##
Updated at UTC 2026-08-04T18:41:50.461972
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-69110 | 9.1 | 0.00% | 2 | 0 | 2026-08-04T17:16:59.733000 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability tha | |
| CVE-2026-69100 | 8.8 | 0.00% | 2 | 0 | 2026-08-04T17:16:59.320000 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains | |
| CVE-2026-48323 | 10.0 | 0.62% | 2 | 0 | 2026-08-04T17:16:55.413000 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-25292 | 7.6 | 0.00% | 2 | 0 | 2026-08-04T17:16:53.797000 | Memory Corruption when processing untrusted user input in the fastboot command h | |
| CVE-2026-24084 | 7.5 | 0.00% | 2 | 0 | 2026-08-04T17:16:52.453000 | Weak configuration when UE does not verify the consistency of its additional sec | |
| CVE-2026-24083 | 7.8 | 0.00% | 2 | 0 | 2026-08-04T17:16:52.040000 | Memory Corruption while processing IOCTL device driver requests with invalid arg | |
| CVE-2026-60007 | 0 | 0.00% | 2 | 0 | 2026-08-04T16:16:26.367000 | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns | |
| CVE-2026-48326 | 9.9 | 0.48% | 2 | 0 | 2026-08-04T16:16:25.497000 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-18686 | 9.8 | 2.61% | 2 | 0 | 2026-08-04T16:16:21.593000 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem | |
| CVE-2026-18401 | None | 0.00% | 1 | 0 | 2026-08-04T15:32:23 | The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the | |
| CVE-2026-69246 | 7.2 | 0.21% | 1 | 0 | 2026-08-04T15:16:42.927000 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives | |
| CVE-2026-66315 | 7.5 | 0.62% | 1 | 0 | 2026-08-04T15:16:38.033000 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke | |
| CVE-2026-48333 | 9.8 | 0.47% | 1 | 0 | 2026-08-04T15:16:35.963000 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | |
| CVE-2026-12816 | 0 | 0.16% | 1 | 0 | 2026-08-04T14:50:12.360000 | In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via len | |
| CVE-2026-58062 | 0 | 0.20% | 2 | 0 | 2026-08-04T14:50:12.360000 | In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without bi | |
| CVE-2026-8763 | 0 | 0.33% | 2 | 0 | 2026-08-04T14:50:12.360000 | In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot | |
| CVE-2026-59638 | 0 | 0.28% | 1 | 0 | 2026-08-04T14:50:12.360000 | In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enable | |
| CVE-2026-48331 | 10.0 | 0.47% | 1 | 0 | 2026-08-04T14:48:22.933000 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) | |
| CVE-2026-62354 | 0 | 0.26% | 1 | 0 | 2026-08-04T14:48:22.933000 | Authorization handling for Parameter Context validation requests in Apache NiFi | |
| CVE-2026-48330 | 10.0 | 0.68% | 1 | 0 | 2026-08-04T14:48:22.933000 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-34641 | 7.8 | 0.14% | 1 | 0 | 2026-08-04T14:48:22.933000 | Premiere Pro is affected by an out-of-bounds write vulnerability that could resu | |
| CVE-2026-6837 | 7.2 | 0.95% | 2 | 0 | 2026-08-04T14:47:47.393000 | A post-authentication command injection vulnerability in the "export-cgi" CGI pr | |
| CVE-2026-18577 | 8.1 | 2.53% | 15 | 1 | 2026-08-04T14:27:12.530000 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco | |
| CVE-2026-18556 | 7.4 | 0.27% | 5 | 0 | 2026-08-04T13:58:04.463000 | Authentication bypass using an alternate path or channel vulnerability in N-able | |
| CVE-2026-14804 | 9.1 | 0.30% | 3 | 0 | 2026-08-04T13:17:35.893000 | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informat | |
| CVE-2026-14175 | 9.8 | 0.40% | 4 | 0 | 2026-08-04T12:34:56 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software | |
| CVE-2026-15721 | 9.8 | 0.23% | 2 | 0 | 2026-08-04T12:34:56 | Cleartext storage of sensitive information vulnerability in Bilin Software and I | |
| CVE-2026-10685 | 7.6 | 0.18% | 1 | 0 | 2026-08-04T12:31:51.160000 | The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() | |
| CVE-2026-17349 | 9.6 | 0.30% | 1 | 0 | 2026-08-04T12:31:51.160000 | /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced | |
| CVE-2026-18754 | 9.1 | 0.31% | 1 | 0 | 2026-08-04T09:31:41 | The product firmware contains an embedded, static RSA private key utilized by th | |
| CVE-2026-15958 | None | 0.14% | 1 | 0 | 2026-08-04T09:31:41 | The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform | |
| CVE-2026-66066 | 0 | 1.70% | 3 | 7 | 2026-08-04T05:16:40.060000 | Action Pack is a framework for handling and responding to web requests. In versi | |
| CVE-2026-68981 | None | 0.32% | 1 | 0 | 2026-08-04T00:35:57 | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the appl | |
| CVE-2026-68979 | None | 0.35% | 1 | 0 | 2026-08-04T00:35:57 | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API me | |
| CVE-2026-18684 | 9.8 | 2.03% | 1 | 0 | 2026-08-04T00:35:01 | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affe | |
| CVE-2026-66310 | 7.7 | 0.40% | 1 | 0 | 2026-08-04T00:35:01 | External control of file name or path in Microsoft Edge for Android allows an un | |
| CVE-2026-66318 | 8.1 | 0.37% | 1 | 0 | 2026-08-04T00:35:01 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize | |
| CVE-2026-18685 | 9.8 | 1.99% | 1 | 0 | 2026-08-04T00:35:01 | A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Imp | |
| CVE-2026-66803 | 10.0 | 0.49% | 1 | 0 | 2026-08-04T00:17:39.977000 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex | |
| CVE-2026-59913 | 7.8 | 0.11% | 1 | 0 | 2026-08-03T21:31:44 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, co | |
| CVE-2026-59912 | 7.8 | 0.10% | 1 | 0 | 2026-08-03T21:31:36 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, co | |
| CVE-2026-18108 | 9.8 | 0.22% | 1 | 0 | 2026-08-03T21:31:35 | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _ve | |
| CVE-2026-67288 | 7.5 | 0.35% | 1 | 0 | 2026-08-03T21:31:31 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart | |
| CVE-2026-69240 | 9.8 | 0.32% | 1 | 0 | 2026-08-03T20:29:52 | ### Summary SQL Injection is possible with strings only **if dialect is set to ` | |
| CVE-2026-67357 | 7.5 | 0.25% | 1 | 0 | 2026-08-03T20:17:27.833000 | ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability | |
| CVE-2026-67298 | 7.5 | 0.38% | 1 | 0 | 2026-08-03T20:17:26.477000 | FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server | |
| CVE-2026-8457 | 9.8 | 0.40% | 2 | 0 | 2026-08-03T19:16:53.733000 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authenticat | |
| CVE-2026-67294 | 5.9 | 0.27% | 1 | 0 | 2026-08-03T19:16:50.143000 | FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose | |
| CVE-2026-67289 | 9.8 | 0.38% | 2 | 0 | 2026-08-03T19:16:50 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and c | |
| CVE-2026-66402 | 9.8 | 0.29% | 2 | 0 | 2026-08-03T19:16:49.210000 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certif | |
| CVE-2026-48449 | 10.0 | 0.54% | 1 | 0 | 2026-08-03T19:16:47.320000 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | |
| CVE-2026-18614 | 9.8 | 2.01% | 1 | 0 | 2026-08-03T19:16:45.200000 | A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the func | |
| CVE-2026-16300 | 9.8 | 0.30% | 1 | 0 | 2026-08-03T18:31:51 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate a passwor | |
| CVE-2026-18612 | 9.8 | 2.16% | 1 | 0 | 2026-08-03T18:30:56 | A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affec | |
| CVE-2026-67296 | 7.5 | 0.34% | 1 | 0 | 2026-08-03T18:16:40.860000 | FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI se | |
| CVE-2026-18574 | 0 | 0.99% | 2 | 0 | 2026-08-03T17:40:27.300000 | An authentication bypass vulnerability in Check Point Security Management Server | |
| CVE-2026-68579 | 9.6 | 0.27% | 1 | 0 | 2026-08-03T17:16:44.330000 | FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the W | |
| CVE-2026-67356 | 8.8 | 0.25% | 1 | 0 | 2026-08-03T17:16:43.343000 | ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigg | |
| CVE-2026-67305 | 0 | 0.49% | 1 | 0 | 2026-08-03T17:16:40.637000 | FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerabili | |
| CVE-2026-67300 | 7.5 | 0.33% | 1 | 0 | 2026-08-03T17:16:40.480000 | FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities i | |
| CVE-2026-67290 | 7.5 | 0.43% | 1 | 0 | 2026-08-03T17:16:40.020000 | FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TS | |
| CVE-2026-65321 | 9.8 | 0.44% | 2 | 1 | 2026-08-03T17:16:39.617000 | PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unau | |
| CVE-2025-71399 | 8.6 | 0.31% | 1 | 0 | 2026-08-03T17:16:28.867000 | Better Auth relies on better-call, which uses the rou3 router library. In affect | |
| CVE-2026-67336 | 8.7 | 0.16% | 1 | 0 | 2026-08-03T16:16:30.790000 | better-auth versions before 1.6.11 contain insecure cryptographic defaults in th | |
| CVE-2026-3245 | 7.5 | 0.24% | 1 | 0 | 2026-08-03T16:16:29.437000 | A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that | |
| CVE-2026-33591 | None | 0.52% | 2 | 0 | 2026-08-03T12:32:43 | A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unaut | |
| CVE-2026-18589 | 9.8 | 0.61% | 1 | 0 | 2026-08-03T09:32:46 | A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the | |
| CVE-2026-9593 | 6.7 | 0.11% | 1 | 0 | 2026-08-03T09:32:46 | A vulnerability in the iDTM FDI allows an attacker with elevated privileges and | |
| CVE-2026-58061 | None | 0.21% | 1 | 0 | 2026-08-03T09:32:36 | In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to calle | |
| CVE-2026-12803 | None | 0.17% | 1 | 0 | 2026-08-03T09:32:36 | In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce w | |
| CVE-2026-59639 | None | 0.17% | 1 | 0 | 2026-08-03T06:32:44 | In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for Sig | |
| CVE-2026-59650 | None | 0.26% | 1 | 0 | 2026-08-03T06:32:44 | In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalid | |
| CVE-2026-68580 | 7.5 | 0.24% | 1 | 0 | 2026-08-02T15:30:26 | FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio inp | |
| CVE-2026-68578 | 7.5 | 0.21% | 1 | 0 | 2026-08-02T15:30:25 | ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the | |
| CVE-2026-68581 | 8.1 | 0.32% | 1 | 0 | 2026-08-02T15:30:25 | Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API | |
| CVE-2026-68582 | 6.5 | 0.21% | 1 | 0 | 2026-08-02T15:30:25 | Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorizat | |
| CVE-2026-18352 | 7.5 | 0.68% | 1 | 0 | 2026-08-02T00:31:17 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversa | |
| CVE-2026-13339 | 7.5 | 0.64% | 1 | 0 | 2026-08-02T00:31:16 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal i | |
| CVE-2026-67292 | 6.5 | 0.26% | 1 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gat | |
| CVE-2026-67291 | 7.5 | 0.34% | 1 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bound | |
| CVE-2026-67304 | 7.5 | 0.35% | 1 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart | |
| CVE-2026-67301 | 7.5 | 0.34% | 1 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async u | |
| CVE-2026-67299 | 7.5 | 0.33% | 1 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async up | |
| CVE-2026-67308 | 10.0 | 0.45% | 1 | 0 | 2026-08-01T15:30:36 | Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub | |
