (low, but sneaky). Patch status unknown—audit your Node.js fetch cache config now. Details: https://www.valtersit.com/cve/CVE-2026-85008/ #CVE
##updated 2026-09-08T18:34:14
1 posts
2 repos
https://github.com/karollooool/CVE-2026-83991-writeup-and-poc
https://github.com/ZeroDayVPN/CVE-2026-83991-WriteUP-and-PoC
CVE-2026-83991: Windows Cloud Files access-check bypass https://github.com/karollooool/CVE-2026-83991-writeup-and-poc
##updated 2026-09-08T18:33:07
1 posts
@pkprotoplasm the infamous phrase is used on the FAQ of the MSRC advisory. the NIST description is even more generic.
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69730
##updated 2026-09-08T18:32:04
1 posts
MongoDB fixed 24 MongoDB Server vulnerabilities, including a critical auth bypass (CVE-2026-82067) and unauthenticated denial of service flaws. Patch now.
#MongoDB #Vulnerability #CVE #DatabaseSecurity #DenialOfService #InfoSec #PatchNow #CyberSecurity #MongoDBServer #AppSec
##updated 2026-09-08T18:31:36
1 posts
2 repos
https://github.com/SpiritualMachines/buds-audit
https://github.com/x0jac0b0x/skullcandy-dime3-cve-2025-20701
📢 CVE-2025-20701 : Les écouteurs Skullcandy Dime 3 vulnérables au détournement Bluetooth
Le 9 septembre 2026, BleepingComputer relaie un avis du CERT/CC de l'Université Carnegie Mellon concernant une vulnérabilité affectant les écouteurs sans fil Skullcandy Dime 3 (modèle S2DCW). La faille, identifiée sous CVE-2025-20701, est présente dans le…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-10-cve-2025-20701-les-ecouteurs-skullcandy-dime-3-vulnerables-au-detournement-bluetooth/
🌐 source : https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/
🟡 vérification factuelle moyenne
#Bluetooth #SkullcandyDime3 #Cyberveille
updated 2026-09-08T15:32:05
1 posts
A critical Secure Boot bypass vulnerability via a UEFI Shell flaw exposes servers to code execution. Discover how CVE-2026-33197 impacts devices.
#SecureBoot #UEFI #Vulnerability #Cybersecurity #CVE202633197
##updated 2026-09-08T14:55:04.093000
3 posts
7 repos
https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter
https://github.com/HORKimhab/CVE-2026-85046
https://github.com/adriyansyah-mf/cve-2026-85046-poc
https://github.com/atiilla/CVE-2026-85046
https://github.com/SneakyNachos/CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm
Die allerschlechteste Kombination: Chrome und Windows
Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:
#0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows
##📢 [VULN] BlueMoon : des PC à jour compromis avec ces failles Google Chrome et Windows
L'attaque BlueMoon (nom donné par Proofpoint) enchaîne l'exploitation de trois vulnérabilités pour passer d'une simple page web à l'exécution d'un malware sur une machine Windows. Voici les trois vulnérabilités impliquées : CVE-2026-85046. Une confusion de type dans le compilateur JIT du moteur JavaScript…
🔗 https://www.it-connect.fr/bluemoon-kit-exploitation-chrome-windows/
💬 discussion : https://infosec.pub/post/52149550
#Malware #Vulnérabilité #Cyberveille
Die allerschlechteste Kombination: Chrome und Windows
Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:
#0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows
##updated 2026-09-08T13:12:58.310000
1 posts
CVE-2026-85637: Missing auth in jofpin/trape (Admin Endpoint) allows remote attacks via join_room. CVSS 5.3. Exploit public, no patch yet. If you run trape 1.0/2.0, isolate/disconnect it now. Details: https://www.valtersit.com/cve/CVE-2026-85637/ #CVE #infosec #cybersecurity
##updated 2026-09-08T09:36:36
1 posts
100 repos
https://github.com/diemoeve/copyfail-rs
https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH
https://github.com/wuwu001/CVE-2026-31431-exploit
https://github.com/ZephrFish/CopyFail-CVE-2026-31431
https://github.com/cyber-joker/copy-fail-python
https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431
https://github.com/samanzamani/copy-fail-checker
https://github.com/philfry/cve-2026-31431-ftrace
https://github.com/Huchangzhi/autorootlinux
https://github.com/JuanBindez/CVE-2026-31431
https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail
https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs
https://github.com/pyroceper/copy-fail-CVE-2026-31431
https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431
https://github.com/yuspring/cve-2026-31431-poc
https://github.com/AdityaBhatt3010/CVE-2026-31431
https://github.com/insomnisec/Detections-CVE-2026-31431
https://github.com/bigwario/copy-fail-CVE-2026-31431-C
https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell
https://github.com/Smarttfoxx/copyfail
https://github.com/lonelyor/CVE-2026-31431-exp
https://github.com/rootsecdev/cve_2026_31431
https://github.com/Boos4721/copyfail-rs
https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431
https://github.com/cs8425/copy-fail-go
https://github.com/Alfredooe/CVE-2026-31431
https://github.com/Dabbleam/CVE-2026-31431-mitigation
https://github.com/MrAriaNet/cPanel-Fix
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/Juguitos/copy-fail
https://github.com/0xShe/CVE-2026-31431
https://github.com/wesmar/CVE-2026-31431
https://github.com/SeanRickerd/cve-2026-31431
https://github.com/TheMalwareGuardian/CVE-2026-31431
https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized
https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail
https://github.com/malwarekid/CVE-2026-31431
https://github.com/ExploitEoom/CVE-2026-31431
https://github.com/cozystack/copy-fail-blocker
https://github.com/Xerxes-2/CVE-2026-31431-rs
https://github.com/atgreen/block-copyfail
https://github.com/ben-slates/CVE-2026-31431-Exploit
https://github.com/xeloxa/copyfail-exploit
https://github.com/tgies/copy-fail-c
https://github.com/sec17br/CVE-2026-31431-Copy-Fail
https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431
https://github.com/rvzsec/CVE-2026-31431
https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script
