## Updated at UTC 2026-08-13T15:44:39.802164

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-71473 8.5 0.26% 2 0 2026-08-13T14:17:12.350000 A flaw was found in the `search-v2-operator` component. A user with specific adm
CVE-2026-66898 9.9 0.34% 2 0 2026-08-13T14:17:11.320000 A path traversal vulnerability in LXD allows an attacker to manipulate file syst
CVE-2026-59310 9.8 1.14% 13 0 2026-08-13T14:17:01.890000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-19003 7.8 0.13% 2 0 2026-08-13T14:16:55.460000 A data source definition containing an over-length file path setting may cause t
CVE-2026-17083 9.8 0.46% 2 0 2026-08-13T14:16:54.963000 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary
CVE-2026-61358 7.8 3.31% 1 0 2026-08-13T13:59:48.317000 Improper link resolution before file access ('link following') in Windows Access
CVE-2026-6464 8.1 0.00% 2 1 2026-08-13T13:19:16.347000 Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrato
CVE-2026-49827 9.8 0.00% 4 0 2026-08-13T13:19:10.050000 WebErpMesv2 is a Resource Management and Manufacturing execution system Web for
CVE-2026-49478 8.7 0.00% 2 0 2026-08-13T13:19:09.790000 Fulcio is a certificate authority for issuing code signing certificates for an O
CVE-2026-19001 9.8 0.38% 2 0 2026-08-13T13:17:48.253000 The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-siz
CVE-2026-12263 8.8 0.00% 2 0 2026-08-13T11:17:38.193000 Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 vers
CVE-2026-59507 9.3 0.32% 2 0 2026-08-13T10:17:15.963000 CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Informatio
CVE-2026-59506 9.3 0.40% 2 0 2026-08-13T10:17:15.840000 CWE-306: Missing Authentication for Critical Function
CVE-2026-59501 8.2 0.32% 2 0 2026-08-13T10:17:15.140000 CWE-284: Improper Access Control
CVE-2026-59500 10.0 0.38% 2 0 2026-08-13T10:17:15.017000 CWE-287: Improper Authentication
CVE-2026-13610 None 0.15% 2 0 2026-08-13T06:33:55 The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignab
CVE-2026-69106 8.8 0.35% 2 0 2026-08-13T05:17:25.610000 A low-privileged user may poison cached artifact metadata under specific conditi
CVE-2026-26035 9.8 0.51% 2 0 2026-08-13T05:17:23.773000 An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet For
CVE-2026-19560 8.8 0.34% 2 0 2026-08-13T05:17:23.613000 Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remot
CVE-2026-19556 8.8 0.34% 2 0 2026-08-13T05:17:23.020000 Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote a
CVE-2026-71193 9.6 0.53% 4 0 2026-08-13T00:31:36 In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_sup
CVE-2026-10534 8.4 0.18% 2 0 2026-08-13T00:31:33 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer
CVE-2026-71469 7.5 0.36% 2 0 2026-08-13T00:31:33 A flaw was found in search-v2-api. An unauthenticated attacker can exploit this
CVE-2026-73519 9.8 0.62% 4 0 2026-08-13T00:31:28 WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret comp
CVE-2026-71471 9.0 1.45% 4 0 2026-08-13T00:31:26 A flaw was found in acm-search-v2-rhel9. An attacker with administrative privile
CVE-2026-73303 8.2 0.23% 2 0 2026-08-12T23:17:24.403000 Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/emai
CVE-2026-55676 8.8 0.30% 1 0 2026-08-12T23:17:21.683000 Malcolm is a network traffic analysis tool suite. The file-upload component (Fil
CVE-2026-19002 8.1 0.29% 2 0 2026-08-12T21:31:51 A missing bounds check when parsing stored procedure parameter metadata in the M
CVE-2026-73326 7.6 0.27% 2 0 2026-08-12T21:31:50 CamaleonCMS contains a missing authorization vulnerability that allows any authe
CVE-2026-73329 8.7 0.23% 2 0 2026-08-12T21:31:50 CamaleonCMS contains a stored cross-site scripting vulnerability that allows aut
CVE-2026-73433 6.6 0.13% 2 0 2026-08-12T21:31:44 A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM
CVE-2026-73332 8.7 0.23% 2 0 2026-08-12T21:31:43 CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_con
CVE-2026-73498 7.7 0.33% 2 0 2026-08-12T21:17:31 ### Summary `confluence_upload_attachment` passes `file_path` directly to `open(
CVE-2026-73493 7.5 0.35% 2 0 2026-08-12T21:08:45 ## Summary `http4s-blaze-server` aggregates the fragments of an incoming WebSoc
CVE-2026-18961 8.1 0.45% 2 0 2026-08-12T21:00:52.257000 The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by Ventr
CVE-2026-66659 9.3 0.29% 4 0 2026-08-12T20:59:00.027000 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-17248 7.1 0.33% 1 0 2026-08-12T20:53:43.330000 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to caus
CVE-2026-19311 8.1 0.41% 2 0 2026-08-12T20:50:27.407000 Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting p
CVE-2026-73418 7.5 0.46% 2 0 2026-08-12T20:21:20 ## Summary The exported `getToken()` helper (`next-auth/jwt` and `@auth/core/jw
CVE-2026-73406 7.5 0.37% 2 0 2026-08-12T20:17:55.617000 Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/
CVE-2026-73300 9.6 0.38% 2 0 2026-08-12T20:17:54.023000 Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integra
CVE-2026-72798 8.6 0.26% 1 0 2026-08-12T20:17:51.543000 SiYuan versions before v3.7.4 fail to properly filter related-database content i
CVE-2026-58115 10.0 0.65% 2 0 2026-08-12T20:17:45.377000 A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1
CVE-2026-50060 7.8 0.11% 1 0 2026-08-12T20:17:44.970000 A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0
CVE-2026-16756 7.5 0.42% 2 0 2026-08-12T20:17:38.353000 Missing connection and header-read timeouts and the absence of a concurrent-conn
CVE-2026-73327 7.6 0.85% 2 0 2026-08-12T18:31:29 Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate ext
CVE-2026-73325 7.8 0.26% 2 0 2026-08-12T18:31:28 Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserializati
CVE-2026-65941 8.8 0.44% 2 0 2026-08-12T18:31:21 In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote att
CVE-2026-69105 8.1 0.13% 2 0 2026-08-12T18:31:19 An unauthenticated attacker may cause untrusted package content to be cached und
CVE-2026-18634 8.4 0.22% 1 0 2026-08-12T18:31:15 An insecure handling of serialized objects vulnerability was found in the one of
CVE-2026-50656 7.8 10.75% 12 3 2026-08-12T18:31:00 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-73294 9.9 0.45% 2 0 2026-08-12T17:17:32.527000 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and
CVE-2026-73122 7.7 0.21% 2 0 2026-08-12T17:17:31.853000 A flaw was found in the multicloud-operators-channel component of Red Hat Advanc