| CVE-2026-67341 | 9.8 | 0.32% | 1 | 0 | 2026-08-01T15:30:30 | ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks o | |
| CVE-2026-67342 | 9.8 | 0.32% | 1 | 0 | 2026-08-01T15:30:30 | ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in | |
| CVE-2026-67297 | 7.5 | 0.34% | 1 | 0 | 2026-08-01T15:30:26 | FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing T | |
| CVE-2026-15414 | 8.8 | 0.34% | 1 | 0 | 2026-08-01T03:31:19 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privileg | |
| CVE-2026-63223 | 9.8 | 0.49% | 1 | 2 | 2026-08-01T00:17:17.750000 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and | |
| CVE-2026-53504 | 7.5 | 0.34% | 1 | 0 | 2026-08-01T00:17:16.823000 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, | |
| CVE-2026-66418 | 9.3 | 0.34% | 1 | 1 | 2026-07-31T23:17:26.170000 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability t | |
| CVE-2026-43832 | 7.5 | 0.24% | 1 | 0 | 2026-07-31T21:32:56 | Successful exploitation of the vulnerability could allow an unauthenticated atta | |
| CVE-2025-69933 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T21:32:55 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /me | |
| CVE-2026-43829 | 7.5 | 0.24% | 1 | 0 | 2026-07-31T21:32:55 | Successful exploitation of the vulnerability could allow an unauthenticated atta | |
| CVE-2026-43831 | 7.5 | 0.24% | 1 | 0 | 2026-07-31T21:32:55 | Successful exploitation of the vulnerability could allow an unauthenticated atta | |
| CVE-2026-15048 | 7.5 | 0.26% | 1 | 0 | 2026-07-31T21:32:55 | The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization c | |
| CVE-2026-67822 | 9.8 | 0.29% | 1 | 0 | 2026-07-31T21:31:55 | Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in | |
| CVE-2026-14930 | 7.5 | 0.24% | 1 | 0 | 2026-07-31T21:31:54 | The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorizati | |
| CVE-2026-53501 | 8.2 | 0.21% | 1 | 0 | 2026-07-31T20:16:51.280000 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, | |
| CVE-2026-43830 | 9.8 | 0.31% | 1 | 0 | 2026-07-31T20:16:50.463000 | Full details and mitigation steps are currently restricted and will be published | |
| CVE-2026-15258 | 8.1 | 0.22% | 1 | 0 | 2026-07-31T20:16:48.207000 | The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not | |
| CVE-2026-14483 | 9.8 | 0.61% | 1 | 2 | 2026-07-31T20:16:46.443000 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulner | |
| CVE-2026-14319 | 7.5 | 0.32% | 1 | 0 | 2026-07-31T20:16:46.290000 | The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to | |
| CVE-2026-56670 | 8.2 | 0.22% | 1 | 0 | 2026-07-31T19:17:11.290000 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes int | |
| CVE-2026-54725 | 9.6 | 0.32% | 1 | 0 | 2026-07-31T19:17:10.833000 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret | |
| CVE-2026-52856 | 7.5 | 0.34% | 1 | 0 | 2026-07-31T19:17:09.120000 | Wings is the server control plane for Pterodactyl, a free, open-source game serv | |
| CVE-2025-69936 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T19:17:03.667000 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /ed | |
| CVE-2025-69935 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T19:17:03.420000 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the | |
| CVE-2025-69934 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T19:17:03.113000 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /de | |
| CVE-2026-53503 | 7.5 | 0.42% | 1 | 0 | 2026-07-31T18:54:57 | ### Summary Thumbor's `filters:convolution(<matrix>, <columns>, <should_normaliz | |
| CVE-2026-62391 | 8.1 | 0.40% | 1 | 0 | 2026-07-31T18:33:21 | The security fix for CVE-2025-66518 is incomplete. Any client who can access to | |
| CVE-2025-69937 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T18:33:16 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the | |
| CVE-2026-58048 | None | 0.50% | 2 | 1 | 2026-07-31T18:32:25 | Improper preservation of SQL mode when renaming databases in cPanel allows exec | |
| CVE-2026-17346 | 8.8 | 0.43% | 1 | 0 | 2026-07-31T18:32:24 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched six | |
| CVE-2026-17351 | 9.0 | 0.45% | 1 | 1 | 2026-07-31T18:32:24 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query pas | |
| CVE-2026-35847 | 9.8 | 0.37% | 1 | 0 | 2026-07-31T18:17:14.613000 | An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrar | |
| CVE-2026-18446 | 7.5 | 0.22% | 1 | 0 | 2026-07-31T18:17:13.383000 | fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash | |
| CVE-2026-12720 | 7.5 | 0.30% | 1 | 1 | 2026-07-31T18:17:10.337000 | The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be | |
| CVE-2026-12695 | 8.1 | 0.29% | 1 | 0 | 2026-07-31T18:17:10.150000 | The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitte | |
| CVE-2026-12251 | 8.1 | 0.23% | 1 | 0 | 2026-07-31T18:17:09.777000 | The Ultimate Member WordPress plugin before 2.12.1 does not filter administrato | |
| CVE-2026-14919 | 9.8 | 0.28% | 1 | 0 | 2026-07-31T17:16:32.863000 | The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its | |
| CVE-2026-13609 | 8.8 | 0.25% | 1 | 0 | 2026-07-31T17:16:32.347000 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML ent | |
| CVE-2026-12721 | 8.6 | 0.26% | 1 | 0 | 2026-07-31T17:16:31.993000 | The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape | |
| CVE-2026-63362 | 5.9 | 1.53% | 1 | 0 | 2026-07-31T16:17:09.013000 | An unsigned integer underflow in the PubSub signature verification path in open | |
| CVE-2026-63222 | 7.5 | 0.45% | 1 | 0 | 2026-07-31T16:17:08.903000 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedF | |
| CVE-2026-52855 | 9.9 | 0.27% | 1 | 0 | 2026-07-31T16:16:48 | ### Impact **Type:** Exposure of sensitive information / insufficiently protect | |
| CVE-2026-63221 | 9.4 | 0.38% | 1 | 0 | 2026-07-31T14:16:50.873000 | CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query B | |
| CVE-2026-14830 | 7.5 | 0.21% | 1 | 0 | 2026-07-31T14:16:46.133000 | The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment proces | |
| CVE-2026-14333 | 7.5 | 0.30% | 1 | 0 | 2026-07-31T14:16:45.960000 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in | |
| CVE-2026-52539 | 9.1 | 0.30% | 1 | 0 | 2026-07-31T12:30:30 | Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOK | |
| CVE-2026-38709 | 9.8 | 2.67% | 2 | 0 | 2026-07-31T12:16:49.683000 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, W | |
| CVE-2026-18452 | 10.0 | 0.43% | 1 | 0 | 2026-07-31T09:31:30 | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials v | |
| CVE-2026-16236 | 8.8 | 0.63% | 1 | 0 | 2026-07-31T09:31:30 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Up | |
| CVE-2026-65309 | 7.5 | 0.15% | 1 | 0 | 2026-07-31T09:31:30 | ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmit | |
| CVE-2026-65310 | 7.5 | 0.32% | 1 | 0 | 2026-07-31T09:31:30 | ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affecte | |
| CVE-2026-12562 | 8.8 | 0.28% | 1 | 0 | 2026-07-31T00:30:29 | The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that | |
| CVE-2026-51291 | 9.8 | 0.00% | 1 | 0 | 2026-07-30T21:31:47 | sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert functi | |
| CVE-2026-43760 | 8.6 | 0.24% | 1 | 0 | 2026-07-30T19:17:30.313000 | An access issue was addressed with improved access restrictions. This issue is f | |
| CVE-2026-17191 | 9.1 | 2.83% | 1 | 0 | 2026-07-30T19:10:52.250000 | An input validation vulnerability exists in an API component of the orchestrator | |
| CVE-2026-17192 | 8.5 | 2.34% | 1 | 0 | 2026-07-30T19:10:52.250000 | A VCO feature does not sufficiently validate caller-supplied input, allowing req | |
| CVE-2026-59309 | 9.8 | 0.74% | 2 | 0 | 2026-07-30T16:17:15.073000 | VMware vCenter contains an authentication bypass vulnerability in the VMware Dir | |
| CVE-2026-41703 | 7.6 | 0.56% | 2 | 0 | 2026-07-30T16:17:11.403000 | VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. | |
| CVE-2026-41709 | 2.7 | 0.38% | 2 | 0 | 2026-07-30T15:31:51 | VMware ESX contains an insufficient logging vulnerability. A malicious administr | |
| CVE-2026-59310 | 9.8 | 1.14% | 2 | 0 | 2026-07-30T15:31:51 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-5492 | 6.5 | 1.60% | 1 | 0 | 2026-07-30T14:18:46.477000 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-5491 | 7.5 | 1.54% | 1 | 0 | 2026-07-30T14:18:46.477000 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-5487 | 7.5 | 1.54% | 1 | 0 | 2026-07-30T14:18:46.477000 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-47876 | 9.3 | 0.28% | 2 | 0 | 2026-07-30T14:16:58.467000 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual | |
| CVE-2026-16498 | 10.0 | 0.33% | 2 | 0 | 2026-07-30T14:08:23.057000 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant cr | |
| CVE-2026-16655 | 7.2 | 0.30% | 1 | 0 | 2026-07-30T14:01:30.413000 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Fo | |
| CVE-2026-12935 | None | 0.81% | 1 | 0 | 2026-07-29T21:31:07 | The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking | |
| CVE-2026-53264 | 7.8 | 0.21% | 2 | 1 | 2026-07-29T21:30:47 | In the Linux kernel, the following vulnerability has been resolved: net/sched: | |
| CVE-2026-67192 | 8.1 | 0.62% | 2 | 0 | 2026-07-29T18:31:46 | Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overfl | |
| CVE-2026-42533 | 8.1 | 3.60% | 1 | 9 | 2026-07-29T05:16:44.720000 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive | |
| CVE-2026-31431 | 7.8 | 94.55% | 1 | 100 | template | 2026-07-28T14:54:01.770000 | In the Linux kernel, the following vulnerability has been resolved: crypto: alg |
| CVE-2026-16462 | 9.8 | 0.42% | 1 | 0 | 2026-07-28T12:31:27 | In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a | |
| CVE-2026-11841 | 9.4 | 0.46% | 1 | 0 | 2026-07-28T12:31:20 | An attacker may perform unauthenticated read and write operations on sensitive f | |
| CVE-2026-12495 | 0 | 0.16% | 2 | 0 | 2026-07-28T08:17:14.187000 | Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http | |
| CVE-2026-48030 | 9.9 | 1.54% | 1 | 1 | 2026-07-27T20:32:11.620000 | Pheditor is a single-file editor and file manager written in PHP. From version 2 | |
| CVE-2026-45112 | 7.5 | 1.94% | 1 | 0 | 2026-07-27T19:51:07.873000 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thr | |
| CVE-2026-63077 | 9.8 | 0.65% | 1 | 1 | 2026-07-27T18:31:56 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe | |
| CVE-2026-9198 | 9.8 | 1.89% | 2 | 3 | template | 2026-07-24T16:57:10.373000 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain |
| CVE-2026-16723 | 9.0 | 0.41% | 1 | 7 | 2026-07-23T15:01:24.377000 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1. | |
| CVE-2026-50522 | 9.8 | 75.76% | 1 | 5 | 2026-07-22T21:31:51 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut | |
| CVE-2026-8933 | 7.8 | 0.21% | 1 | 0 | 2026-07-21T15:30:51 | A local privilege escalation vulnerability exists in snap-confine, a set-capabil | |
| CVE-2026-34486 | 7.5 | 42.63% | 2 | 6 | template | 2026-07-20T12:18:48.440000 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f |
| CVE-2026-15409 | 10.0 | 78.44% | 2 | 6 | template | 2026-07-16T05:16:18.293000 | A Server-side request forgery (SSRF) vulnerability has been identified in the SM |