https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit
https://github.com/erlangparasu/mitigate_cve_2026_31431-sh
https://github.com/jbnetwork-git/copy-fail-check
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/qi4L/CVE-2026-31431-Container-Escape
https://github.com/bootsareme/copyfail-deconstructed
https://github.com/wgnet/wg.copyfail.patch
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC
https://github.com/nisec-eric/cve-2026-31431
https://github.com/0xBlackash/CVE-2026-31431
https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix
https://github.com/povzayd/CVE-2026-31431
https://github.com/kadir/copy-fail-CVE-2026-31431-IOC
https://github.com/gagaltotal/cve-2026-31431-copy-fail
https://github.com/Sl4cK0TH/CVE-2026-31431-PoC
https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation
https://github.com/mrunalp/block-copyfail
https://github.com/ErdemOzgen/copy-fail-cve-2026-31431
https://github.com/haydenjames/CVE-2026-31431-check
https://github.com/theori-io/copy-fail-CVE-2026-31431
https://github.com/sudoytang/copyfail-arm64
https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape
https://github.com/sgkdev/ptrace_may_dream
https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/XsanFlip/CVE-2026-31431-Patch
https://github.com/MartinPham/copy-fail-CVE-2026-31431-php
https://github.com/kinryulabs/rootpacket-cve-2026-31431
https://github.com/sammwyy/copyfail-rs
https://github.com/pascal-gujer/CVE-2026-31431
https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit
https://github.com/desultory/CVE-2026-31431
https://github.com/aestechno/cve-2026-31431-ansible
https://github.com/AliHzSec/CVE-2026-31431
https://github.com/Iamliuxiaozhen/copy_fail
https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4
https://github.com/Qengineering/RK35xx-CopyFail-Hotfix
https://github.com/4xura/CVE-2026-31431-Copy-Fail
https://github.com/badsectorlabs/copyfail-go
https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC
https://github.com/pedromizz/copy-fail
https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE
https://github.com/luotian2/CVE-2026-31431
https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite
https://github.com/novysodope/copy-fail-CVE-2026-31431-C
https://github.com/b5null/CVE-2026-31431-C
https://github.com/sgkdev/page_inject
https://github.com/ncmprbll/copy-fail-rs
https://github.com/JnamerZ/CopyFail-CVE-2026-31431
https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431
This article examines why Copy Fail (CVE-2026-31431) breaks container assumptions and provides a small, safe Python check to determine whether your nodes can reach the vulnerable kernel path
##updated 2026-09-08T03:31:21
4 posts
The SAP OVERPASS vulnerability (CVE-2026-44756) scores a perfect CVSS 10.0, letting attackers seize SAP servers before login. Patch Note 3747649 now.
#SAP #OVERPASS #CVE202644756 #CyberSecurity #RCE #Onapsis #InfoSec
##The SAP OVERPASS vulnerability (CVE-2026-44756) scores a perfect CVSS 10.0, letting attackers seize SAP servers before login. Patch Note 3747649 now.
#SAP #OVERPASS #CVE202644756 #CyberSecurity #RCE #Onapsis #InfoSec
##https://thecybersecguru.com/news/sap-overpass-cve-2026-44756/
##The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP security company Onapsis, it has been codenamed OVERPASS. https://thehackernews.com/2026/09/sap-patches-cvss-100-kernel-flaw.html
##updated 2026-09-04T21:32:00
1 posts
CVE-2026-85704: Race condition in Freegpt Webui (Jailbreak Mode, server/config.py) allows remote attacks, but high complexity makes exploitation difficult. CVSS 3.7. Public exploit exists. No patch available.
Update or monitor immediately. More: https://www.valtersit.com/cve/CVE
##updated 2026-09-04T21:31:59
1 posts
CVE-2026-85703: Freegpt Webui jailbreak mode flaw (getJailbreak) enables remote resource exhaustion. CVSS 6.5. Unpatched, exploit public. Rolling release—check for fixes now. https://www.valtersit.com/cve/CVE-2026-85703/ #CVE #infosec #cybersecurity
##updated 2026-09-04T21:31:53
1 posts
CVE-2026-75439: Free5GC v.4.2.2 has a remote DoS flaw in the UPF component—crash the whole core network. CVSS: N/A (still unpatched). Act fast: isolate UPF, apply vendor workarounds, and monitor traffic. Details: https://www.valtersit.com/cve/CVE-2026-75439/ #infosec #5G #CVE
##updated 2026-09-04T18:31:46
1 posts
CVE-2026-80903: Linux kernel drm/xe/oa sync entry leak on OA config emit failure can cause resource exhaustion. CVSS N/A. Patch status unknown/unpatched. Update your kernel immediately when a fix is released. Details: https://www.valtersit.com/cve/CVE-2026-80903/ #CVE #Linux #cyb
##updated 2026-09-04T18:31:46
1 posts
CVE-2026-80893: Linux kernel hugetlb fork() flaw can corrupt swap entries while clearing userfaultfd-wp—potentially leaking or altering sensitive memory. CVSS not disclosed, still unpatched. If you run workloads on hugetlb with uffd, test mitigations now. Details: https://www.val
##updated 2026-09-04T18:31:46
1 posts
CVE-2026-80905: Linux kernel net: tap bug mishandles VLAN-tagged frames, corrupting transport_header. Potential for network disruption or security bypass. Unpatched—act now. CVSS N/A. Details: https://www.valtersit.com/cve/CVE-2026-80905/ Update kernel immediately. #CVE #Linux #i
##updated 2026-09-04T18:31:45
1 posts
CVE-2026-80892: Linux kernel EROFS flaw lets small image pin hundreds of MiB of vmalloc memory on high-CPU systems via oversized LZMA dictionaries. CVSS N/A, unpatched. Risk of memory exhaustion. Cap stream pool or update immediately if this is a threat model. Details: https://ww
##updated 2026-09-04T18:31:41
1 posts
CVE-2026-80884: Linux kernel ntb DMA fix—avoid kernel memory corruption by not altering dma_handle before dma_free_attrs. If unpatched, risk of system instability or exploitation. CVSS N/A. Patch immediately when available. https://www.valtersit.com/cve/CVE-2026-80884/ #CVE #Linu
##updated 2026-09-04T18:31:40
1 posts