CVE-2026-70468 8.1 0.59% 2 0 2026-08-12T15:30:49 A authentication bypass using an alternate path or channel vulnerability in Fort
CVE-2026-72898 10.0 10.40% 9 1 template 2026-08-12T15:18:30.347000 Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via t
CVE-2026-66147 9.4 1.05% 1 0 2026-08-12T15:18:18.370000 An unauthenticated command injection vulnerability was identified in the GMS Dis
CVE-2026-68820 7.0 0.33% 37 1 2026-08-12T14:57:30.717000 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-73232 7.5 0.45% 1 0 2026-08-12T14:18:38.810000 ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious
CVE-2026-67568 9.1 0.24% 2 0 2026-08-12T14:18:33.557000 The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access
CVE-2026-70398 9.6 0.22% 4 0 2026-08-12T13:17:24.637000 A flaw was found in multicloud-integrations, a component of Red Hat Advanced Clu
CVE-2026-57858 8.9 0.41% 4 1 2026-08-12T13:17:22.943000 Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripti
CVE-2026-48763 8.2 0.31% 1 0 2026-08-12T13:17:22.633000 TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated
CVE-2026-19594 8.1 0.40% 2 0 2026-08-12T13:17:22.180000 Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versi
CVE-2026-19426 8.2 0.30% 2 0 2026-08-12T13:17:21.930000 POS System developed by FitSoft has a Missing Authentication vulnerability. Unau
CVE-2026-67282 None 0.57% 2 0 2026-08-12T09:31:30 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabri
CVE-2025-41770 7.5 0.39% 4 0 2026-08-12T09:31:30 An unauthenticated denial-of-service vulnerability in the device's PLCnext Engin
CVE-2025-41771 4.3 0.16% 2 0 2026-08-12T09:31:30 An authenticated attacker with low privileges can access an endpoint in the cont
CVE-2025-41769 9.8 0.59% 6 0 2026-08-12T08:17:11.590000 The device's PROFINET service is affected by a buffer overflow vulnerability tha
CVE-2026-64954 8.2 0.23% 2 0 2026-08-12T06:30:49 Velociraptor allows scheduling new collections via VQL queries in notebooks. For
CVE-2026-66807 7.8 0.36% 1 0 2026-08-12T05:19:35.273000 Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker
CVE-2026-62747 7.8 0.32% 1 0 2026-08-12T05:18:29.177000 Heap-based buffer overflow in Windows Device Association Service allows an autho
CVE-2026-58231 10.0 0.73% 5 0 2026-08-12T05:17:56.963000 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent
CVE-2026-53413 8.3 0.41% 1 1 2026-08-12T05:17:55.123000 Missing bounds check in the annotator function of Zoom Clients allows buffer ove
CVE-2026-18129 8.1 0.87% 2 0 2026-08-12T05:17:42.950000 Cleartext transmission of sensitive information in the Core of Ivanti Endpoint M
CVE-2026-6484 8.2 0.14% 1 0 2026-08-12T03:31:23 In an UEFI, Lack of verified boot to certain FV may cause arbitrary code executi
CVE-2026-72526 9.9 0.30% 4 0 2026-08-12T03:31:18 A flaw was found in the multicloud-integrations component. The Application propa
CVE-2026-66878 7.7 0.21% 2 0 2026-08-12T02:16:37.937000 A flaw was found in multicloud-operators-subscription. A privileged user, specif
CVE-2026-68067 9.8 0.28% 2 0 2026-08-12T00:31:23 The login endpoint on the Mira cloud API accepts any format-valid string in the
CVE-2026-66875 8.8 0.24% 1 0 2026-08-12T00:31:23 In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote u
CVE-2026-73246 7.5 0.35% 1 0 2026-08-11T22:19:05.287000 Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc
CVE-2026-19579 5.4 0.24% 2 0 2026-08-11T22:17:21.750000 Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object r
CVE-2026-73282 4.8 0.16% 2 0 2026-08-11T21:33:18 In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a
CVE-2026-18690 8.1 0.26% 1 0 2026-08-11T21:33:12 An issue in MongoDB Server could allow an authenticated user with a limited data
CVE-2026-20349 8.6 0.87% 18 0 2026-08-11T21:32:37 A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall A
CVE-2026-73283 2.5 0.08% 2 0 2026-08-11T21:17:53.413000 In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was su
CVE-2026-73281 3.5 0.16% 2 0 2026-08-11T21:17:52.563000 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were
CVE-2026-18687 7.1 0.17% 1 0 2026-08-11T21:17:31.273000 MongoDB Server's handling of a Queryable Encryption maintenance operation did no
CVE-2026-73226 8.8 0.39% 1 0 2026-08-11T20:18:48.007000 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ft
CVE-2026-72971 5.5 0.36% 1 0 2026-08-11T20:18:46.067000 Improper link resolution before file access ('link following') in Windows Contai
CVE-2021-44228 10.0 100.00% 1 100 template 2026-08-11T19:33:44.513000 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12
CVE-2026-73069 9.1 0.36% 1 0 2026-08-11T19:18:49.750000 Twenty is an open-source CRM (customer relationship management) platform. Prior
CVE-2026-20338 7.5 0.33% 2 0 2026-08-11T18:54:19.877000 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-62901 7.5 1.08% 1 0 2026-08-11T18:53:58 ## Executive summary Microsoft is releasing this security advisory to provide i
CVE-2026-71398 10.0 0.64% 2 0 2026-08-11T18:32:06 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-71362 9.1 0.48% 9 0 2026-08-11T18:32:00 Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
CVE-2026-48381 9.0 0.48% 2 0 2026-08-11T18:32:00 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-27302 10.0 0.57% 2 0 2026-08-11T18:32:00 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-71384 9.6 0.24% 2 0 2026-08-11T18:31:59 is affected by an Incorrect Authorization vulnerability that could result in a S
CVE-2026-66804 7.8 3.03% 3 2 2026-08-11T18:31:49 Improper access control in Windows Cross Device Service allows an authorized att
CVE-2026-62832 7.8 2.39% 2 0 2026-08-11T18:31:33 Improper link resolution before file access ('link following') in Windows User P
CVE-2026-61353 7.8 0.32% 1 0 2026-08-11T18:31:13 Heap-based buffer overflow in Windows Telephony Service allows an authorized att
CVE-2026-58641 7.8 0.40% 1 0 2026-08-11T18:31:08 Integer overflow or wraparound in .NET allows an unauthorized attacker to elevat
CVE-2026-59124 9.8 1.72% 2 0 2026-08-11T18:31:01 Deserialization of untrusted data in Microsoft High Performance Computing (HPC)
CVE-2026-48362 10.0 2.07% 2 0 2026-08-11T18:30:56 ColdFusion is affected by an Improper Neutralization of Special Elements used in
CVE-2026-53414 6.5 0.28% 1 0 2026-08-11T18:30:54 Missing bounds check in the annotator function of Zoom Clients allows buffer ove