| CVE-2026-15410 | 7.2 | 76.35% | 2 | 3 | 2026-07-14T21:32:21 | Post-authentication improper control of generation of code ('Code Injection') vu | |
| CVE-2026-54121 | 8.8 | 1.05% | 1 | 12 | 2026-07-14T18:32:37 | Improper authorization in Active Directory Certificate Services (AD CS) allows a | |
| CVE-2026-50343 | 7.8 | 3.50% | 2 | 1 | 2026-07-14T18:32:22 | Improper privilege management in Microsoft Install Service allows an authorized | |
| CVE-2026-46300 | 7.8 | 7.01% | 1 | 15 | 2026-07-14T15:33:05 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff | |
| CVE-2026-43284 | 7.8 | 93.23% | 1 | 43 | 2026-07-14T15:31:59 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: | |
| CVE-2026-49413 | 7.1 | 0.15% | 1 | 1 | 2026-07-01T14:04:37.143000 | The Linuxulator determined whether a binary was set-user-ID or set-group-ID by c | |
| CVE-2026-10702 | 4.3 | 0.72% | 1 | 2 | 2026-06-30T03:36:54 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w | |
| CVE-2026-12044 | 8.8 | 0.71% | 1 | 0 | 2026-06-19T00:31:46 | SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT O | |
| CVE-2026-12045 | 9.0 | 0.48% | 1 | 0 | 2026-06-19T00:31:46 | Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker wh | |
| CVE-2026-42897 | 8.1 | 70.31% | 3 | 1 | 2026-06-17T10:48:34.893000 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2026-1070 | 4.3 | 0.16% | 1 | 2 | 2026-06-17T10:14:56.770000 | The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request F | |
| CVE-2025-8943 | 9.8 | 72.31% | 1 | 0 | template | 2026-06-17T10:07:59.880000 | The Custom MCPs feature is designed to execute OS commands, for instance, using |
| CVE-2023-32233 | 7.8 | 12.97% | 1 | 7 | 2026-06-17T05:58:22.273000 | In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when | |
| CVE-2025-66376 | 7.2 | 21.97% | 1 | 0 | 2026-03-18T18:31:10 | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas | |
| CVE-2025-66518 | None | 0.91% | 1 | 0 | 2026-01-29T03:42:38 | Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols | |
| CVE-2013-4786 | 7.5 | 78.57% | 2 | 1 | 2025-04-11T04:12:49 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R | |
| CVE-2026-18830 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-69098 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-17583 | 0 | 0.00% | 1 | 1 | N/A | ||
| CVE-2026-58073 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-64633 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-59726 | 0 | 0.48% | 3 | 1 | N/A | ||
| CVE-2026-59774 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-56671 | 0 | 0.66% | 1 | 0 | N/A | ||
| CVE-2026-56673 | 0 | 0.43% | 1 | 0 | N/A | ||
| CVE-2026-56672 | 0 | 0.24% | 1 | 0 | N/A | ||
| CVE-2026-4941 | 0 | 0.00% | 1 | 2 | N/A |
updated 2026-08-04T17:16:59.733000
2 posts
🔴 CVE-2026-69110 - Critical (9.1)
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69110/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-69110 - Critical (9.1)
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69110/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T17:16:59.320000
2 posts
🟠 CVE-2026-69100 - High (8.8)
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitel...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69100/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-69100 - High (8.8)
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitel...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69100/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T17:16:55.413000
2 posts
Adobe Campaign Classic is impacted by CVE-2026-48323 (CRITICAL, CVSS 10). Improper neutralization in the template engine allows remote code execution — no user interaction needed. No patch yet. Monitor advisories: https://radar.offseq.com/threat/cve-2026-48323-improper-neutralization-of-special-elements-used-in-a-template-engine-cwe-1336-in-adobe-9070fce8af299a9b #OffSeq #Adobe #Vuln #CVE202648323
##🔴 CVE-2026-48323 - Critical (10)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vul...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48323/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T17:16:53.797000
2 posts
🟠 CVE-2026-25292 - High (7.6)
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-25292/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-25292 - High (7.6)
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-25292/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T17:16:52.453000
2 posts
🟠 CVE-2026-24084 - High (7.5)
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-24084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-24084 - High (7.5)
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-24084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T17:16:52.040000
2 posts
🟠 CVE-2026-24083 - High (7.8)
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-24083/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-24083 - High (7.8)
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-24083/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T16:16:26.367000
2 posts
Eclipse Milo (0.6.0 – 1.1.4) faces a CRITICAL flaw (CVE-2026-60007): error messages in username-token RSA PKCS#1 v1.5 handling enable padding oracle attacks, risking password compromise. Patch status unclear. https://radar.offseq.com/threat/cve-2026-60007-cwe-204-in-eclipse-foundation-eclipse-milo-bf23a775f0392e71 #OffSeq #EclipseMilo #Vuln #Infosec
##Eclipse Milo (0.6.0 – 1.1.4) faces a CRITICAL flaw (CVE-2026-60007): error messages in username-token RSA PKCS#1 v1.5 handling enable padding oracle attacks, risking password compromise. Patch status unclear. https://radar.offseq.com/threat/cve-2026-60007-cwe-204-in-eclipse-foundation-eclipse-milo-bf23a775f0392e71 #OffSeq #EclipseMilo #Vuln #Infosec
##updated 2026-08-04T16:16:25.497000
2 posts
CVE-2026-48326 - Critical SQLi in Adobe Campaign Classic. Low-privilege attacker can achieve RCE. CVSS 9.9, unpatched. Mitigate immediately. #CVE #Adobe #infosec
##🔴 CVE-2026-48326 - Critical (9.9)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48326/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T16:16:21.593000
2 posts
CVE-2026-18686 - Critical command injection in GL.iNet GL-MT3000 via nas-web.add_user. Public exploit, CVSS 9.8, unpatched. Restrict access and monitor now. #CVE #GLiNet #infosec
##CVE-2026-18686: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated code execution possible — no patch yet. Limit admin interface exposure & monitor for abuse. https://radar.offseq.com/threat/cve-2026-18686-command-injection-in-glinet-gl-mt3000-14534eb705079787 #OffSeq #CVE #RouterSecurity
##updated 2026-08-04T15:32:23
1 posts
🚨 EUVD-2026-52703
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: jackson-core, jackson-core, jackson-core (+2 more)
🏢 Vendor: FasterXML
📅 Updated: 2026-08-04
📝 The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.
Th...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52703
##updated 2026-08-04T15:16:42.927000
1 posts
CVE-2026-69246 - Guzzle HTTP client mishandles Host header via libcurl IDNA/decoding, leading to request smuggling/SSRF. CVSS 7.2. No patch yet; upgrade when fixed. #CVE #PHP #infosec
##updated 2026-08-04T15:16:38.033000
1 posts
🟠 CVE-2026-66315 - High (7.5)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66315/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T15:16:35.963000
1 posts
CVE-2026-48333 (CRITICAL, CVSS 9.8): Incorrect Authorization in Adobe Campaign Classic enables attackers to escalate privileges without user interaction. No patch info yet — monitor vendor updates. https://radar.offseq.com/threat/cve-2026-48333-incorrect-authorization-cwe-863-in-adobe-adobe-campaign-classic-c17f18d3ff17c03b #OffSeq #Adobe #Security #CVE202648333
##updated 2026-08-04T14:50:12.360000
1 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-04T14:50:12.360000
2 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##CVE-2026-58062 (CRITICAL, CVSS 9.3): Bouncy Castle Java improperly validates stapled OCSP, risking cert trust. Affects =1.66, <1.85, LTS <2.73.12. Update to 1.85+ or LTS 2.73.12. Details: https://radar.offseq.com/threat/cve-2026-58062-cwe-295-improper-certificate-validation-in-legion-of-the-bouncy-castle-inc-bc-java-1fb42d02f3400e15 #OffSeq #BouncyCastle #JavaSecurity
##updated 2026-08-04T14:50:12.360000
2 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##CVE-2026-8763: CRITICAL vuln in Bouncy Castle BC-JAVA (<1.85, 2.73.0-2.73.11). Improper cert validation via trailing dot bypasses name constraints — risk of MITM attacks. No patch yet. Monitor vendor for updates. https://radar.offseq.com/threat/cve-2026-8763-cwe-295-improper-certificate-validation-in-legion-of-the-bouncy-castle-inc-bc-java-e499664fa1a18bc4 #OffSeq #BouncyCastle #Vuln #CVE20268763
##updated 2026-08-04T14:50:12.360000
1 posts
CVE-2026-59638 (CRITICAL, CVSS 9.3) in BC-JAVA: Improper cert validation due to default CN-fallback can expose TLS connections to MITM. Affects <1.85, LTS <2.73.12. Patch status unknown — monitor vendor & consider disabling fallback. https://radar.offseq.com/threat/cve-2026-59638-cwe-297-improper-validation-of-certificate-with-host-mismatch-in-legion-of-the-bouncy-aa319f6f20b27a8a #OffSeq #CVE202659638 #infosec
##updated 2026-08-04T14:48:22.933000
1 posts
Adobe patched critical Adobe Campaign Classic flaws. CVE-2026-48331 scores CVSS 10.0 and enables arbitrary code execution. Update to build 9399 now.
#Adobe #AdobeCampaignClassic #CVE202648331 #ArbitraryCodeExecution #Vulnerability #SSRF #SQLInjection #InfoSec #CyberSecurity
##updated 2026-08-04T14:48:22.933000
1 posts
Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.
##updated 2026-08-04T14:48:22.933000
1 posts
🔴 CVE-2026-48330 - Critical (10)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48330/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T14:48:22.933000
1 posts
🟠 CVE-2026-34641 - High (7.8)
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-34641/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T14:47:47.393000
2 posts
CVE-2026-6837 - Post-auth command injection in Zyxel WAX650S export-cgi. Admin RCE. CVSS 7.2. Unpatched - restrict admin access now. #CVE #Zyxel #infosec
##CVE-2026-6837 - Post-auth command injection in Zyxel WAX650S export-cgi. Admin RCE. CVSS 7.2. Unpatched - restrict admin access now. #CVE #Zyxel #infosec
##updated 2026-08-04T14:27:12.530000
15 posts
1 repos
🔵 THREAT INTELLIGENCE
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
Vulnerability | CRITICAL
CVEs: CVE-2026-18577
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises...
Full analysis:
https://www.yazoul.net/news/article/cisa-adds-exploited-n-able-n-central-flaw-to-kev-after-customer-compromises
by Yazoul AI
##CISA Warns of Active N-able Flaw Exploit in Federal Agencies
Exploiting the N-able flaw can give attackers unrestricted control over your N-central console, putting your entire operation at risk. Federal agencies have just three days to patch this high-severity vulnerability, tracked as CVE-2026-18577, under CISA's Binding Operational Directive 26-04.