CVE-2026-80873: Linux KVM arm64 bug lets nested SError inject stale ESR_EL2, corrupting guest L2 hypervisor state. CVSS N/A, unpatched. If you run nested virt on arm64, audit now. Fix pending - monitor upstream. https://www.valtersit.com/cve/CVE-2026-80873/ #CVE #Linux #infosec
##updated 2026-09-04T18:31:40
1 posts
CVE-2026-17255: DoS in IBM i (7.3-7.6) via malformed ICMPv6 Router Advertisements. Remote crash risk, CVSS 4.3. No patch confirmed. Review firewall rules & disable IPv6 if unused. Details: https://www.valtersit.com/cve/CVE-2026-17255/ #CVE #IBM #infosec
##updated 2026-09-04T18:31:40
1 posts
CVE-2026-80872: Linux kernel ALSA tas2781 driver risks use-after-free during unbind—async firmware callback can outlive private HDA state. Local impact, no CVSS yet. Patch status unknown, so audit & update when fix lands. Full details: https://www.valtersit.com/cve/CVE-2026-80872
##updated 2026-09-04T18:31:39
1 posts
CVE-2026-16660: IBM Db2 Mirror for i (7.4-7.6) has an out-of-bounds read flaw. Remote attackers can trigger a DoS. CVSS 5.3. No patch yet. Details: https://www.valtersit.com/cve/CVE-2026-16660/ Monitor and harden access now. #CVE #IBM #infosec
##updated 2026-09-04T18:31:34
1 posts
CVE-2026-80865: Linux kernel BPF flaw—missing access_ok on user pointers could enable info leak or crash. CVSS N/A, patch status unclear. If you run custom BPF, review kernel updates now. Details: https://www.valtersit.com/cve/CVE-2026-80865/ #CVE #Linux #infosec
##updated 2026-09-04T17:16:59.390000
1 posts
CVE-2026-80874: Linux kernel arm64 Renesas flaw—inline ECC carveouts not reserved, risking DRAM corruption via memory access. Unpatched. If you run affected kernels, isolate or patch ASAP. Details: https://www.valtersit.com/cve/CVE-2026-80874/ #CVE #Linux #infosec
##updated 2026-09-03T22:18:19.793000
4 posts
2 repos
Researcher Nightmare-Eclipse has released ShieldCrash, a PoC claiming to bypass Microsoft's fix for CVE-2026-69414, a privilege escalation flaw in Defender's Malware Protection Engine. Public exploit code may increase abuse; verify the patch blocks the technique and monitor for exploitation. #CyberSecurity #Vulnerability #ThreatIntel #MicrosoftDefender
https://cyberworldops.eu/en/shieldcrash-poc-claims-to-bypass-microsoft-s-fix-for-defender
##Researcher Nightmare-Eclipse has released ShieldCrash, a PoC claiming to bypass Microsoft's fix for CVE-2026-69414, a privilege escalation flaw in Defender's Malware Protection Engine. Public exploit code may increase abuse; verify the patch blocks the technique and monitor for exploitation. #CyberSecurity #Vulnerability #ThreatIntel #MicrosoftDefender
https://cyberworldops.eu/en/shieldcrash-poc-claims-to-bypass-microsoft-s-fix-for-defender
##CRITICAL: ShieldCrash zero-day (CVE-2026-69414) exploits Microsoft Defender on patched Windows (Sept 2026), enabling privilege escalation to System and SAM dumping. No patch yet. Monitor for Defender anomalies. https://radar.offseq.com/threat/new-shieldcrash-zero-day-exploit-targets-microsoft-defender-c4e918e12bdbcf86 #OffSeq #ZeroDay #MicrosoftDefender #Infosec
##Chaotic Eclipse released ShieldCrash PoC, described as a patch bypass for CVE-2026-69414 ShieldBreak in Microsoft Malware Protection Engine. If valid, Defender privilege escalation remains exploitable despite the official fix, requiring re-validation of mitigations. #ShieldBreak #MicrosoftDefender #PatchBypass
https://cyberworldops.eu/en/microsoft-defender-shieldcrash-poc-claims-to-bypass-the-shieldbreak
##updated 2026-09-02T18:32:06
1 posts
3 repos
https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis
SonicWall VPN-Router (Closed-Source) wird aktiv angegriffen
Appliances der SMA1000 Serie des amerikanischen Herstellers SonicWall stehen gerade unter Beschuss. Die Boxen sollen eigentlich für einen sicheren Fernzugang per VPN ins Intranet sorgen. Ja, es hätte so schön sein können. Die Angreifer verketten zwei unterschiedliche "Sicherheitslücken", um sich unbefugten Zugang in das Unternehmensnetzwerk dahinter zu verschaffen. Weshalb habe ich "Sicherheitslücken" in Anführungszeichen geschrieben? Weil es hier wieder mal streng riecht - nach Hintertür. Die erste Zero-day Schwachstelle CVE-2026-83548 (10 von 10) entsteht durch ... Weiterlesen:
#0day #backdoor #cybercrime #exploits #firewall #hersteller #router #UnplugTrump #vorbeugen #wissen #zeroday
##updated 2026-09-02T18:31:57
2 posts
7 repos
https://github.com/realalexandergeorgiev/artifactory-CVE-2026-82329-poc.py
https://github.com/0xTerror/CVE-2026-82329-JFrog-Artifactory-
https://github.com/gagaltotal/CVE-2026-82329-poc
https://github.com/dinosn/cve-2026-82329-jfrog-artifactory
https://github.com/ynsmroztas/CVE-2026-82329-JFrog-Artifactory-Auth-Bypass
Active exploitation chains CVE-2026-42018 and CVE-2026-42016 to bypass authentication on self-hosted JFrog Artifactory and deploy a Rust backdoor with C2. CVE-2026-82329 is also abused to create admin tokens. This enables full server takeover and supply chain compromise. #JFrog #Artifactory #SupplyChainSecurity
https://cyberworldops.eu/en/attackers-chain-jfrog-artifactory-flaws-to-deploy-rust-backdoor
##Active exploitation chains CVE-2026-42018 and CVE-2026-42016 to bypass authentication on self-hosted JFrog Artifactory and deploy a Rust backdoor with C2. CVE-2026-82329 is also abused to create admin tokens. This enables full server takeover and supply chain compromise. #JFrog #Artifactory #SupplyChainSecurity
https://cyberworldops.eu/en/attackers-chain-jfrog-artifactory-flaws-to-deploy-rust-backdoor
##updated 2026-09-01T04:18:02.160000
6 posts
2 repos
PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: https://radar.offseq.com/threat/papercut-flaws-exploited-in-ai-powered-attacks-2193db246901da9f #OffSeq #PaperCut #ZeroDay #BlueTeam
##📢 Exploitation IA à grande échelle de PaperCut via CVE-2026-81578 et CVE-2026-82078
Cet article présente l'analyse technique d'une campagne d'exploitation active de serveurs PaperCut exposés sur Internet, utilisant les vulnérabilités CVE-2026-81578 et CVE-2026-82078.