CVE-2026-53415 8.3 0.39% 1 0 2026-08-11T18:30:54 Use after Free in the annotator function of Zoom Clients may allow a meeting par
CVE-2026-67180 8.4 0.17% 1 0 2026-08-11T18:30:53 Google Turbinia allows arbitrary command execution via worker tasks. An attacker
CVE-2026-56721 8.8 0.36% 2 0 2026-08-11T18:17:37.757000 CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerabil
CVE-2026-73079 8.5 0.31% 1 0 2026-08-11T17:19:15.747000 Sub2API is an AI API gateway platform designed to distribute and manage API quot
CVE-2026-67179 7.8 0.14% 1 0 2026-08-11T16:17:34.113000 Genkit does not properly validate host request headers. Any host on the develope
CVE-2026-73080 9.3 0.38% 1 0 2026-08-11T15:58:24 ### Impact `VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote e
CVE-2026-72922 8.2 0.27% 1 0 2026-08-11T15:17:38.350000 AutoGPT is a workflow automation platform for creating, deploying, and managing
CVE-2026-72921 8.1 0.24% 1 0 2026-08-11T15:17:38.217000 SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_
CVE-2026-72914 7.5 0.45% 2 0 2026-08-11T14:17:15.200000 Mastodon is a free, open-source social network server based on ActivityPub. Prio
CVE-2026-46670 9.8 1.65% 1 0 template 2026-08-11T14:17:13.863000 YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthentic
CVE-2026-19418 None 0.21% 1 0 2026-08-11T09:32:42 The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069)
CVE-2026-8917 None 0.11% 1 0 2026-08-11T03:31:59 Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and
CVE-2026-34265 9.8 0.44% 2 0 2026-08-11T03:31:57 SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl
CVE-2026-44758 9.1 0.51% 2 0 2026-08-11T03:31:55 SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig
CVE-2026-66058 0 0.22% 1 0 2026-08-10T13:19:52.897000 Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0,
CVE-2026-64564 9.8 0.48% 1 4 2026-08-09T04:17:43.283000 In the Linux kernel, the following vulnerability has been resolved: sctp: don't
CVE-2026-66059 0 0.27% 1 0 2026-08-08T04:17:50.503000 Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0,
CVE-2026-66000 0 0.26% 1 0 2026-08-07T19:18:51.847000 Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0,
CVE-2026-20337 7.5 0.36% 2 0 2026-08-07T18:31:52 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-71319 9.6 0.32% 2 0 2026-08-07T05:17:03.660000 Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nux
CVE-2026-63456 9.8 0.43% 2 0 2026-08-06T15:40:50.227000 Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orch
CVE-2026-63455 9.8 0.43% 2 0 2026-08-06T15:40:50.227000 Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orch
CVE-2026-67261 9.8 1.60% 2 0 2026-08-06T15:32:56 Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.
CVE-2026-34966 7.6 0.31% 2 0 2026-08-05T21:31:47 Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that
CVE-2026-20272 9.8 0.34% 1 0 2026-08-05T18:31:45 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-61515 9.8 1.58% 2 0 2026-08-05T14:17:08.690000 Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated c
CVE-2026-71209 7.5 1.76% 1 0 template 2026-08-05T09:31:27 audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches
CVE-2026-18577 8.1 4.10% 2 3 2026-08-04T15:33:20 An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco
CVE-2026-59309 9.8 0.74% 3 0 2026-07-30T16:17:15.073000 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-47876 9.3 0.28% 1 0 2026-07-30T15:31:54 VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual
CVE-2026-64560 7.8 0.12% 1 1 2026-07-30T12:19:03.630000 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t
CVE-2025-4318 0 0.93% 2 0 2026-07-29T16:17:47.997000 The AWS Amplify Studio UI component property expressions in the aws-amplify/ampl
CVE-2026-64747 7.8 0.14% 2 1 2026-07-29T05:17:03.413000 A buffer overflow was addressed with improved size validation. This issue is fix
CVE-2026-43723 7.8 0.15% 2 0 2026-07-28T19:31:46.327000 A path handling issue was addressed with improved validation. This issue is fixe
CVE-2026-31431 7.8 99.91% 1 100 template 2026-07-28T14:54:01.770000 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-53360 8.8 0.18% 2 1 2026-07-22T19:07:37.640000 In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: R
CVE-2026-53361 7.1 0.13% 3 1 2026-07-18T09:32:17 In the Linux kernel, the following vulnerability has been resolved: af_unix: Se
CVE-2026-55040 9.1 2.96% 19 2 2026-07-14T18:32:38 Weak authentication in Microsoft Office SharePoint allows an unauthorized attack
CVE-2026-12879 0 0.19% 1 0 2026-07-09T16:39:17.737000 An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apige
CVE-2026-45659 8.8 9.86% 1 2 2026-07-01T21:35:53 Deserialization of untrusted data in Microsoft Office SharePoint allows an autho
CVE-2026-49473 8.8 0.28% 2 0 2026-06-30T18:09:14 ### Summary @cedar-policy/authorization-for-expressjs is an open-source Express.
CVE-2025-7771 0 6.83% 1 12 2026-06-17T10:05:37.643000 ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow a
CVE-2026-47717 7.5 1.20% 2 0 template 2026-05-27T22:51:19 ### Summary The GET /api/project endpoint exposes sensitive project configurati
CVE-2026-22185 None 0.13% 2 0 2026-01-08T18:31:46 OpenLDAP Lightning Memory-Mapped Database (LMDB) mdb_load contains a heap buffer
CVE-2025-24472 8.1 3.87% 1 1 2025-10-22T00:34:17 An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2
CVE-2024-55591 9.8 98.26% 3 9 template 2025-10-22T00:34:16 An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2
CVE-2025-24994 7.3 1.18% 2 0 2025-03-11T18:32:28 Improper access control in Windows Cross Device Service allows an authorized att
CVE-2025-24076 7.3 3.15% 2 1 2025-03-11T18:32:27 Improper access control in Windows Cross Device Service allows an authorized att
CVE-2026-65640 0 0.00% 7 1 N/A
CVE-2026-48273 0 0.00% 2 0 N/A
CVE-2026-49481 0 0.88% 4 0 N/A
CVE-2026-49819 0 0.61% 4 0 N/A
CVE-2026-73501 0 0.34% 2 0 N/A
CVE-2026-19654 0 0.40% 2 0 N/A
CVE-2026-73299 0 1.21% 2 0 N/A
CVE-2026-18952 0 0.32% 2 0 N/A
CVE-2026-73293 0 0.40% 2 0 N/A
CVE-2026-73292 0 0.19% 2 0 N/A
CVE-2026-73225 0 0.31% 2 0 N/A
CVE-2026-44772 0 0.00% 2 0 N/A
CVE-2026-72916 0 0.36% 2 0 N/A
CVE-2026-72915 0 0.28% 2 0 N/A
CVE-2026-12234 0 0.08% 2 0 N/A
CVE-2026-48765 0 0.26% 3 0 N/A
CVE-2026-73247 0 0.30% 1 0 N/A
CVE-2026-73249 0 0.25% 1 0 N/A
CVE-2026-73234 0 0.16% 1 0 N/A
CVE-2026-73231 0 0.15% 1 0 N/A
CVE-2026-73224 0 0.34% 1 0 N/A
CVE-2026-59765 0 0.00% 2 0 N/A
CVE-2026-72920 0 0.41% 1 0 N/A
CVE-2026-17106 0 0.00% 1 3 N/A