#Nable #Cve202618577 #Cisa #BindingOperationalDirective2604 #FederalAgencies
##New.
Rapid7: CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild/ @Rapid7Official #infosec #vulnerabiity
##CISA added this vulnerability to the catalogue yesterday, if you missed it:
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-18577
Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching https://arcticwolf.com/resources/blog/cve-2026-18556-cve-2026-18577/ #infosec #vulnerability #CISA
##New.
Rapid7: CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild/ @Rapid7Official #infosec #vulnerabiity
##CISA added this vulnerability to the catalogue yesterday, if you missed it:
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-18577
Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching https://arcticwolf.com/resources/blog/cve-2026-18556-cve-2026-18577/ #infosec #vulnerability #CISA
##Geopolitical: Trump indicates ongoing talks with Iran for Strait of Hormuz reopening (Aug 3-4), though Tehran denies. Gaza operations persist.
Technology: SK hynix & Sandisk unveil HBF standard for AI memory (Aug 4). White House schedules AI safety talks (Aug 4).
Cybersecurity: CISA alerts to active exploitation of N-able N-central flaw (CVE-2026-18577) (Aug 3). Interpol: AI fuels over 55% of African cybercrime (Aug 3).
#AnonNews_irc #Cybersecurity #News
URGENT C-SUITE BRIEF: Active exploitation verified on CISA KEV for CVE-2026-18577 (N-able N-central). Executive leadership must oversee immediate patch deployment, supply chain auditing, and trust model revalidation to safeguard organizational assets. Full strategic analysis: https://thecybermind.co/0156
##N-able warns of N-central auth bypass flaw exploited in attacks
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-...
🔗️ [Bleepingcomputer] https://link.is.it/tS9UYV
##N-able warns of N-central auth bypass flaw exploited in attacks
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-...
🔗️ [Bleepingcomputer] https://www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/
##ALERT: Active exploitation verified for CVE-2026-18577 in N-able N-central. Unauthenticated attackers can execute account takeovers via alternate path manipulation. Access our complete threat breakdown, SPL/KQL detection logic, and hardening guidance here: https://thecybermind.co/jily
##🚨 [CISA-2026:0803] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-18577 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm ; https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-18577
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260803 #cisa20260803 #cve_2026_18577 #cve202618577
##CVE ID: CVE-2026-18577
Vendor: N-able
Product: N-central
Date Added: 2026-08-03
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18577
CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.
#Nable #Ncentral #CVE202618577 #AccountTakeover #RMM #CyberSecurity
##Some time ago I discovered a meddler in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse:
https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
##updated 2026-08-04T13:58:04.463000
5 posts
CVE ID: CVE-2026-18556
Vendor: N-able
Product: N-central
Date Added: 2026-08-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18556
CISA added this vulnerability to the catalogue yesterday, if you missed it:
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-18577
Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching https://arcticwolf.com/resources/blog/cve-2026-18556-cve-2026-18577/ #infosec #vulnerability #CISA
##CVE ID: CVE-2026-18556
Vendor: N-able
Product: N-central
Date Added: 2026-08-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18556
CISA added this vulnerability to the catalogue yesterday, if you missed it:
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-18577
Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching https://arcticwolf.com/resources/blog/cve-2026-18556-cve-2026-18577/ #infosec #vulnerability #CISA
##🏆 New Achievement! Management Remotely Destroyed!
Today's dungeon crawl is brought to you by Deferred Patch Tuesdays — when you're too busy managing clients to manage yourself. N-able N-central, the RMM platform MSPs trust to run everyone else's networks, is harboring CVE-2026-18556, a CVSS 9.8 authentication bypass being actively exploited in the wild. Attackers are waltzing — no, sorry — strolling right through, dropping Cloudflare tunnels for cozy, persistent access. (1/2)
##updated 2026-08-04T13:17:35.893000
3 posts
🔴 CVE-2026-14804 - Critical (9.1)
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.
This issue affects HUMANIST Digital Human Resources: from ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14804/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-14804 - Critical (9.1)
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.
This issue affects HUMANIST Digital Human Resources: from ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14804/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-14804: CRITICAL (CVSS 9.1) in HUMANIST Digital HR v26.0 🛡️ Hard-coded cryptographic key (CWE-321) allows data exposure & integrity loss. No official fix — limit access & track vendor updates. https://radar.offseq.com/threat/cve-2026-14804-cwe-321-use-of-hard-coded-cryptographic-key-in-bilin-software-and-informatics-7feb29c78f0c5d49 #OffSeq #Vulnerability #CVE202614804
##updated 2026-08-04T12:34:56
4 posts
🔴 CVE-2026-14175 - Critical (9.8)
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.
This issue affects HUMANIST Digital Human Resources: from...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14175/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-14175 (CRITICAL, CVSS 9.8): HUMANIST Digital HR v26.0 has an unrestricted file upload flaw — attackers can deploy web shells for full compromise. No patch yet. Restrict uploads, monitor, and apply network controls. https://radar.offseq.com/threat/cve-2026-14175-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-bilin-software-and-caf423644ef42f8e #OffSeq #Vuln #AppSec
##🔴 CVE-2026-14175 - Critical (9.8)
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.
This issue affects HUMANIST Digital Human Resources: from...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14175/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-14175 (CRITICAL, CVSS 9.8): HUMANIST Digital HR v26.0 has an unrestricted file upload flaw — attackers can deploy web shells for full compromise. No patch yet. Restrict uploads, monitor, and apply network controls. https://radar.offseq.com/threat/cve-2026-14175-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-bilin-software-and-caf423644ef42f8e #OffSeq #Vuln #AppSec
##updated 2026-08-04T12:34:56
2 posts
🔴 CVE-2026-15721 - Critical (9.8)
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-15721 - Critical (9.8)
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T12:31:51.160000
1 posts
🟠 CVE-2026-10685 - High (7.6)
The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0).
Per the pub...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10685/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T12:31:51.160000
1 posts
🔴 CVE-2026-17349 - Critical (9.6)
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, sh...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17349/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T09:31:41
1 posts
CVE-2026-18754: GeoVision GV-AS1620 (GV-Cloud) v1.16 has a CRITICAL bug — static RSA key in firmware lets attackers decrypt HTTPS & spoof server. No fix yet; restrict access & watch for vendor updates. https://radar.offseq.com/threat/cve-2026-18754-cwe-321-use-of-hard-coded-cryptographic-key-in-geovision-inc-gv-as1620-gv-cloud-c051119ceee7e889 #OffSeq #Vuln #Cybersecurity #TLS
##updated 2026-08-04T09:31:41
1 posts
CVE-2026-15958 (CRITICAL): Easy Integration for Dropbox <2.2.0 suffers from missing authorization, letting unauthenticated users manage Dropbox files and access account emails. Patch or disable plugin. https://radar.offseq.com/threat/cve-2026-15958-cwe-862-missing-authorization-in-easy-integration-for-dropbox-50b9554583db42aa #OffSeq #WordPress #CVE #Security
##updated 2026-08-04T05:16:40.060000
3 posts
7 repos
https://github.com/0xBlackash/CVE-2026-66066
https://github.com/HackSpeak/CVE-2026-66066
https://github.com/0xsha/KindaRails2Shell
https://github.com/paveg/rails-activestorage-vips-audit
https://github.com/shinthink/CVE-2026-66066
A critical KindaRails2Shell Rails RCE flaw (CVE-2026-66066) in Active Storage exposes servers to secret theft and remote code execution via image uploads.
#RubyOnRails #KindaRails2Shell #CVE202666066 #Cybersecurity #WebSecurity
##📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
Ruby on Rails warnt vor CVE-2026-66066 in Active Storage. Angreifer können über präparierte Bild-Uploads Dateien des Servers auslesen und so an Schlüssel oder Zugangsdaten gelangen. Betroffen sind Anwendungen mit libvips. Updates und forensische Prüfwerkzeuge stehen bereit.
1/2
##updated 2026-08-04T00:35:57
1 posts
Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.
##updated 2026-08-04T00:35:57
1 posts
Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.
##updated 2026-08-04T00:35:01
1 posts
CVE-2026-18684 | CRITICAL command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5) 🛡️ Remote attackers can execute commands — no patch yet. Restrict access and watch for vendor updates. Info: https://radar.offseq.com/threat/cve-2026-18684-command-injection-in-glinet-gl-mt3000-4a4de87391e0f428 #OffSeq #CVE202618684 #IoTSecurity
##updated 2026-08-04T00:35:01
1 posts
🟠 CVE-2026-66310 - High (7.7)
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T00:35:01
1 posts
🟠 CVE-2026-66318 - High (8.1)
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66318/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T00:35:01
1 posts
CVE-2026-18685: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated RCE possible. No patch yet — restrict access & monitor for abuse. Details: https://radar.offseq.com/threat/cve-2026-18685-command-injection-in-glinet-gl-mt3000-32060ee21fb81c76 #OffSeq #vuln #IoT #infosec
##updated 2026-08-04T00:17:39.977000
1 posts
🔴 CVE-2026-66803 - Critical (10)
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66803/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T21:31:44
1 posts
🟠 CVE-2026-59913 - High (7.8)
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59913/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T21:31:36
1 posts
🟠 CVE-2026-59912 - High (7.8)
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59912/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T21:31:35
1 posts
CVE-2026-18108 - Critical auth bypass in Perl Net::SAML2. Encrypted assertions without signatures accepted. CVSS 9.8. Upgrade to >=0.86 now. #CVE #Perl #infosec
##updated 2026-08-03T21:31:31
1 posts
🟠 CVE-2026-67288 - High (7.5)
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T20:29:52
1 posts
🔴 CVE-2026-69240 - Critical (9.8)
Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69240/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T20:17:27.833000
1 posts
🟠 CVE-2026-67357 - High (7.5)
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-Ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67357/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T20:17:26.477000
1 posts
🟠 CVE-2026-67298 - High (7.5)
FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_L...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67298/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T19:16:53.733000
2 posts
CVE-2026-8457: WPWeb WooCommerce - Social Login (<=2.8.7) suffers CRITICAL auth bypass. Forged Apple id_tokens + exposed nonce = attacker can access any WordPress user, even admins. Disable Apple login or plugin ASAP. https://radar.offseq.com/threat/cve-2026-8457-cwe-289-authentication-bypass-by-alternate-name-in-wpweb-woocommerce-social-login-6bb1cfa7304c2708 #OffSeq #WordPress #Vuln
##🔴 CVE-2026-8457 - Critical (9.8)
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T19:16:50.143000
1 posts
CVE-2026-67294 | FreeRDP <3.29.0: Improper EKU validation lets trusted clientAuth certs be accepted as server certs in TLS, enabling RDP server impersonation. Severity: CRITICAL. Patch pending. https://radar.offseq.com/threat/freerdp-before-3290-improperly-validates-the-extended-key-usage-eku-purpose-of-the-peer-certificate-be33a6738062bc49 #OffSeq #FreeRDP #TLS #infosec
##updated 2026-08-03T19:16:50
2 posts
CVE-2026-67289: FreeRDP ≤3.28.0 has a CRITICAL flaw (CVSS 9.8) in RDP redirection — improper CRLF/control character validation exposes clients to HTTP header injection via proxies. Upgrade to 3.29.0+ now. https://radar.offseq.com/threat/freerdp-before-3290-affected-versions-3280-does-not-validate-crlf-and-control-characters-in-the-server-2a6872dd9d8a1a0c #OffSeq #FreeRDP #CVE202667289 #infosec
##🔴 CVE-2026-67289 - Critical (9.8)
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67289/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T19:16:49.210000
2 posts
CVE-2026-66402: FreeRDP <=3.28.0 suffers CRITICAL TLS cert validation flaws. Attackers can bypass server identity checks — risk of MITM & impersonation. Patch to 3.29.0 ASAP. 🔒 https://radar.offseq.com/threat/freerdp-before-3290-affected-versions-3280-contains-multiple-tls-certificate-identity-validation-277a8c919a50c368 #OffSeq #Vulnerability #TLS #FreeRDP
##🔴 CVE-2026-66402 - Critical (9.8)
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66402/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T19:16:47.320000
1 posts
Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now.