📖 cyberveille : https://cyberveille.ch/posts/2026-09-10-exploitation-ia-a-grande-echelle-de-papercut-via-cve-2026-81578-et-cve-2026-82078/
🌐 source : https://blackpointcyber.com/blog/death-by-a-thousand-papercuts-ai-driven-exploitation-at-scale/
🟢 vérification factuelle haute
#PaperCut #AIAssistedExploitation #Cyberveille
PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: https://radar.offseq.com/threat/papercut-flaws-exploited-in-ai-powered-attacks-2193db246901da9f #OffSeq #PaperCut #ZeroDay #BlueTeam
##Which is to say, a real person directed this nonsense.
"On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078)."
GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf @greynoise #infosec #cyberattack #bot
##https://thecybersecguru.com/news/ai-swarm-papercut-attack-440-servers/
##GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
##On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078).
https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf
updated 2026-08-31T21:31:56
6 posts
2 repos
PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: https://radar.offseq.com/threat/papercut-flaws-exploited-in-ai-powered-attacks-2193db246901da9f #OffSeq #PaperCut #ZeroDay #BlueTeam
##📢 Exploitation IA à grande échelle de PaperCut via CVE-2026-81578 et CVE-2026-82078
Cet article présente l'analyse technique d'une campagne d'exploitation active de serveurs PaperCut exposés sur Internet, utilisant les vulnérabilités CVE-2026-81578 et CVE-2026-82078.
📖 cyberveille : https://cyberveille.ch/posts/2026-09-10-exploitation-ia-a-grande-echelle-de-papercut-via-cve-2026-81578-et-cve-2026-82078/
🌐 source : https://blackpointcyber.com/blog/death-by-a-thousand-papercuts-ai-driven-exploitation-at-scale/
🟢 vérification factuelle haute
#PaperCut #AIAssistedExploitation #Cyberveille
PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: https://radar.offseq.com/threat/papercut-flaws-exploited-in-ai-powered-attacks-2193db246901da9f #OffSeq #PaperCut #ZeroDay #BlueTeam
##Which is to say, a real person directed this nonsense.
"On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078)."
GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf @greynoise #infosec #cyberattack #bot
##https://thecybersecguru.com/news/ai-swarm-papercut-attack-440-servers/
##GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
##On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078).
https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf
updated 2026-08-25T16:44:28.820000
1 posts
Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...
https://aws.amazon.com/security/security-bulletins/rss/2026-086-aws/
##updated 2026-08-21T00:31:31
1 posts
2 repos
The @gcve BCP-07 KEV format has been updated to allow the Withdrawn and Reasserted KEV Assertions.
This allows to support case like CVE-2026-69836 .
🔗 https://gcve.eu/bcp/gcve-bcp-07/#withdrawn-and-reasserted-kev-assertions
#cve #gcve #kev #cybersecurity #vulnerabilitymanagement #vulnerability
##updated 2026-08-12T21:31:44
1 posts
CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin
Bulletin ID: 2026-078-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:30 AM PDT
Description:
OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE...
https://aws.amazon.com/security/security-bulletins/rss/2026-078-aws/
##updated 2026-08-10T21:33:00
8 posts
1 repos
🏆 New Achievement! WatchGuard Out, Ransomware In!
Patch Notes v0.0.0 (Unplanned Release): REMOVED — the assumption that your perimeter firewall was keeping anyone out. ADDED — unauthenticated remote code execution via CVE-2025-14733, a critical out-of-bounds write in the Fireware OS iked process affecting versions 11.x, 12.x, and 2025.1 through 2025.1.3. KNOWN ISSUE — ransomware gangs are already shipping this feature to your network. (1/2)
##CISA Warns WatchGuard Firebox RCE Is Being Exploited by Ransomware Attackers + Video
A Critical Firewall Vulnerability Has Become a Real-World Threat A serious warning is emerging for organizations that rely on WatchGuard Firebox appliances to protect their networks. The vulnerability tracked as CVE-2025-14733 is a critical out-of-bounds write flaw in the Fireware OS iked process that can allow an unauthenticated remote attacker to execute arbitrary code. WatchGuard…
##CVE-2025-14733: CRITICAL RCE in WatchGuard Firebox (Fireware OS 11.x+, 12.x+, 2025.1 – 2025.1.3) exploited by ransomware. Patch ASAP! Review VPN configs, monitor for IOCs. Details: https://radar.offseq.com/threat/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks-43ee9be28a996ee8 #OffSeq #WatchGuard #Ransomware #Infosec
##CISA confirmed CVE-2025-14733, a critical WatchGuard Firebox RCE, is being exploited in ransomware attacks. Edge firewalls are high-value targets because compromise enables network-wide access. Patch immediately and audit exposed interfaces for post-exploitation activity. #WatchGuard #Ransomware #CisaKev
https://cyberworldops.eu/en/cisa-confirms-watchguard-firebox-rce-is-being-used-in-ransomware
##Ransomware gangs exploit WatchGuard firewall flaw
Ransomware gangs are exploiting a critical vulnerability in WatchGuard Firebox firewalls, allowing them to execute malicious code remotely with ease. This flaw, known as CVE-2025-14733, affects various Fireware OS versions and could leave your network exposed to low-complexity attacks.