CVE-2026-71473
(8.5 HIGH)

EPSS: 0.26%

updated 2026-08-13T14:17:12.350000

2 posts

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critical settings, leading to the replacement of container images. This ultimately results in container image injection on the managed cluster, potentially com

thehackerwire@mastodon.social at 2026-08-12T23:00:20.000Z ##

🟠 CVE-2026-71473 - High (8.5)

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T23:00:20.000Z ##

🟠 CVE-2026-71473 - High (8.5)

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66898
(9.9 CRITICAL)

EPSS: 0.34%

updated 2026-08-13T14:17:11.320000

2 posts

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing pa

thehackerwire@mastodon.social at 2026-08-12T22:01:06.000Z ##

🔴 CVE-2026-66898 - Critical (9.9)

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T22:01:06.000Z ##

🔴 CVE-2026-66898 - Critical (9.9)

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-08-13T14:17:01.890000

13 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Analyst207@mastodon.social at 2026-08-13T14:02:13.000Z ##

VMware vCenter Flaw Exploited Days After Disclosure

Within days of Broadcom's advisory, a critical VMware vCenter flaw, CVE-2026-59310, was exploited, putting 361 victim IP addresses across 47 countries at risk. This severe vulnerability allowed attackers to turn a logging service into a gateway to infiltrate operating systems worldwide.

osintsights.com/vmware-vcenter

#Cve202659310 #Vmware #Vcenter #DirectoryTraversal #SupplyChain

##

Hackread@mstdn.social at 2026-08-13T11:44:19.000Z ##

📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310.