#AdobeCampaign #CVE202648449 #AdobeBridge #CriticalPatch #RCE
##updated 2026-08-03T19:16:45.200000
1 posts
🔴 CVE-2026-18614 - Critical (9.8)
A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18614/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T18:31:51
1 posts
CVE-2026-16300: ChamaWP (<1.0.13) is vulnerable to missing authorization — attackers can reset any user’s password, including admins. Risk: full site takeover. Patch status unconfirmed; restrict password resets & monitor logs. https://radar.offseq.com/threat/cve-2026-16300-cwe-862-missing-authorization-in-chamawp-fe7ac84163659c18 #OffSeq #WordPress #Vuln
##updated 2026-08-03T18:30:56
1 posts
CVE-2026-18612 - Critical command injection in GL.iNet GL-MT3000 (<=4.4.5). Remote exploit public, unpatched. CVSS 9.8. Disable remote management immediately. #CVE #GLiNet #infosec
##updated 2026-08-03T18:16:40.860000
1 posts
🟠 CVE-2026-67296 - High (7.5)
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67296/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T17:40:27.300000
2 posts
CVE-2026-18574 is a Check Point authentication bypass rated CVSS 9.3, letting attackers run commands as admin. Patch via the latest Jumbo Hotfix.
#CheckPoint #CVE202618574 #AuthenticationBypass #SecurityManagement #CyberSecurity #Firewall
##CRITICAL auth bypass (CVE-2026-18574, CVSS 9.3) affects Check Point Security Management Server & MDS. Remote attackers can execute commands w/o auth. No patch yet — restrict management access. https://radar.offseq.com/threat/cve-2026-18574-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-checkpoint-security-b30ba167a9a0b365 #OffSeq #CVE202618574 #CheckPoint #Infosec 🔒
##updated 2026-08-03T17:16:44.330000
1 posts
🔴 CVE-2026-68579 - Critical (9.6)
FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68579/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T17:16:43.343000
1 posts
🟠 CVE-2026-67356 - High (8.8)
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can creat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67356/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T17:16:40.637000
1 posts
FreeRDP Windows client <3.29.0 has a CRITICAL heap buffer overflow in clipboard virtual channel (CVE-2026-67305). Malicious RDP servers can trigger remote code execution. Upgrade to 3.29.0+ ASAP. https://radar.offseq.com/threat/freerdp-windows-client-before-3290-contains-a-heap-buffer-overflow-vulnerability-in-the-clipboard-852516cbfae157b3 #OffSeq #FreeRDP #CVE202667305 #infosec
##updated 2026-08-03T17:16:40.480000
1 posts
🟠 CVE-2026-67300 - High (7.5)
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67300/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T17:16:40.020000
1 posts
🟠 CVE-2026-67290 - High (7.5)
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67290/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T17:16:39.617000
2 posts
1 repos
CRITICAL: PyAthena <3.35.4 is vulnerable to SQL injection (CVE-2026-65321). Improper escaping allows unauthenticated attackers to inject SQL, risking data loss/exfiltration. Patch status unconfirmed — restrict DELETE/CTAS use. https://radar.offseq.com/threat/cve-2026-65321-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-in-1db4ff7a0ac0fe70 #OffSeq #CVE202665321 #PyAthena
##🔴 CVE-2026-65321 - Critical (9.8)
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65321/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T17:16:28.867000
1 posts
🟠 CVE-2025-71399 - High (8.6)
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71399/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T16:16:30.790000
1 posts
CVE-2026-67336: better-auth <1.6.11 uses insecure crypto defaults in oidcProvider & mcp, advertising 'none' algo & accepting plain PKCE. Exploitation can lead to unsigned tokens & code interception. Severity: CRITICAL. Patch to 1.6.11+ https://radar.offseq.com/threat/better-auth-versions-before-1611-contain-insecure-cryptographic-defaults-in-the-oidcprovider-and-mcp-eb22076a221f3a81 #OffSeq #CVE202667336 #OAuth #Security
##updated 2026-08-03T16:16:29.437000
1 posts
🟠 CVE-2026-3245 - High (7.5)
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3245/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T12:32:43
2 posts
WAPT Server (CVE-2026-33591) : une faille permet de contourner l’authentification https://www.it-connect.fr/wapt-server-cve-2026-33591/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##Tranquil IT WAPT Server 2.6.0.16767 hit by CVE-2026-33591 (CRITICAL, CVSS 10). Remote attackers can bypass authentication & grab session tokens via crafted packets. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-33591-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-tranquil-it-systems-98c0bb813dbf7caa #OffSeq #CVE202633591 #Infosec #Vulnerability
##updated 2026-08-03T09:32:46
1 posts
CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. https://radar.offseq.com/threat/cve-2026-18589-stack-based-buffer-overflow-in-wavlink-wl-nu516u1-be242f6f491145cd #OffSeq #CVE202618589 #IoTSecurity #PatchManagement
##updated 2026-08-03T09:32:46
1 posts
#OT #Advisory VDE-2026-065
Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library
A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.
#CVE CVE-2026-9593
https://certvde.com/en/advisories/vde-2026-065/
#CSAF https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-065.json
##updated 2026-08-03T09:32:36
1 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-03T09:32:36
1 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-03T06:32:44
1 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-03T06:32:44
1 posts
BC-JAVA users: CVE-2026-59650 (CRITICAL, CVSS 9.3) exposes MTI/A0 Diffie-Hellman via improper input validation. Affects <1.85, 2.73.0 – 2.73.11. No patch yet — avoid affected versions & monitor for updates. https://radar.offseq.com/threat/cve-2026-59650-cwe-20-improper-input-validation-in-legion-of-the-bouncy-castle-inc-bc-java-bfb9720e803b614a #OffSeq #Vulnerability #Java #Cryptography
##updated 2026-08-02T15:30:26
1 posts
🟠 CVE-2026-68580 - High (7.5)
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can su...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68580/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:25
1 posts
🟠 CVE-2026-68578 - High (7.5)
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema muta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68578/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:25
1 posts
🟠 CVE-2026-68581 - High (8.1)
Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JW...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68581/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:25
1 posts
CVE-2026-68582 (CRITICAL): go-vikunja vikunja ≤2.3.0 allows attackers with a share link to read kanban bucket titles & user info from other tenants due to broken object auth at /projects/{project}/views/{view}/tasks. Update to 2.4.0+! https://radar.offseq.com/threat/cve-2026-68582-authorization-bypass-through-user-controlled-key-in-go-vikunja-vikunja-b2e26579de3aa2bc #OffSeq #CVE202668582 #Vulnerability
##updated 2026-08-02T00:31:17
1 posts
🟠 CVE-2026-18352 - High (7.5)
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18352/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T00:31:16
1 posts
🟠 CVE-2026-13339 - High (7.5)
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arb...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13339/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
FreeRDP <3.29.0 has a CRITICAL buffer over-disclosure (CVE-2026-67292). Malicious WebSocket peers can leak memory or crash clients via crafted Ping frames. No patch confirmed — avoid unknown gateways. Details: https://radar.offseq.com/threat/freerdp-before-3290-contains-a-buffer-over-disclosure-vulnerability-in-the-gateway-websocket-transport-67044e0124c23808 #OffSeq #FreeRDP #CVE202667292 #AppSec
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67291 - High (7.5)
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67291/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67304 - High (7.5)
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67304/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67301 - High (7.5)
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67301/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67299 - High (7.5)
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67299/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🔴 CVE-2026-67308 - Critical (10)
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters int...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67308/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:30
1 posts
ArcadeDB (<26.7.2) hit by CRITICAL vuln (CVE-2026-67341, CVSS 9.3). Improper auth lets users with DB access execute arbitrary JS via DEFINE FUNCTION, bypassing admin-only restrictions. Restrict access, monitor usage, check for patches. https://radar.offseq.com/threat/cve-2026-67341-incorrect-authorization-in-arcadedata-arcadedb-6bb8ad21f1650c1c #OffSeq #CVE #infosec
##updated 2026-08-01T15:30:30
1 posts
ArcadeDB <26.7.2 hit by CRITICAL CVE-2026-67342: Auth bypass via unvalidated HTTP endpoints (time series, batch, Prometheus, Grafana). Attackers can access & modify DBs. Restrict endpoints, monitor logs. https://radar.offseq.com/threat/cve-2026-67342-authorization-bypass-through-user-controlled-key-in-arcadedata-arcadedb-9042ff023c492871 #OffSeq #ArcadeDB #Vuln #Infosec
##updated 2026-08-01T15:30:26
1 posts
🟠 CVE-2026-67297 - High (7.5)
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67297/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T03:31:19
1 posts
🟠 CVE-2026-15414 - High (8.8)
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15414/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T00:17:17.750000
1 posts
2 repos
🔴 CVE-2026-63223 - Critical (9.8)
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an applicat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63223/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T00:17:16.823000
1 posts
🟠 CVE-2026-53504 - High (7.5)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53504/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T23:17:26.170000
1 posts
1 repos
🔴 CVE-2026-66418 - Critical (9.3)
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is reco...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66418/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:56
1 posts
🟠 CVE-2026-43832 - High (7.5)
Full details and mitigation steps are currently restricted and will be published at a later date.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43832/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:55
1 posts
🔴 CVE-2025-69933 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69933/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:55
1 posts
🟠 CVE-2026-43829 - High (7.5)
Full details and mitigation steps are currently restricted and will be published at a later date.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43829/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:55
1 posts
🟠 CVE-2026-43831 - High (7.5)
Full details and mitigation steps are currently restricted and will be published at a later date.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43831/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:55
1 posts
🟠 CVE-2026-15048 - High (7.5)
The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15048/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:31:55
1 posts
🔴 CVE-2026-67822 - Critical (9.8)
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without leng...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67822/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:31:54
1 posts
🟠 CVE-2026-14930 - High (7.5)
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14930/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:51.280000
1 posts
🟠 CVE-2026-53501 - High (8.2)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() remove...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53501/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:50.463000
1 posts
🔴 CVE-2026-43830 - Critical (9.8)
Full details and mitigation steps are currently restricted and will be published at a later date.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43830/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:48.207000
1 posts
🟠 CVE-2026-15258 - High (8.1)
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL inje...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:46.443000
1 posts
2 repos
🔴 CVE-2026-14483 - Critical (9.8)
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14483/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:46.290000
1 posts
🟠 CVE-2026-14319 - High (7.5)
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their n...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14319/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:11.290000
1 posts
🟠 CVE-2026-56670 - High (8.2)
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56670/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:10.833000
1 posts
🔴 CVE-2026-54725 - Critical (9.6)
vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54725/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:09.120000
1 posts
🟠 CVE-2026-52856 - High (7.5)
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52856/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:03.667000
1 posts
🔴 CVE-2025-69936 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:03.420000
1 posts
🔴 CVE-2025-69935 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:03.113000
1 posts
🔴 CVE-2025-69934 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:54:57
1 posts
🟠 CVE-2026-53503 - High (7.5)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(, , ) filter passes the user-controlled value to a C extension (thumbor/ext/filters/_convolution.c) where it is used as a divisor (for %...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53503/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:21
1 posts
🟠 CVE-2026-62391 - High (8.1)
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.