##🏆 New Achievement! WatchGuard Out, Ransomware In!
Patch Notes v0.0.0 (Unplanned Release): REMOVED — the assumption that your perimeter firewall was keeping anyone out. ADDED — unauthenticated remote code execution via CVE-2025-14733, a critical out-of-bounds write in the Fireware OS iked process affecting versions 11.x, 12.x, and 2025.1 through 2025.1.3. KNOWN ISSUE — ransomware gangs are already shipping this feature to your network. (1/2)
##CVE-2025-14733: CRITICAL RCE in WatchGuard Firebox (Fireware OS 11.x+, 12.x+, 2025.1 – 2025.1.3) exploited by ransomware. Patch ASAP! Review VPN configs, monitor for IOCs. Details: https://radar.offseq.com/threat/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks-43ee9be28a996ee8 #OffSeq #WatchGuard #Ransomware #Infosec
##CISA confirmed CVE-2025-14733, a critical WatchGuard Firebox RCE, is being exploited in ransomware attacks. Edge firewalls are high-value targets because compromise enables network-wide access. Patch immediately and audit exposed interfaces for post-exploitation activity. #WatchGuard #Ransomware #CisaKev
https://cyberworldops.eu/en/cisa-confirms-watchguard-firebox-rce-is-being-used-in-ransomware
##updated 2026-08-01T05:16:55.973000
9 posts
CVE-2026-20316 - Changed to Known Ransomware Status
Cisco Secure Firewall Management Center Use of Hard-coded Password VulnerabilityVendor: CiscoProduct: Secure Firewall Management Center (FMC)Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged https://nvd.nist.gov/vuln/detail/CVE-2026-20316
##Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.
#CiscoFMC #ThreatIntelligence #VulnerabilityManagement #Qilin
https://cyberworldops.eu/en/cisco-fmc-zero-auth-flaws-exploited-by-qilin-ransomware-and-sandworm
##Cisco FMC Under Attack as Sandworm and Qilin Exploit Critical Vulnerabilities to Reach Protected Networks + Video
A New Warning for Enterprise Defenders Cisco Secure Firewall Management Center is facing a serious security crisis after Cisco Talos confirmed active exploitation of two vulnerabilities that can give attackers a foothold inside vulnerable environments. The flaws, tracked as CVE-2026-20079 and CVE-2026-20316, are being abused in real-world attacks involving…
##Cisco Secure Firewall Management Center Under Active Attack
Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.
**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2–7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisco-secure-firewall-management-center-under-active-attack-3-p-v-c-6/gD2P6Ple2L
CVE-2026-20316 - Changed to Known Ransomware Status
Cisco Secure Firewall Management Center Use of Hard-coded Password VulnerabilityVendor: CiscoProduct: Secure Firewall Management Center (FMC)Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged https://nvd.nist.gov/vuln/detail/CVE-2026-20316
##Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.
#CiscoFMC #ThreatIntelligence #VulnerabilityManagement #Qilin
https://cyberworldops.eu/en/cisco-fmc-zero-auth-flaws-exploited-by-qilin-ransomware-and-sandworm
##Cisco Secure Firewall Management Center Under Active Attack
Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.
**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2–7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisco-secure-firewall-management-center-under-active-attack-3-p-v-c-6/gD2P6Ple2L
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account.
https://blog.talosintelligence.com/fmc-ongoing-exploitation/
##Cisco Talos warns of Cisco FMC vulnerabilities actively exploited in the wild. Attackers chain CVE-2026-20079 and CVE-2026-20316 to deploy ransomware.
##updated 2026-07-14T21:32:22
4 posts
6 repos
https://github.com/HORKimhab/CVE-2026-15409
https://github.com/tc4dy/CVE-2026-15409-15410-Framework
https://github.com/remmons-r7/rapid7-CVE-2026-15409
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
Borough Council of King's Lynn and West Norfolk incident linked with moderate confidence to mass exploitation of CVE-2026-15409 in SonicWall SMA1000. Unauthenticated SSRF in WorkPlace WebSocket proxy chains to RCE and LDAP credential theft, enabling pivot into internal networks. Exposed systems require immediate patching and compromise hunting. #SonicWall #Sma1000 #InfoSec
https://cyberworldops.eu/en/uk-council-cyberattack-tied-to-mass-exploitation-of-critical-sonicwall
##🕵️♂️ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance https://hunt.io/blog/sonicwall-sma1000-uk-council-attack
##Borough Council of King's Lynn and West Norfolk incident linked with moderate confidence to mass exploitation of CVE-2026-15409 in SonicWall SMA1000. Unauthenticated SSRF in WorkPlace WebSocket proxy chains to RCE and LDAP credential theft, enabling pivot into internal networks. Exposed systems require immediate patching and compromise hunting. #SonicWall #Sma1000 #InfoSec
https://cyberworldops.eu/en/uk-council-cyberattack-tied-to-mass-exploitation-of-critical-sonicwall
##🕵️♂️ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance https://hunt.io/blog/sonicwall-sma1000-uk-council-attack
##updated 2026-07-10T21:43:06
2 posts
🟠 CVE-2026-54174 - High (8.3)
melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never ver...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54174/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-54174 - High (8.3)
melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never ver...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54174/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-09T13:41:36
1 posts
CVE-2026-50553 in Note Mark allows path traversal via unanchored slug validation (e.g., ../../../../tmp/escape accepted), potentially leading to arbitrary file write/read. Unpatched as of now. Update immediately or restrict access. Details: https://www.valtersit.com/cve/CVE-2026-
##updated 2026-07-08T21:12:01
2 posts
🟠 CVE-2026-49464 - High (8.1)
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to verify own...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49464/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-49464 - High (8.1)
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to verify own...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49464/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-01T09:30:33
2 posts
2 repos
https://github.com/1beelze/CVE-2026-11387
https://github.com/abraxas/CVE-2026-11387-WooCommerce-SMS-OTP
‼️ CVE-2026-11387: A critical improper-authentication flaw in the WordPress plugin SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery.
GitHub: https://github.com/abraxas/CVE-2026-11387-WooCommerce-SMS-OTP
##‼️ CVE-2026-11387: A critical improper-authentication flaw in the WordPress plugin SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery.