Listen/Read: hackread.com/apt-exploits-crit

#CyberSecurity #VMware #vCenter #APT #Vulnerability

##

beyondmachines1 at 2026-08-13T10:01:21.207Z ##

Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access

German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).

**If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.**

beyondmachines.net/event_detai

##

ottoto2017@prattohome.com at 2026-08-13T06:50:40.000Z ##

「攻撃者がVMware vCenterの脆弱性を悪用し、永続的なリモートアクセスを取得する 」: #TheHackerNews

「QUIRSOの 新たな調査結果 によると、攻撃者は、最近パッチが適用されたBroadcom VMware vCenterの重大なセキュリティ脆弱性を積極的に悪用し始めている。

問題となっている脆弱性は CVE-2026-59310 (CVSSスコア:9.8)で、VMware vCenterサーバーのディレクトリトラバーサル脆弱性であり、ネットワークアクセス権を持つ悪意のある攻撃者がこれを悪用して任意のコードを実行できる可能性がある。この脆弱性に対するパッチは、ブロードコム社が先月末にリリースした。

ドイツのサイバーセキュリティ企業は、インシデント対応活動中にこの活動を発見したと発表した。 」

thehackernews.com/2026/08/atta

#prattohome

##

cyberworldops at 2026-08-13T00:10:01.009Z ##

VMware vCenter Under Attack: CVE-2026-59310 Enables Persistent Access

cyberworldops.eu/en/vmware-vce

##

netsecio@mastodon.social at 2026-08-12T15:06:48.000Z ##

📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi

Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday

🔗 cyber.netsecops.io/articles/vm

##

undercodenews@mastodon.social at 2026-08-12T12:34:48.000Z ##

VMware vCenter Under Attack: Critical CVE-2026-59310 Exploited in a Rapid Global Intrusion Campaign + Video

A New Warning for Virtualization Administrators Virtualization infrastructure has quietly become one of the most valuable targets in modern cyberattacks. A compromised workstation can expose one user or one endpoint, but a compromised virtualization-management server can potentially open a path toward dozens, hundreds, or even thousands of workloads. That is why…

undercodenews.com/vmware-vcent

##

jbhall56 at 2026-08-12T12:03:53.426Z ##

The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. thehackernews.com/2026/08/atta

##

Hackread@mstdn.social at 2026-08-13T11:44:19.000Z ##

📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310.

Listen/Read: hackread.com/apt-exploits-crit

#CyberSecurity #VMware #vCenter #APT #Vulnerability

##

beyondmachines1@infosec.exchange at 2026-08-13T10:01:21.000Z ##

Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access

German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).

**If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

ottoto2017@prattohome.com at 2026-08-13T06:50:40.000Z ##

「攻撃者がVMware vCenterの脆弱性を悪用し、永続的なリモートアクセスを取得する 」: #TheHackerNews

「QUIRSOの 新たな調査結果 によると、攻撃者は、最近パッチが適用されたBroadcom VMware vCenterの重大なセキュリティ脆弱性を積極的に悪用し始めている。

問題となっている脆弱性は CVE-2026-59310 (CVSSスコア:9.8)で、VMware vCenterサーバーのディレクトリトラバーサル脆弱性であり、ネットワークアクセス権を持つ悪意のある攻撃者がこれを悪用して任意のコードを実行できる可能性がある。この脆弱性に対するパッチは、ブロードコム社が先月末にリリースした。

ドイツのサイバーセキュリティ企業は、インシデント対応活動中にこの活動を発見したと発表した。 」

thehackernews.com/2026/08/atta

#prattohome

##

cyberworldops@infosec.exchange at 2026-08-13T00:10:01.000Z ##

VMware vCenter Under Attack: CVE-2026-59310 Enables Persistent Access

cyberworldops.eu/en/vmware-vce

##

jbhall56@infosec.exchange at 2026-08-12T12:03:53.000Z ##

The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. thehackernews.com/2026/08/atta

##

CVE-2026-19003
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-13T14:16:55.460000

2 posts

A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder selection handling, and is reached only when a user opens the setup dialog for such a data source and initiates a file or fol

thehackerwire@mastodon.social at 2026-08-12T23:01:17.000Z ##

🟠 CVE-2026-19003 - High (7.8)

A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T23:01:17.000Z ##

🟠 CVE-2026-19003 - High (7.8)

A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17083
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-08-13T14:16:54.963000

2 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

nyanbinary at 2026-08-13T14:26:21.890Z ##

also: those are some god damn useless CVEs, istg... db.gcve.eu/vuln/cve-2026-17083

##

nyanbinary@infosec.exchange at 2026-08-13T14:26:21.000Z ##

also: those are some god damn useless CVEs, istg... db.gcve.eu/vuln/cve-2026-17083

##

CVE-2026-61358
(7.8 HIGH)

EPSS: 3.31%

updated 2026-08-13T13:59:48.317000

1 posts

Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

hugovalters@mastodon.social at 2026-08-12T18:13:05.000Z ##

CVE-2026-61358 - Privilege escalation in Windows ATBroker.exe via link following. CVSS 7.8. Patch immediately. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-613

##

CVE-2026-6464
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-13T13:19:16.347000

2 posts

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has

1 repos

https://github.com/oscerd/CVE-2026-64640

thehackerwire@mastodon.social at 2026-08-13T14:00:46.000Z ##

🟠 CVE-2026-6464 - High (8.1)

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T14:00:46.000Z ##

🟠 CVE-2026-6464 - High (8.1)

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49827
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-13T13:19:10.050000

4 posts

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chai

thehackerwire@mastodon.social at 2026-08-13T14:01:03.000Z ##

🔴 CVE-2026-49827 - Critical (9.8)