This issue ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:16
1 posts
🔴 CVE-2025-69937 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69937/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:25
2 posts
1 repos
cPanel Flaw Exposes Database Vulnerability to Authenticated Users
A critical cPanel flaw, CVE-2026-58048, with a near-perfect CVSS score of 9.4, allows authenticated users to execute SQL commands with root-level access, putting databases at risk. This vulnerability lets users with basic cPanel access escalate privileges and take control of the server's administrative database.
#Cpanel #Cve202658048 #SqlInjection #PrivilegeEscalation #WebHosting
##CVE-2026-58048: cPanel Root SQL Execution Flaw Patched
##updated 2026-07-31T18:32:24
1 posts
🟠 CVE-2026-17346 - High (8.8)
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:24
1 posts
1 repos
🔴 CVE-2026-17351 - Critical (9)
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17351/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:14.613000
1 posts
🔴 CVE-2026-35847 - Critical (9.8)
An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35847/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:13.383000
1 posts
🟠 CVE-2026-18446 - High (7.5)
fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18446/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:10.337000
1 posts
1 repos
https://github.com/webshellseo8/CVE-2026-12720-Proof-of-Concept
🟠 CVE-2026-12720 - High (7.5)
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12720/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:10.150000
1 posts
🟠 CVE-2026-12695 - High (8.1)
The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:09.777000
1 posts
🟠 CVE-2026-12251 - High (8.1)
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12251/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T17:16:32.863000
1 posts
🔴 CVE-2026-14919 - Critical (9.8)
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to red...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14919/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T17:16:32.347000
1 posts
🟠 CVE-2026-13609 - High (8.8)
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13609/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T17:16:31.993000
1 posts
🟠 CVE-2026-12721 - High (8.6)
The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:17:09.013000
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-31T16:17:08.903000
1 posts
🟠 CVE-2026-63222 - High (7.5)
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63222/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:16:48
1 posts
🔴 CVE-2026-52855 - Critical (9.9)
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T14:16:50.873000
1 posts
🔴 CVE-2026-63221 - Critical (9.4)
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63221/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T14:16:46.133000
1 posts
🟠 CVE-2026-14830 - High (7.5)
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without pa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14830/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T14:16:45.960000
1 posts
🟠 CVE-2026-14333 - High (7.5)
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14333/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T12:30:30
1 posts
🔴 CVE-2026-52539 - Critical (9.1)
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52539/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T12:16:49.683000
2 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
🔴 CVE-2026-38709 - Critical (9.8)
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulne...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-38709/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:30
1 posts
🔴 CVE-2026-18452 - Critical (10)
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:30
1 posts
🟠 CVE-2026-16236 - High (8.8)
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficie...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16236/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:30
1 posts
🟠 CVE-2026-65309 - High (7.5)
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores
and transmits user passwords using a reversible format instead of a
one-way password hash. This allows an attacker able to read the
credential store or capture network traffic to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65309/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:30
1 posts
🟠 CVE-2026-65310 - High (7.5)
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any authentication and permissive CORS on every response. An
unauthenticated attacker with network acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T00:30:29
1 posts
🟠 CVE-2026-12562 - High (8.8)
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug interface granting full root-level access
to the embedded system. This vulnerability stems from a
network-accessible port running a Target Communica...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12562/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:47
1 posts
Ok, the first one is absolutely it:
##Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.
updated 2026-07-30T19:17:30.313000
1 posts
macOS security bug went unreported due to Apple being deluged by AI slop reports
Apple이 macOS Screen Sharing/Remote Management의 레거시 VNC 비밀번호 옵션에서 발생하는 원격 코드 실행 취약점(CVE-2026-43760)을 수정했습니다. 공격자는 macOS 계정 없이 VNC 비밀번호만으로 인증한 뒤 로직 결함을 악용해 root 소유 파일을 생성할 수 있으며, 예시로 /private/etc/sudoers.d에 무비밀번호...
##updated 2026-07-30T19:10:52.250000
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-30T19:10:52.250000
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-30T16:17:15.073000
2 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T16:17:11.403000
2 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T15:31:51
2 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T15:31:51
2 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T14:18:46.477000
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-30T14:18:46.477000
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-30T14:18:46.477000
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-30T14:16:58.467000
2 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T14:08:23.057000
2 posts
Terraform MCP Server Flaw CVE-2026-16498 Scores CVSS 10.0
##Terraform MCP Server Flaw CVE-2026-16498 Scores CVSS 10.0
##updated 2026-07-30T14:01:30.413000
1 posts
Fluent Forms CVE-2026-16655 scores 7.2 on the CVSS scale — High severity — and allows data manipulation or extraction without admin credentials. If my sites were running Fluent Forms below 6.2.8, updating would be my immediate priority. Check your version now and update to 6.2.8.
#WordPress #WordPressSecurity #FluentForms #CVE #WebSecurity
##updated 2026-07-29T21:31:07
1 posts
A TP-Link TL-WR940N flaw, CVE-2026-12935, allows unauthenticated remote code execution via an RTSP stack buffer overflow. Update the router firmware now.
#TPLink #TLWR940N #CVE202612935 #RCE #RouterSecurity #InfoSec
##updated 2026-07-29T21:30:47
2 posts
1 repos
A Linux kernel vulnerability, CVE-2026-53264, lets a local user run arbitrary code via a net/sched use-after-free. A public PoC is now available.
#CVE202653264 #LinuxKernel #UseAfterFree #PrivilegeEscalation #InfoSec
##A Linux kernel vulnerability, CVE-2026-53264, lets a local user run arbitrary code via a net/sched use-after-free. A public PoC is now available.
#CVE202653264 #LinuxKernel #UseAfterFree #PrivilegeEscalation #InfoSec
##updated 2026-07-29T18:31:46
2 posts
Pre-Auth Stack Buffer Overflow Hits Xlight FTP Server (CVE-2026-67192)
https://securityonline.info/xlight-ftp-cve-2026-67192/?utm_source=mastodon&utm_medium=jetpack_social
##Pre-Auth Stack Buffer Overflow Hits Xlight FTP Server (CVE-2026-67192)
https://securityonline.info/xlight-ftp-cve-2026-67192/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-29T05:16:44.720000
1 posts
9 repos
https://github.com/suominen/CVE-2026-42533
https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report
https://github.com/Daniyal48/ghostlock-vagrant-box
https://github.com/srkyn/nginx-map-risk-audit
https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner
https://github.com/seguridadentrerios/CVE-2026-42533
https://github.com/jelasin/CVE-2026-42533
Here's my five-week holiday, June 27 - August 2. This is the evidence trail of a man who does not know how to stop.
Running (11 runs, ~131 km):
- Jun 27: 12 km
- Jun 29: 6.5 km easy
- Jul 1: 8.37 km Mile Repeats treadmill
- Jul 4: 15.14 km trail long run
- Jul 6: 5.33 km easy hill run in drizzle
- Jul 11: 10.33 km long run in +30°C heat
- Jul 17: 6.26 km Zwift Hill Repeats
- Jul 18: 21.90 km half marathon
- Jul 21: 6.01 km Tempo 2-1 outdoors
- Jul 23: 5.05 km Current Pace Calibration 5K
- Jul 25: 25.03 km "Lost in the Swamp" 25K trail, 397m elevation
- Jul 27: 5.04 km Zwift Lutece Express, Paris
- Jul 28: 6.16 km Zwift On Off Ks
- Jul 30: 5.04 km 5x1km intervals
- Aug 1: 26.41 km 26K trail adventure, 415m elevation, 211 min
Health setbacks:
- Jun 27: 9/10 migraine at 23:55
- Jul 18: 9/10 migraine
- Jul 19: terrible postdrome
- Jun 28: postdrome day
Linux desktop deep dive (the real holiday project):
- Switched compositor from Hyprland to driftwm (infinite canvas + DMS shell)
- Built the "quantum realm" living wallpaper - transparent evolving fbm fog/stream/void over a NASA starmap
- Fixed driftwm animated blur GPU overheating (PR #220), stale pointer constraint, VRR support
- Submitted PRs for driftwm blur mask caching (#185) and animate_fps background cap (#184)
- Tried and rejected niri (tile columns kill floating workflow I'm fond of)
- Tried and abandoned Nourish/Y5 Dev session (no XWayland, launcher friction)
- Wrote a full compositor alternatives comparison doc
RAM saga:
- Diagnosed OW2 FPS collapse on Arch: 30 GB demand vs 16 GB RAM, swap full issue
- Survived earlyoom killing the compositor under a ~21 GB DMS shell leak, since fixed
- Ordered Corsair LPX 2x16 GB DDR4-3200, installed to 48 GB total
- Fixed accidentally forgotten MemoryHigh=3G shell cap that had throttled 1.3M times and forced 10 GB into swap
Gaming:
- Started Red Dead Redemption 2 (Jul 4)
- Overwatch 2: fixed dead-zone click bug, recovered corrupted update (75 GB repair), played several comps
- Played RV There Yet? with my son, laughed our assess off (Jul 22)
- Deeper gaming and compatibility optimizations on Linux
Mementomori ry association:
- Filed Mementomori ry association application to PRH - registered Jul 7
- Applied for bank account, handled phone calls, paperwork, meeting minutes
- Set up emails
- Rewrote mementomori.social terms of service
- Decided membership fees, signed board minutes
- Built sophisticated signup-report-monitor (Mastodon to Matrix forwarder)
- Built members.mementomori.social MVP
- Mementods Mastodon fork upgrades from upstream to v4.7.0-alpha.1 and alpha.2
Open source contributions:
- Halloy IRC client: timestamp position PR (#2206), blank space fix PR (#2221), ISO-8859-1 decode PR (#2254)
- Sidra music player: Last.fm scrobbling PR (#145)
- DMS plugin registry: CPU, Disk, I/O monitors submitted
- Released dms-cpu-monitor, dms-disk-monitor, dms-ram-monitor, dms-vram-monitor, dms-gpu-monitor (all from 1.0.0 through multiple releases)
- Released lc (linux-cleaner) among other side projects
Server / infra:
- 2 server maintenance windows
- Upgraded 31 servers in total
- One dist-upgrade from Ubuntu server 20.04 through 22.04 to 24.04 LTS
- Built another personal dedicated server for side projects, migrated some services to it from other servers
- Fixed some StorageBox issues, shipped open source tool backup-to-storagebox v3.0.0
- Fixed minor DNS/Redis issues on multiple servers
- Addressed nginx CVE-2026-42533
- Fixed some failing certs, stale mounts, CIFS hangs due incident calls
Customer client work (yes, on holiday, I'm an entrepreneur):
- ~25 tickets handled
- Fixed issues for 14 sites
- Sent 2 quotes
- Handled 5 job applications
- Fixed one unauthenticated nonce type confusion vulnerability
- Fixed one caching issue
Personal infra / tools:
- Built and iterated dough (open source personal budgeting app): releases 3.3.0 through 3.16.0
- Built dough-mcp (releases 0.2.0 through 0.3.0)
- Nanoclaw (Son of Anton) fork releases 1.19.0 through 1.30.0 (12 releases)
- Personal day planner tool releases 1.22.0 through 1.24.0
- Dotfiles releases 2.10.7 through 2.42.2 (relentless)
- Rewrote completelty our home weather system c.rolle.wtf with precipitation and better forecast
- Set up quick tool based on ff2mpv + mpv for instant adless YouTube playback
- Ungoogled-chromium optimization pass with NVDEC hardware decode
- Fixed home WiFi dropouts (5 GHz DFS, channel splitting, RSSI deauth) with Ubiquity router
- Tested alternative browsers: Thorium, Zen, Brave Origin Nightly, Orion
- Tried dozens of new alternative AI models
- Released lc 0.1.0, omnishuffle 1.3.1, lastfm-recommendations 2.1.0
- Released Luku for iOS 1.2.3
- Fixed some technical challenges long overdue
Finance / admin:
- Paid taxes
- Paid bills
- Categorized and flagged hundreds of transactions
- Daily dough reconciliations
- Company finance review
- Updated company finance sheets
Family:
- 18th anniversary with my wife (Jul 2) - pizza and movie at home
- Weekly café dates with my wife (Jul 5, 12, 19, 26)
- Sushi lunch with my wife (Jul 1)
- Coffee with a friend (Jul 10, sat down for 4 hours)
- Family lunch (Jul 31)
- Trip to mom's place for a few days with kids, strawberries, pancakes, summer days (Jul 13)
Other:
- Migrated off Google Photos to PixelUnion, cancelled Google One
- Wrote a blog post about the Google Photos migration
- Completed CRM migration off Pipedrive (yes, work stuff but a fun one)
- Completed GitBook to Outline tech doc migration (also fun work stuff)
Zero actual rest days that contained zero commits. Oops.