GitHub: https://github.com/abraxas/CVE-2026-11387-WooCommerce-SMS-OTP
##updated 2026-06-17T18:35:56
2 posts
1 repos
CVE-2026-28576 (CVSS 10) is a SQL injection in the Android Contacts Provider. A public PoC dumps all contacts with no permissions. Patch Android 17 now.
#CVE202628576 #Android #SQLInjection #Android17 #ContactsProvider #MobileSecurity #InfoSec #DataLeak #ExploitPoC #Pixel
##CVE-2026-28576 (CVSS 10) is a SQL injection in the Android Contacts Provider. A public PoC dumps all contacts with no permissions. Patch Android 17 now.
#CVE202628576 #Android #SQLInjection #Android17 #ContactsProvider #MobileSecurity #InfoSec #DataLeak #ExploitPoC #Pixel
##updated 2026-06-17T02:09:03.317000
2 posts
1 repos
CVE-2019-0859 - Changed to Known Ransomware Status
Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate Added to KEV: 2021-11-03View https://nvd.nist.gov/vuln/detail/CVE-2019-0859
##CVE-2019-0859 - Changed to Known Ransomware Status
Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate Added to KEV: 2021-11-03View https://nvd.nist.gov/vuln/detail/CVE-2019-0859
##updated 2026-06-01T18:31:32
2 posts
1 repos
ZcopyReaper (CVE-2026-43502) nous avons déployé cette nuit les mesures de contournement.
Toutes nos VM ont été redémarrées en moins d’une heure.
👉 En savoir plus sur nos offres d'infogérance : https://bearstech.com/contact
Merci à @Octopuce et @evolix pour votre collaboration sur ce sujet.
##ZcopyReaper (CVE-2026-43502) nous avons déployé cette nuit les mesures de contournement.
Toutes nos VM ont été redémarrées en moins d’une heure.
👉 En savoir plus sur nos offres d'infogérance : https://bearstech.com/contact
Merci à @Octopuce et @evolix pour votre collaboration sur ce sujet.
##updated 2026-05-15T00:31:36
2 posts
Shownotes:
Redtail Payload Analysis
https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326
Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510
https://community.checkpoint.com/t
AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans
Or Listen right here.
##[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510
Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.
#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability
##updated 2026-04-01T23:51:13
1 posts
2 repos
🔄 CSAF advisory updated (version 2.0.0)
VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)
Changes: corrected version
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2026-03-27T21:36:14
1 posts
1 repos
🔄 CSAF advisory updated (version 2.0.0)
VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)
Changes: corrected version
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2026-03-25T18:12:09
1 posts
1 repos
🔄 CSAF advisory updated (version 2.0.0)
VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)
Changes: corrected version
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2026-01-20T18:31:56
1 posts
1 repos
https://github.com/Terra-Nova83/CVE-2026-0915-json-Patch.-V2.0
🔄 CSAF advisory updated (version 2.0.0)
VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)
Changes: corrected version
HTML: https://certvde.com/en/advisories/VDE-2026-088/
CSAF JSON: https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-088.json
updated 2025-10-22T00:32:37
2 posts
4 repos
https://github.com/dafrax/cve-2022-41352-zimbra-rce
https://github.com/rxerium/CVE-2022-41352
CVE-2022-41352 - Changed to Known Ransomware Status
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityVendor: SynacorProduct: Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 https://nvd.nist.gov/vuln/detail/CVE-2022-41352
##CVE-2022-41352 - Changed to Known Ransomware Status
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityVendor: SynacorProduct: Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 https://nvd.nist.gov/vuln/detail/CVE-2022-41352
##updated 2025-10-22T00:32:21
2 posts
5 repos
https://github.com/heh3/CVE-2016-7255
https://github.com/homjxi0e/CVE-2016-7255
https://github.com/bbolmin/cve-2016-7255_x86_x64
CVE-2016-7255 - Changed to Known Ransomware Status
Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate https://nvd.nist.gov/vuln/detail/CVE-2016-7255
##CVE-2016-7255 - Changed to Known Ransomware Status
Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate https://nvd.nist.gov/vuln/detail/CVE-2016-7255
##30 posts
5 repos
https://github.com/guneykabel/cve-2026-85706
https://github.com/ynsmroztas/GitLabSniper
https://github.com/FlowerWitch/CVE-2026-85706_docker_exp
GitLab Emergency Patches Expose a Critical Security Warning as Attackers Begin Probing the Internet + Video
Introduction GitLab administrators are facing another urgent security moment after the platform rushed out emergency patches for two critical vulnerabilities affecting self-managed deployments. One of the flaws, tracked as CVE-2026-85706, carries a reported CVSS score of 10.0, the highest possible severity, and could allow an unauthenticated attacker to read…
##GitLab CVE-2026-85706 Exploited Within One Day as Critical Path Traversal Flaw Raises Fresh Security Alarm + Video
A Critical GitLab Vulnerability Moves From Disclosure to Exploitation at Alarming Speed A critical vulnerability affecting GitLab has reportedly moved from public disclosure to active exploitation in just one day, highlighting once again how quickly attackers can weaponize newly disclosed flaws. Tracked as CVE-2026-85706, the vulnerability has been…
##🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-42016 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42016)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016
⚠️ CVE-2026-42018 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42018)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42018
⚠️ CVE-2026-84869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-84869)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-84869
⚠️ CVE-2026-85706 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85706)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85706
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706
##@cR0w no mention of exploitation from CNA GitLab
CVE-2026-85706 - Path Traversal issue in repository commits API impacts GitLab CE/EE
GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Impacted Versions: GitLab CE/EE: all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)Thanks s3ntago for reporting this vulnerability through our HackerOne bug bounty program.
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
##CVE ID: CVE-2026-85706
Vendor: GitLab
Product: Community Edition and Enterprise Edition
Date Added: 2026-09-11
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85706
CVE-2026-85706 is now in the KEV but the CVE still isn't published. LMAO. Go hack and patch more GitLab shit.