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-13T13:30:27.621Z ##

CVE-2026-49827: SMEWebify WebErpMesv2 ≤1.19 has a CRITICAL vuln — improper input validation lets any self-registered user achieve unauth'd RCE via PHP file upload (scan_file param). Patch with commit 5c54862fa044b363fd2be03d586750e81afd6818 radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-13T14:01:03.000Z ##

🔴 CVE-2026-49827 - Critical (9.8)

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-13T13:30:27.000Z ##

CVE-2026-49827: SMEWebify WebErpMesv2 ≤1.19 has a CRITICAL vuln — improper input validation lets any self-registered user achieve unauth'd RCE via PHP file upload (scan_file param). Patch with commit 5c54862fa044b363fd2be03d586750e81afd6818 radar.offseq.com/threat/cve-20 #OffSeq #CVE202649827 #infosec

##

CVE-2026-49478
(8.7 HIGH)

EPSS: 0.00%

updated 2026-08-13T13:19:09.790000

2 posts

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind SSRF, substitute and cache malicious JWKS keys, or disclose ServiceAccount tokens to external hosts.

thehackerwire@mastodon.social at 2026-08-13T14:01:13.000Z ##

🟠 CVE-2026-49478 - High (8.7)

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T14:01:13.000Z ##

🟠 CVE-2026-49478 - High (8.7)

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19001
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-08-13T13:17:48.253000

2 posts

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-12T22:02:10.000Z ##

🔴 CVE-2026-19001 - Critical (9.8)

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T22:02:10.000Z ##

🔴 CVE-2026-19001 - Critical (9.8)

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12263
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-13T11:17:38.193000

2 posts

Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.

thehackerwire@mastodon.social at 2026-08-13T12:00:54.000Z ##

🟠 CVE-2026-12263 - High (8.8)

Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T12:00:54.000Z ##

🟠 CVE-2026-12263 - High (8.8)

Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59507
(9.3 CRITICAL)

EPSS: 0.32%

updated 2026-08-13T10:17:15.963000

2 posts

CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control

offseq at 2026-08-13T10:30:23.699Z ##

CVE-2026-59507 (CRITICAL, CVSS 9.3) impacts Priority ERP Portal Generator addon: hard-coded creds, info exposure, improper access control. No patch yet — restrict access & monitor systems. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-13T10:30:23.000Z ##

CVE-2026-59507 (CRITICAL, CVSS 9.3) impacts Priority ERP Portal Generator addon: hard-coded creds, info exposure, improper access control. No patch yet — restrict access & monitor systems. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #ERP

##

CVE-2026-59506
(9.3 CRITICAL)

EPSS: 0.40%

updated 2026-08-13T10:17:15.840000

2 posts

CWE-306: Missing Authentication for Critical Function

offseq at 2026-08-13T12:00:25.087Z ##

CVE-2026-59506 (CRITICAL): Portal Generator addon to Priority ERP lacks authentication for a critical function. Unauthenticated remote attackers can access sensitive data. No patch yet — restrict access & monitor. More info: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-13T12:00:25.000Z ##

CVE-2026-59506 (CRITICAL): Portal Generator addon to Priority ERP lacks authentication for a critical function. Unauthenticated remote attackers can access sensitive data. No patch yet — restrict access & monitor. More info: radar.offseq.com/threat/cve-20 #OffSeq #CVE202659506 #ERP #Infosec

##

CVE-2026-59501
(8.2 HIGH)

EPSS: 0.32%

updated 2026-08-13T10:17:15.140000

2 posts

CWE-284: Improper Access Control

CVE-2026-59500
(10.0 CRITICAL)

EPSS: 0.38%

updated 2026-08-13T10:17:15.017000

2 posts

CWE-287: Improper Authentication

CVE-2026-13610(CVSS UNKNOWN)

EPSS: 0.15%

updated 2026-08-13T06:33:55

2 posts

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

offseq at 2026-08-13T07:30:23.391Z ##

CVE-2026-13610 | CRITICAL privilege flaw in KiviCare <4.5.2 lets unauthenticated attackers create privileged staff accounts, risking patient data exposure 🏥. Restrict registration endpoint & monitor user creation. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-13T07:30:23.000Z ##

CVE-2026-13610 | CRITICAL privilege flaw in KiviCare <4.5.2 lets unauthenticated attackers create privileged staff accounts, risking patient data exposure 🏥. Restrict registration endpoint & monitor user creation. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #Healthcare

##

CVE-2026-69106
(8.8 HIGH)

EPSS: 0.35%

updated 2026-08-13T05:17:25.610000

2 posts

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

thehackerwire@mastodon.social at 2026-08-12T20:01:20.000Z ##

🟠 CVE-2026-69106 - High (8.8)

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T20:01:20.000Z ##

🟠 CVE-2026-69106 - High (8.8)

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-26035
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-08-13T05:17:23.773000

2 posts

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password

thehackerwire@mastodon.social at 2026-08-12T14:00:13.000Z ##

🔴 CVE-2026-26035 - Critical (9.8)

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T14:00:13.000Z ##

🔴 CVE-2026-26035 - Critical (9.8)

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19560
(8.8 HIGH)

EPSS: 0.34%

updated 2026-08-13T05:17:23.613000

2 posts

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

DailyCyberSecurity at 2026-08-12T03:45:23.321Z ##

Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.

securityonline.info/chrome-use

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T03:45:23.000Z ##

Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.

#Chrome #Google #UseAfterFree #CVE #BrowserSecurity #PatchNow #Cybersecurity

securityonline.info/chrome-use

##

CVE-2026-19556
(8.8 HIGH)

EPSS: 0.34%

updated 2026-08-13T05:17:23.020000

2 posts

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

DailyCyberSecurity at 2026-08-12T03:45:23.321Z ##

Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.

securityonline.info/chrome-use

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T03:45:23.000Z ##

Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.