This is everything I have documented.
Tomorrow, I get to rest at the office 😂
##updated 2026-07-28T14:54:01.770000
1 posts
100 repos
https://github.com/adysec/cve-2026-31431
https://github.com/cs8425/copy-fail-go
https://github.com/samanzamani/copy-fail-checker
https://github.com/tgies/copy-fail-c
https://github.com/insomnisec/Detections-CVE-2026-31431
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/bigwario/copy-fail-CVE-2026-31431-C
https://github.com/cozystack/copy-fail-blocker
https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431
https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail
https://github.com/0xBlackash/CVE-2026-31431
https://github.com/xeloxa/copyfail-exploit
https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431
https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs
https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/st4rburn/public-passwd
https://github.com/ErdemOzgen/copy-fail-cve-2026-31431
https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit
https://github.com/MartinPham/copy-fail-CVE-2026-31431-php
https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell
https://github.com/4xura/CVE-2026-31431-Copy-Fail
https://github.com/ncmprbll/copy-fail-rs
https://github.com/JnamerZ/CopyFail-CVE-2026-31431
https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431
https://github.com/Huchangzhi/autorootlinux
https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection
https://github.com/yxdm02/CVE-2026-31431
https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation
https://github.com/malwarekid/CVE-2026-31431
https://github.com/sgkdev/ptrace_may_dream
https://github.com/XsanFlip/CVE-2026-31431-Patch
https://github.com/cyber-joker/copy-fail-python
https://github.com/diemoeve/copyfail-rs
https://github.com/wesmar/CVE-2026-31431
https://github.com/kinryulabs/rootpacket-cve-2026-31431
https://github.com/aestechno/cve-2026-31431-ansible
https://github.com/wuwu001/CVE-2026-31431-exploit
https://github.com/theori-io/copy-fail-CVE-2026-31431
https://github.com/guiimoraes/CVE-2026-31431
https://github.com/AdityaBhatt3010/CVE-2026-31431
https://github.com/mrunalp/block-copyfail
https://github.com/SeanRickerd/cve-2026-31431
https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE
https://github.com/abdullaabdullazade/CVE-2026-31431
https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431
https://github.com/rootsecdev/cve_2026_31431
https://github.com/lonelyor/CVE-2026-31431-exp
https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC
https://github.com/erlangparasu/mitigate_cve_2026_31431-sh
https://github.com/yuspring/cve-2026-31431-poc
https://github.com/Smarttfoxx/copyfail
https://github.com/jbnetwork-git/copy-fail-check
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/1neptune/CopyFail
https://github.com/pascal-gujer/CVE-2026-31431
https://github.com/JuanBindez/CVE-2026-31431
https://github.com/ZephrFish/CopyFail-CVE-2026-31431
https://github.com/H1d3r/copy-fail_LPE_Interactive
https://github.com/Dabbleam/CVE-2026-31431-mitigation
https://github.com/ben-slates/CVE-2026-31431-Exploit
https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized
https://github.com/Boos4721/copyfail-rs
https://github.com/Sl4cK0TH/CVE-2026-31431-PoC
https://github.com/sammwyy/copyfail-rs
https://github.com/desultory/CVE-2026-31431
https://github.com/MrAriaNet/cPanel-Fix
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC
https://github.com/TheMalwareGuardian/CVE-2026-31431
https://github.com/Alfredooe/CVE-2026-31431
https://github.com/b5null/CVE-2026-31431-C
https://github.com/kadir/copy-fail-CVE-2026-31431-IOC
https://github.com/professional-slacker/alg_check
https://github.com/badsectorlabs/copyfail-go
https://github.com/qi4L/CVE-2026-31431-Container-Escape
https://github.com/haydenjames/CVE-2026-31431-check
https://github.com/bootsareme/copyfail-deconstructed
https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431
https://github.com/Xerxes-2/CVE-2026-31431-rs
https://github.com/philfry/cve-2026-31431-ftrace
https://github.com/sgkdev/page_inject
https://github.com/pedromizz/copy-fail
https://github.com/luotian2/CVE-2026-31431
https://github.com/novysodope/copy-fail-CVE-2026-31431-C
https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431
https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit
https://github.com/Iamliuxiaozhen/copy_fail
https://github.com/Juguitos/copy-fail
https://github.com/sec17br/CVE-2026-31431-Copy-Fail
https://github.com/atgreen/block-copyfail
https://github.com/povzayd/CVE-2026-31431
https://github.com/AliHzSec/CVE-2026-31431
https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite
https://github.com/0xShe/CVE-2026-31431
https://github.com/wgnet/wg.copyfail.patch
https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4
https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit
#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI
The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431
https://certvde.com/en/advisories/vde-2026-072/
#CSAF https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2026/ppsa-2026-003.json
##updated 2026-07-28T12:31:27
1 posts
CVE-2026-16462 is a critical SQL injection in Weidmueller PROCON-WEB SCADA, rated CVSS 9.8. An unauthenticated attacker can run SQL commands. Patch now.
#PROCONWEB #Weidmueller #CVE202616462 #SQLInjection #SCADA #CyberSecurity
##updated 2026-07-28T12:31:20
1 posts
CVE-2026-11841 lets an unauthenticated attacker reach internal files on SICK InspectorP6xx devices, risking device compromise. CVSS 9.4. Update to 5.4.0.
#SICK #InspectorP6xx #CVE202611841 #OTSecurity #ICS #CyberSecurity
##updated 2026-07-28T08:17:14.187000
2 posts
Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-auth-stack-buffer-overflow-in-the-mercusys-mb115-4g
##Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-auth-stack-buffer-overflow-in-the-mercusys-mb115-4g
##updated 2026-07-27T20:32:11.620000
1 posts
1 repos
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-27T19:51:07.873000
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-27T18:31:56
1 posts
1 repos
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
📰 JetBrains Patches Critical Unauthenticated RCE Flaw in TeamCity
🚨 CRITICAL ALERT: JetBrains patches CVE-2026-63077, a 9.8 CVSS unauthenticated RCE in TeamCity On-Premises. All versions affected. Exploit allows full server takeover. Upgrade immediately to prevent supply chain attacks! #TeamCity #CI/CD #CyberSecurity
##updated 2026-07-24T16:57:10.373000
2 posts
3 repos
https://github.com/ywh-jfellus/CVE-2026-9198
CVE ID: CVE-2026-9198
Vendor: IBM
Product: Langflow
Date Added: 2026-08-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9198
CVE ID: CVE-2026-9198
Vendor: IBM
Product: Langflow
Date Added: 2026-08-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9198
updated 2026-07-23T15:01:24.377000
1 posts
7 repos
https://github.com/EQSTLab/CVE-2026-16723
https://github.com/fazilbaig1/CVE-2026-16723
https://github.com/dinosn/fastjson-jsontype-rce-lab
https://github.com/HORKimhab/CVE-2026-16723
https://github.com/why-success/fastjson-rce-lab
📢 Exploitation active de CVE-2026-16723 dans Fastjson : RCE sans authentification
SecurityWeek, publié le 28 juillet 2026. L'article rapporte l'exploitation active d'une vulnérabilité critique dans Fastjson, une bibliothèque Java de sérialisation/désérialisation JSON développée par Alibaba, largement utilisée dans les applications Spring Boot.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-04-exploitation-active-de-cve-2026-16723-dans-fastjson-rce-sans-authentification/
🌐 source : https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/
🟢 vérification factuelle haute
#Fastjson #RCE #Cyberveille
updated 2026-07-22T21:31:51
1 posts
5 repos
https://github.com/HORKimhab/CVE-2026-50522
https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept
https://github.com/ChPratik/CVE-2026-50522
(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Severity: CRITICAL Impact Summary: An unauthorized attacker could exploit a deserialization vulnerability in Microsoft SharePoint to execute arbitrary code over a network....
##updated 2026-07-21T15:30:51
1 posts
Yea, moving to snap , improve security.
Oh, look.
Just few days ago: CVE-2026-8933 - *another* security issue in snapd
H A H A !
##updated 2026-07-20T12:18:48.440000
2 posts
6 repos
https://github.com/AirSkye/CVE-2026-34486-poc
https://github.com/404-src/CVE-2026-34486
https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction
https://github.com/anonmrc/CVE-2026-34486-e-Tomcat-Tribes
CVE ID: CVE-2026-34486
Vendor: Apache
Product: Tomcat
Date Added: 2026-08-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34486
CVE ID: CVE-2026-34486
Vendor: Apache
Product: Tomcat
Date Added: 2026-08-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34486
updated 2026-07-16T05:16:18.293000
2 posts
6 repos
https://github.com/remmons-r7/rapid7-CVE-2026-15409
https://github.com/0xBlackash/CVE-2026-15409
https://github.com/HORKimhab/CVE-2026-15409
https://github.com/tc4dy/CVE-2026-15409-15410-Framework
https://github.com/Ch4120N/CVE-2026-15409
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
CVE-2026-15409 - Changed to Known Ransomware Status
SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilityVendor: SonicWallProduct: SMA1000 AppliancesSonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.Status changed from Unknown to Known for ransomware campaign usage.Flip https://nvd.nist.gov/vuln/detail/CVE-2026-15409
##A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.
#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533
##updated 2026-07-14T21:32:21
2 posts
3 repos
https://github.com/tc4dy/CVE-2026-15409-15410-Framework
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
CVE-2026-15410 - Changed to Known Ransomware Status
SonicWall SMA1000 Appliances Code Injection VulnerabilityVendor: SonicWallProduct: SMA1000 AppliancesSonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: https://nvd.nist.gov/vuln/detail/CVE-2026-15410
##A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.