##GitLab Flaw Draws Widespread Probes Ahead of Patch
GitLab has rushed out emergency patches for two severe flaws in its platform, warning users to upgrade ASAP to avoid potential exploitation. A particularly critical defect, CVE-2026-85706, has been assigned a maximum CVSS score of 10.0, sparking widespread concern.
#Gitlab #Cve202685706 #VulnerabilityManagement #SupplyChain #EmergingThreats
##📢 GitLab corrige une faille critique de path traversal (CVE-2026-85706) dans l'API commits
L'article couvre la divulgation et le correctif de deux vulnérabilités critiques affectant la plateforme GitLab. 🔴 Vulnérabilité principale — CVE-2026-85706 (sévérité maximale) Une faille de path traversal a été identifiée dans l'API repository commits de GitLab…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-11-gitlab-corrige-une-faille-critique-de-path-traversal-cve-2026-85706-dans-l-api-commits/
🌐 source : https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
🟢 vérification factuelle haute
#GitLab #PathTraversal #Cyberveille
GitLab Discloses Path Traversal Flaw Exploited in Wild
GitLab has revealed a critical path traversal flaw, CVE-2026-85706, that allows unauthenticated users to access sensitive files on its servers, and security researchers have already spotted attackers probing for vulnerabilities in the wild. This maximum-severity bug, scoring a CVSS 10.0, enables hackers to read arbitrary files,…
#PathTraversalFlaw #Gitlab #Cve202685706 #EmergingThreats #RepositoryExploitation
##🚨 CVE-2026-85706: An unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1
##🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure
Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.
⠀
The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.
Affected versions include:
• GitLab 18.7 through versions before 19.1.8
• GitLab 19.2 through versions before 19.2.6
• GitLab 19.3 through versions before 19.3.2
⠀
GitLab disclosed and patched the vulnerability on September 10.
Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.
⠀
Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.
GitLab.com is already patched.
Source: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
##📰 GitLab Patches Critical CVSS 10.0 Path Traversal Vulnerability
GitLab releases emergency patches for a critical CVSS 10.0 path traversal flaw (CVE-2026-85706). Unauthenticated attackers can read arbitrary files. Active scanning detected. Upgrade self-managed instances NOW. #GitLab #CVE #CyberSecurity #PatchNow
##GitLab Users Urged to Act Fast as Maximum-Severity Path Traversal Flaw Faces Early Probing + Video
GitLab Users Urged to Act Fast as Maximum-Severity Path Traversal Flaw Faces Early Probing A Serious Warning for GitLab Administrators GitLab users are facing another urgent cybersecurity warning after the platform patched a maximum-severity vulnerability that could expose sensitive information from vulnerable installations. The flaw, tracked as CVE-2026-85706, involves…
##GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
##https://thecybersecguru.com/news/gitlab-cve-2026-85706-cvss-10-path-traversal/
##GitLab alerta para vulnerabilidade de gravidade máxima e pede atualização imediata. A falha, identificada como CVE-2026-85706, foi descoberta por um investigador de segurança e reportada através do programa de recompensas de bugs do HackerOne. 🚨
##GitLab urges users to patch max severity path traversal flaw
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.
🔗️ [Bleepingcomputer] https://link.is.it/jdshdd
##GitLab Warns Users to Patch Path Traversal Flaw
GitLab is urging users to upgrade immediately to patch a critical path traversal flaw, CVE-2026-85706, that could expose sensitive files to unauthenticated attackers. This maximum-severity vulnerability requires prompt action to protect self-managed GitLab installations.
#Gitlab #PathTraversal #Cve202685706 #VulnerabilityManagement #EmergingThreats
##GitLab patched critical GitLab vulnerabilities, led by CVE-2026-85706 with a CVSS 10.0 score. Update your server now to protect source code from exposure.
#GitLab #CVE202685706 #Vulnerabilities #DevSecOps #Cybersecurity
https://securityonline.info/gitlab-vulnerabilities-cve-2026-85706-cvss-10/
🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-42016 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42016)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016
⚠️ CVE-2026-42018 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42018)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42018
⚠️ CVE-2026-84869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-84869)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-84869
⚠️ CVE-2026-85706 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85706)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85706
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706
##@cR0w no mention of exploitation from CNA GitLab
CVE-2026-85706 - Path Traversal issue in repository commits API impacts GitLab CE/EE
GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Impacted Versions: GitLab CE/EE: all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)Thanks s3ntago for reporting this vulnerability through our HackerOne bug bounty program.
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
##CVE ID: CVE-2026-85706
Vendor: GitLab
Product: Community Edition and Enterprise Edition
Date Added: 2026-09-11
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85706
CVE-2026-85706 is now in the KEV but the CVE still isn't published. LMAO. Go hack and patch more GitLab shit.
##🚨 CVE-2026-85706: An unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1
##🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure
Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.
⠀
The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.
Affected versions include:
• GitLab 18.7 through versions before 19.1.8
• GitLab 19.2 through versions before 19.2.6
• GitLab 19.3 through versions before 19.3.2
⠀
GitLab disclosed and patched the vulnerability on September 10.
Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.
⠀
Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.
GitLab.com is already patched.
Source: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
##GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
##https://thecybersecguru.com/news/gitlab-cve-2026-85706-cvss-10-path-traversal/
##GitLab alerta para vulnerabilidade de gravidade máxima e pede atualização imediata. A falha, identificada como CVE-2026-85706, foi descoberta por um investigador de segurança e reportada através do programa de recompensas de bugs do HackerOne. 🚨
##GitLab urges users to patch max severity path traversal flaw
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.
🔗️ [Bleepingcomputer] https://link.is.it/jdshdd
##GitLab patched critical GitLab vulnerabilities, led by CVE-2026-85706 with a CVSS 10.0 score. Update your server now to protect source code from exposure.
#GitLab #CVE202685706 #Vulnerabilities #DevSecOps #Cybersecurity
https://securityonline.info/gitlab-vulnerabilities-cve-2026-85706-cvss-10/
CVE-2026-61608: SolidInvoice user invitation links never expire—leaked emails can grant access to company accounts anytime. CVSS 6.8. Unpatched risk. Update to v3.0.1 now. https://www.valtersit.com/cve/CVE-2026-61608/ #CVE #infosec #SolidInvoice
##🟠 CVE-2026-89066 - High (7.8)
Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89066/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-89066 - High (7.8)
Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89066/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71416 - High (8.8)
Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71416/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71416 - High (8.8)
Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71416/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##https://thecybersecguru.com/news/gitlab-cve-2026-85706-cvss-10-path-traversal/
##https://thecybersecguru.com/news/gitlab-cve-2026-85706-cvss-10-path-traversal/
##🟠 CVE-2026-87908 - High (7.5)
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87908/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-87908 - High (7.5)
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-87908/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Gen Threat Labs discovered a critical remote code execution vulnerability (CVE-2026-51990) in Sogou Input Method. The vulnerability is actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link. https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou
##Gen Threat Labs discovered a critical remote code execution vulnerability (CVE-2026-51990) in Sogou Input Method. The vulnerability is actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link. https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou
##CVE-2026-73848: XSS in emlog ≤2.6.29 via unescaped tag names in article editor. Attacker executes arbitrary JS via crafted tag—full account takeover risk. CVSS N/A. UNPATCHED. Update or restrict editor access immediately. Details: https://www.valtersit.com/cve/CVE-2026-73848/ #CV
##CVE-2026-57166: Stack buffer overflow in PJSIP's telnet CLI front-end (pj_cli_telnet_cre). Long command lines can overflow fixed buffers—potential code execution. CVSS N/A, unpatched. If you enable telnet CLI, disable it or update once a fix lands. Details: https://www.valtersit.
##Patch CVE-2026-16338 immediately. Learn how this 9.9 CVSS flaw allows arbitrary file write attacks in IBM DataStage and how to secure your data today.
#CVE202616338 #IBMDataStage #CyberSecurity #InfoSec #ArbitraryFileWrite #CloudSecurity #VulnerabilityPatch
##Patch CVE-2026-16338 immediately. Learn how this 9.9 CVSS flaw allows arbitrary file write attacks in IBM DataStage and how to secure your data today.
#CVE202616338 #IBMDataStage #CyberSecurity #InfoSec #ArbitraryFileWrite #CloudSecurity #VulnerabilityPatch
##Dell patched critical Dell ObjectScale vulnerabilities, led by CVE-2026-70416. Fix these Dell ObjectScale vulnerabilities to stop remote code execution.
#DellObjectScale #Cybersecurity #CVE202670416 #Vulnerabilities #InfoSec
##Dell patched critical Dell ObjectScale vulnerabilities, led by CVE-2026-70416. Fix these Dell ObjectScale vulnerabilities to stop remote code execution.
#DellObjectScale #Cybersecurity #CVE202670416 #Vulnerabilities #InfoSec
##Dell patched critical Dell Networking OS10 vulnerabilities, including CVE-2026-63695. Update your Dell SmartFabric OS10 switches to prevent session theft.
#DellNetworking #Cybersecurity #Vulnerabilities #CVE202663695 #InfoSec
##Dell patched critical Dell Networking OS10 vulnerabilities, including CVE-2026-63695. Update your Dell SmartFabric OS10 switches to prevent session theft.
#DellNetworking #Cybersecurity #Vulnerabilities #CVE202663695 #InfoSec
##🔴 CVE-2026-89049 - Critical (9.9)
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89049/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT
Description:
AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances...
https://aws.amazon.com/security/security-bulletins/rss/2026-107-aws/
##🔴 CVE-2026-89049 - Critical (9.9)
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89049/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT
Description:
AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances...
https://aws.amazon.com/security/security-bulletins/rss/2026-107-aws/
##🟠 CVE-2026-88052 - High (7.8)
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_ins...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88052/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-88052 - High (7.8)
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_ins...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-88052/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##2 posts
8 repos
https://github.com/4minx/CVE-2026-72898
https://github.com/0xBlackash/CVE-2026-72898
https://github.com/VuxNx/CVE-2026-72898
https://github.com/codeb0ssx/CVE-2026-72898-PoC
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
https://github.com/Franc-Zar/CVE-2026-72898-safe-detection
https://github.com/d-maggipinto/CVE-2026-72898-metabase-sqli
⚠️Alerte CERT-FR⚠️
Le CERT-FR a connaissance de nombreuses compromissions de Metabase vulnérables à l'injection SQL CVE-2026-72898.
##⚠️Alerte CERT-FR⚠️
Le CERT-FR a connaissance de nombreuses compromissions de Metabase vulnérables à l'injection SQL CVE-2026-72898.
##Arista Networks Arbitrary RCE Vulnerability
Arista EOS에서 P4Runtime가 활성화된 특정 구성에 대해 인증 없이 원격 코드 실행이 가능한 CVE-2026-73453이 공개됐다. 공격자는 P4Runtime 세션 초기화 과정의 악성 패킷으로 스위치의 완전한 관리자 권한을 획득할 수 있으며, CVSS v3.1 점수는 10.0이다. 다만 P4Runtime는 기본적으로 비활성화되어 있으므로, 운영자는 `show p4-runtime`으로 노출 여부를 우선 점검해야 한다. 영향받는 환경은 mTLS와 gNSI Authz를 적용하고, EOS 4.36.2F·4.35.6M·4...
https://www.arista.com/en/support/advisories-notices/security-advisory/24730-security-advisory-0174
##Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line
Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.
**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/fortinet-patches-critical-authentication-bypass-and-proxy-flaws-across-product-line-t-c-t-4-1/gD2P6Ple2L
Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line
Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.
**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/fortinet-patches-critical-authentication-bypass-and-proxy-flaws-across-product-line-t-c-t-4-1/gD2P6Ple2L
CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK
Bulletin ID: 2026-095-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 10:00 AM PDT
Description:
Amazon CodeCatalyst blueprints are reusable project templates that generate a software proj...
https://aws.amazon.com/security/security-bulletins/rss/2026-095-aws/
##Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...
https://aws.amazon.com/security/security-bulletins/rss/2026-086-aws/
##Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...
https://aws.amazon.com/security/security-bulletins/rss/2026-086-aws/
##Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...
https://aws.amazon.com/security/security-bulletins/rss/2026-086-aws/
##🔴 CVE-2026-54694 - Critical (9.6)
SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an H...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54694/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##