#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533
##updated 2026-07-14T18:32:37
1 posts
12 repos
https://github.com/GlendonNotGlen/certighost-cve-2026-54121-slides
https://github.com/nafiez/Metasploit-CVE-2026-54121-Certighost
https://github.com/ChPratik/CVE-2026-54121
https://github.com/HORKimhab/CVE-2026-54121
https://github.com/AtlasVector/Certighost-CVE-2026-54121
https://github.com/0xBlackash/CVE-2026-54121
https://github.com/aniqfakhrul/CVE-2026-54121
https://github.com/sam00/POC-CVE-2026-54121-Certighost
https://github.com/mwnickerson/certighost-bof
https://github.com/marcgoam/CVE-2026-54121-CertiGhost
A Microsoft acaba de corrigir a falha Certighost, que permitia a um utilizador com acessos básicos manipular o sistema de cadastro e obter um certificado válido em nome de um Controlador de Domínio, assumindo a gestão absoluta de uma rede Windows. A falha, classificada como de gravidade alta, foi corrigida com a CVE-2026-54121. 🛡️
##updated 2026-07-14T18:32:22
2 posts
1 repos
Details and proof-of-concept exploit code for CVE-2026-50343 are now public. The Windows privilege escalation flaw hands standard users SYSTEM privileges.
##Details and proof-of-concept exploit code for CVE-2026-50343 are now public. The Windows privilege escalation flaw hands standard users SYSTEM privileges.
##updated 2026-07-14T15:33:05
1 posts
15 repos
https://github.com/ExploitEoom/CVE-2026-46300
https://github.com/nonameuserosint-hue/Fragnesia-go
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/BenedictEjepu/CVE-2026-46300-Fragnesia---TryHackMe-Lab-Project
https://github.com/azilRababe/CVE-2026-46300
https://github.com/HORKimhab/CVE-2026-46300
https://github.com/Sentebale/CVE-2026-46300
https://github.com/First-John/cve_2026_frag_family_fix
https://github.com/0xBlackash/CVE-2026-46300
https://github.com/MadExploits/CVE-2026-46300
https://github.com/Maxime288/Fragnesia-CVE-2026-46300
https://github.com/AzDevops143/FRAGNESIA-Charan-cve-2026-46300
https://github.com/1neptune/Fragnesia
https://github.com/BenedictEjepu/CVE-2026-46300-Fragnesia---TryHackMe-Lab-Walkthrough
#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI
The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431
https://certvde.com/en/advisories/vde-2026-072/
#CSAF https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2026/ppsa-2026-003.json
##updated 2026-07-14T15:31:59
1 posts
43 repos
https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284
https://github.com/xd20111/CVE-2026-43284
https://github.com/LucasPDiniz/CVE-2026-43284
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan
https://github.com/First-John/cve_2026_frag_family_fix
https://github.com/MadExploits/CVE-2026-46300
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/0xlane/pagecache-guard
https://github.com/haydenjames/dirty-frag-check
https://github.com/ChernStepanov/DirtyFrag-for-dummies
https://github.com/suominen/CVE-2026-43284
https://github.com/t1ckprivate/CVE-2026-43284-Dirty-Frag
https://github.com/liamromanis101/DirtyFrag-Detector
https://github.com/Aiyakami/rust_dirtyfrag
https://github.com/krisiasty/vcheck
https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284
https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284
https://github.com/1neptune/DirtyFrag
https://github.com/armircetaj/tetragon-dirtyfrag
https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag
https://github.com/XRSecCD/202605_dirty_frag
https://github.com/lukeslp/redtail-ioc
https://github.com/cumakurt/linuxpi
https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/nonameuserosint-hue/DirtyFrag-go
https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester
https://github.com/dixyes/dirtypatch
https://github.com/attaattaatta/CVE-2026-43500
https://github.com/linnemanlabs/dirtyfrag-arm64
https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4
https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC
https://github.com/RevyHub/CVE-2026-43284---DirtyFrag-Analysis-THM-
https://github.com/g0thamRabb1t/CVE-2026-43284-dirtyfrag-detection
https://github.com/metalx1993/dirtyfrag-patches
https://github.com/nabhan-mohy/Dirty-Frag-Research-CVE-2026-43284-
https://github.com/ryan2929/CVE-2026-43284-
https://github.com/0xBlackash/CVE-2026-43284
https://github.com/AK777177/Dirty-Frag-Analysis
https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC
#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI
The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431
https://certvde.com/en/advisories/vde-2026-072/
#CSAF https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2026/ppsa-2026-003.json
##updated 2026-07-01T14:04:37.143000
1 posts
1 repos
CVE-2026-49413 - FreeBSD LPE via Linuxulator AT_SECURE Logic Bug https://lobste.rs/s/j1sfc2 #freebsd #security
https://ii4gsp.github.io/cve-2026-49413/
updated 2026-06-30T03:36:54
1 posts
2 repos
⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser
🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…
##updated 2026-06-19T00:31:46
1 posts
🟠 CVE-2026-17346 - High (8.8)
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-19T00:31:46
1 posts
🔴 CVE-2026-17351 - Critical (9)
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17351/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-17T10:48:34.893000
3 posts
1 repos
📰 Russian Group Midnight Blizzard Exploits Outlook XSS Flaw (CVE-2026-42897)
Russian actor Midnight Blizzard (Storm-2945) exploits Outlook XSS flaw CVE-2026-42897 to access mailboxes. Also hijacks hotel Wi-Fi in 'CaptiveCrunch' campaign to steal M365 tokens with CornFlake & ChocoShell malware. #ThreatIntel #APT
##Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...
🔗️ [Cybersecurity360] https://link.is.it/ssYZlG
##Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...
🔗️ [Cybersecurity360] https://link.is.it/ssYZlG
##updated 2026-06-17T10:14:56.770000
1 posts
2 repos
⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser
🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…
##updated 2026-06-17T10:07:59.880000
1 posts
🚨 EUVD-2026-52795
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: Flowise
🏢 Vendor: FlowiseAI
📅 Updated: 2026-08-04
📝 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52795
##updated 2026-06-17T05:58:22.273000
1 posts
7 repos
https://github.com/oferchen/POC-CVE-2023-32233
https://github.com/Destawell/gemini-2.5-pro-nf-tables-red-teaming
https://github.com/void0red/CVE-2023-32233
https://github.com/Destawell/gemini-2.5-pro-nf-tables-red-teamin
https://github.com/PIDAN-HEIDASHUAI/CVE-2023-32233
Ok, the first one is absolutely it:
##Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.
updated 2026-03-18T18:31:10
1 posts
📢 TA488 exploite une zero-day Zimbra (CVE-2025-66376) pour espionner des gouvernements via half-click
📝 ## 🔍 Contexte
Publié le 23 juillet 2026 par l'équipe Threat Research...
📖 cyberveille : https://cyberveille.ch/posts/2026-08-02-ta488-exploite-une-zero-day-zimbra-cve-2025-66376-pour-espionner-des-gouvernements-via-half-click/
🌐 source : https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits
#CVE_2025_66376 #IOC #Cyberveille
updated 2026-01-29T03:42:38
1 posts
🟠 CVE-2026-62391 - High (8.1)
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.
This issue ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2025-04-11T04:12:49
2 posts
1 repos
⚠️ CRITICAL: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
CVE-2013-4786 in IPMI 2.0 allows unauthenticated attackers to harvest password hashes from Baseboard Management Controllers via UDP 623, then crack them offline. Over 24,000 internet-exposed BMCs are vulnerable, and many run weak or predictable default credentials. Compromised BMCs give attackers d…
🤖 AI generated summary
##LAVA found 36,872 exposed BMCs leaking IPMI password hashes via CVE-2013-4786. Some are already exploited in the wild. Here is how to lock them down.
#BMC #IPMI #CVE20134786 #DataCenter #Supermicro #CyberSecurity
##CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation
Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT
Description:
We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API...
https://aws.amazon.com/security/security-bulletins/rss/2026-073-aws/
##CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation
Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT
Description:
We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API...
https://aws.amazon.com/security/security-bulletins/rss/2026-073-aws/
##🔴 CVE-2026-69098 - Critical (9.8)
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-69098 - Critical (9.8)
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##📰 Thermo Fisher DNA Software Flaw Allows Undetectable Evidence Tampering
A critical flaw (CVE-2026-17583) in Thermo Fisher's forensic DNA software allows for nearly undetectable evidence tampering. The vulnerability impacts the integrity of the criminal justice system. Patches are available. #CyberSecurity #Forensics #DNA
##A critical Veeam Service Provider Console flaw lets attackers steal agent credentials, while a second enables remote code execution. Update to 9.3 now.
#Veeam #VSPC #ServiceProviderConsole #CVE202658073 #RCE #RemoteCodeExecution #Vulnerability #MSP #CyberSecurity #InfoSec
https://securityonline.info/veeam-vspc-cve-2026-58073/?utm_source=mastodon&utm_medium=jetpack_social
##A critical Veeam Service Provider Console flaw lets attackers steal agent credentials, while a second enables remote code execution. Update to 9.3 now.
#Veeam #VSPC #ServiceProviderConsole #CVE202658073 #RCE #RemoteCodeExecution #Vulnerability #MSP #CyberSecurity #InfoSec
https://securityonline.info/veeam-vspc-cve-2026-58073/?utm_source=mastodon&utm_medium=jetpack_social
##A critical Veeam ONE vulnerability, CVE-2026-64633, allows remote unauthenticated code execution at CVSS 10.0. Update to build 13.1.0.7034 now.
#Veeam #VeeamONE #CVE202664633 #RCE #RemoteCodeExecution #Vulnerability #CVSS10 #PatchNow #CyberSecurity #InfoSec
##A critical Veeam ONE vulnerability, CVE-2026-64633, allows remote unauthenticated code execution at CVSS 10.0. Update to build 13.1.0.7034 now.
#Veeam #VeeamONE #CVE202664633 #RCE #RemoteCodeExecution #Vulnerability #CVSS10 #PatchNow #CyberSecurity #InfoSec
##RufRoot CVE-2026-59726: Unauthenticated RCE in Ruflo MCP Bridge Exposes AI Agent Keys
##RufRoot CVE-2026-59726: Unauthenticated RCE in Ruflo MCP Bridge Exposes AI Agent Keys
##🏆 New Achievement! RufRoot Has Entered The Arena!
PHASE ONE BEGINS. The challenger: CVE-2026-59726, alias RufRoot, a CVSS 10.0 critical flaw in the open-source AI agent platform Ruflo. Its special move — exploiting an exposed Model Context Protocol bridge to hand unauthenticated attackers full control of enterprise AI environments. No credentials required. No mercy shown. Noma Security surfaced this beast hiding in every Ruflo version before 3.16.3.
This is not a warm-up encounter. (1/2)
##Critical Gitea Flaw Opens the Door to Silent File Theft and Potential Server Takeover + Video
Introduction: When a Public Repository Becomes a Gateway to the Server Open-source development platforms are built to make collaboration easier, but the same features that improve productivity can become dangerous when hidden trust boundaries fail. A newly disclosed critical vulnerability in Gitea, tracked as CVE-2026-59774, demonstrates how an apparently limited…
##Gitea Vulnerability CVE-2026-59774 Enables Unauthenticated Remote Code Execution
##🟠 CVE-2026-56671 - High (7.5)
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment che...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56671/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-56673 - High (7.5)
ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56673/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-56672 - High (8.2)
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and acc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56672/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-49413 - FreeBSD LPE via Linuxulator AT_SECURE Logic Bug https://lobste.rs/s/j1sfc2 #freebsd #security
https://ii4gsp.github.io/cve-2026-49413/