#Chrome #Google #UseAfterFree #CVE #BrowserSecurity #PatchNow #Cybersecurity

securityonline.info/chrome-use

##

CVE-2026-71193
(9.6 CRITICAL)

EPSS: 0.53%

updated 2026-08-13T00:31:36

4 posts

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redire

offseq at 2026-08-13T01:30:26.660Z ##

OpenStack Designate CRITICAL vuln (CVE-2026-71193, CVSS 9.6): Authenticated users can hijack or disrupt DNS cross-tenant by bypassing zone checks via AttributeFilter in multi-pool deployments. Disable AttributeFilter until patched. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-13T00:00:05.000Z ##

🔴 CVE-2026-71193 - Critical (9.6)

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different poo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-13T01:30:26.000Z ##

OpenStack Designate CRITICAL vuln (CVE-2026-71193, CVSS 9.6): Authenticated users can hijack or disrupt DNS cross-tenant by bypassing zone checks via AttributeFilter in multi-pool deployments. Disable AttributeFilter until patched. radar.offseq.com/threat/cve-20 #OffSeq #OpenStack #DNS #Vuln

##

thehackerwire@mastodon.social at 2026-08-13T00:00:05.000Z ##

🔴 CVE-2026-71193 - Critical (9.6)

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different poo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10534
(8.4 HIGH)

EPSS: 0.18%

updated 2026-08-13T00:31:33

2 posts

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

thehackerwire@mastodon.social at 2026-08-13T08:00:36.000Z ##

🟠 CVE-2026-10534 - High (8.4)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T08:00:36.000Z ##

🟠 CVE-2026-10534 - High (8.4)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71469
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-13T00:31:33

2 posts

A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory exhaustion of the search-api pod, resulting in a Denial of Service (DoS).

thehackerwire@mastodon.social at 2026-08-13T08:00:13.000Z ##

🟠 CVE-2026-71469 - High (7.5)

A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T08:00:13.000Z ##

🟠 CVE-2026-71469 - High (7.5)

A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73519
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-08-13T00:31:28

4 posts

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate without any session, API key, or user account. Attackers can reach an affected node's management po

offseq at 2026-08-13T03:00:30.513Z ##

CVE-2026-73519: WolfStack <25.9.2 vulnerable to hard-coded secret in src/auth/mod.rs — remote attackers can bypass auth & run root commands in containers via the management port. Restrict access & monitor for X-WolfStack-Secret usage. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T23:00:10.000Z ##

🔴 CVE-2026-73519 - Critical (9.8)

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-13T03:00:30.000Z ##

CVE-2026-73519: WolfStack <25.9.2 vulnerable to hard-coded secret in src/auth/mod.rs — remote attackers can bypass auth & run root commands in containers via the management port. Restrict access & monitor for X-WolfStack-Secret usage. radar.offseq.com/threat/cve-20 #OffSeq #CVE202673519

##

thehackerwire@mastodon.social at 2026-08-12T23:00:10.000Z ##

🔴 CVE-2026-73519 - Critical (9.8)

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71471
(9.0 None)

EPSS: 1.45%

updated 2026-08-13T00:31:26

4 posts

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attac

thehackerwire@mastodon.social at 2026-08-13T08:00:24.000Z ##

🔴 CVE-2026-71471 - Critical (9)

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-13T04:30:24.734Z ##

CVE-2026-71471 (CRITICAL): acm-search-v2-rhel9 lets hub admins with Search CR patch rights deploy arbitrary containers fleet-wide. RCE & data access at risk. Restrict Search CR patch access now. Full details: radar.offseq.com/threat/a-flaw

##

thehackerwire@mastodon.social at 2026-08-13T08:00:24.000Z ##

🔴 CVE-2026-71471 - Critical (9)

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-13T04:30:24.000Z ##

CVE-2026-71471 (CRITICAL): acm-search-v2-rhel9 lets hub admins with Search CR patch rights deploy arbitrary containers fleet-wide. RCE & data access at risk. Restrict Search CR patch access now. Full details: radar.offseq.com/threat/a-flaw #OffSeq #Kubernetes #RedHat #Infosec

##

CVE-2026-73303
(8.2 HIGH)

EPSS: 0.23%

updated 2026-08-12T23:17:24.403000

2 posts

Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated attacker who obtains a victim account identifier can start the email-change workflow for the victim, receive and submit the verification code through POST

thehackerwire@mastodon.social at 2026-08-12T21:01:26.000Z ##

🟠 CVE-2026-73303 - High (8.2)

Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T21:01:26.000Z ##

🟠 CVE-2026-73303 - High (8.2)

Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55676
(8.8 HIGH)

EPSS: 0.30%

updated 2026-08-12T23:17:21.683000

1 posts

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (`file-upload/php/config.php:16`), so the type check is a no-op and every extension is ac

thehackerwire@mastodon.social at 2026-08-11T22:00:10.000Z ##

🟠 CVE-2026-55676 - High (8.8)

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19002
(8.1 HIGH)

EPSS: 0.29%

updated 2026-08-12T21:31:51

2 posts

A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client appli

thehackerwire@mastodon.social at 2026-08-12T22:02:20.000Z ##

🟠 CVE-2026-19002 - High (8.1)

A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T22:02:20.000Z ##

🟠 CVE-2026-19002 - High (8.1)

A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73326
(7.6 HIGH)

EPSS: 0.27%

updated 2026-08-12T21:31:50

2 posts

CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime across the attack, front_cache, cama_meta_tag, and cama_contact_form plugins to al

thehackerwire@mastodon.social at 2026-08-12T21:01:37.000Z ##

🟠 CVE-2026-73326 - High (7.6)

CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorizatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T21:01:37.000Z ##

🟠 CVE-2026-73326 - High (7.6)

CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorizatio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73329
(8.7 HIGH)

EPSS: 0.23%

updated 2026-08-12T21:31:50

2 posts

CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter during draft creation. Attackers can submit a malicious HTML payload as a draft title through the drafts creation endpoint, which is persisted to the databas

thehackerwire@mastodon.social at 2026-08-12T21:00:25.000Z ##

🟠 CVE-2026-73329 - High (8.7)

CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter duri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T21:00:25.000Z ##

🟠 CVE-2026-73329 - High (8.7)

CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter duri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73433
(6.6 MEDIUM)

EPSS: 0.13%

updated 2026-08-12T21:31:44

2 posts

A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the counter underflows to a very large unsigned value, causing subsequent null-terminated

thehackerwire@mastodon.social at 2026-08-12T21:00:14.000Z ##

🟠 CVE-2026-73433 - High (7.6)

A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T21:00:14.000Z ##

🟠 CVE-2026-73433 - High (7.6)

A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73332
(8.7 HIGH)

EPSS: 0.23%

updated 2026-08-12T21:31:43

2 posts

CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which lacks proper authorization controls. Attackers can persist malicious script payloads into the database that execute in vic

thehackerwire@mastodon.social at 2026-08-12T21:00:35.000Z ##

🟠 CVE-2026-73332 - High (8.7)

CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T21:00:35.000Z ##

🟠 CVE-2026-73332 - High (8.7)

CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73498
(7.7 HIGH)

EPSS: 0.33%

updated 2026-08-12T21:17:31

2 posts

### Summary `confluence_upload_attachment` passes `file_path` directly to `open(file_path, "rb")` with no path validation. Any authenticated MCP client — or an AI agent manipulated via prompt injection — can read any file the server process can access and exfiltrate it to Confluence as an attachment. ### Details Root cause: `src/mcp_atlassian/confluence/attachments.py`, `_upload_attachment_direct

thehackerwire@mastodon.social at 2026-08-12T23:01:08.000Z ##

🟠 CVE-2026-73498 - High (7.7)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T23:01:08.000Z ##

🟠 CVE-2026-73498 - High (7.7)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73493
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-12T21:08:45

2 posts

## Summary `http4s-blaze-server` aggregates the fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated fragmented message and drive unbounded heap growth in the server JVM, resulting in denial of service via `OutOfMemoryError`. ## Impact Any http4s application serving WebSocket routes over

thehackerwire@mastodon.social at 2026-08-12T23:00:57.000Z ##

🟠 CVE-2026-73493 - High (7.5)

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A clie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T23:00:57.000Z ##

🟠 CVE-2026-73493 - High (7.5)

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A clie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18961
(8.1 HIGH)

EPSS: 0.45%

updated 2026-08-12T21:00:52.257000

2 posts

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me endpoint as proof of mailbox ownership — Generic::normalize_common() copies this valu

thehackerwire@mastodon.social at 2026-08-12T04:00:18.000Z ##

🟠 CVE-2026-18961 - High (8.1)

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the pl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T04:00:18.000Z ##

🟠 CVE-2026-18961 - High (8.1)

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the pl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66659
(9.3 CRITICAL)

EPSS: 0.29%

updated 2026-08-12T20:59:00.027000

4 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9.

thehackerwire@mastodon.social at 2026-08-12T12:00:11.000Z ##

🔴 CVE-2026-66659 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection.

This issue affects Tablesome Table: from n/a through 1.2.9.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-12T07:30:27.118Z ##

CVE-2026-66659: CRITICAL SQL Injection (CVSS 9.3) in Essekia Tablesome Table ≤1.2.9. Allows unauth’d blind SQLi & data disclosure. No patch yet — monitor vendor updates. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T12:00:11.000Z ##

🔴 CVE-2026-66659 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection.

This issue affects Tablesome Table: from n/a through 1.2.9.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T07:30:27.000Z ##

CVE-2026-66659: CRITICAL SQL Injection (CVSS 9.3) in Essekia Tablesome Table ≤1.2.9. Allows unauth’d blind SQLi & data disclosure. No patch yet — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #SQLInjection #Vuln #Infosec

##

CVE-2026-17248
(7.1 HIGH)

EPSS: 0.33%

updated 2026-08-12T20:53:43.330000

1 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.

hugovalters@mastodon.social at 2026-08-13T15:07:04.000Z ##

CVE-2026-17248 - DoS in IBM i 7.3-7.6 via improper OS command neutralization. Remote authenticated attacker can crash systems. CVSS 7.1. No patch yet - monitor advisory. #CVE #IBM #infosec

valtersit.com/cve/CVE-2026-172

##

CVE-2026-19311
(8.1 HIGH)

EPSS: 0.41%

updated 2026-08-12T20:50:27.407000

2 posts

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

thehackerwire@mastodon.social at 2026-08-12T20:00:16.000Z ##

🟠 CVE-2026-19311 - High (8.1)

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T20:00:16.000Z ##

🟠 CVE-2026-19311 - High (8.1)

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73418
(7.5 HIGH)

EPSS: 0.46%

updated 2026-08-12T20:21:20

2 posts

## Summary The exported `getToken()` helper (`next-auth/jwt` and `@auth/core/jwt`) can throw an uncaught exception when it reads a malformed `Authorization: Bearer …` header. When no session cookie is present, `getToken()` URL-decodes the bearer value before validating it, and malformed percent-encoding causes the decode step to throw rather than being treated as an invalid token. Because `getTok

thehackerwire@mastodon.social at 2026-08-12T22:00:55.000Z ##

🟠 CVE-2026-73418 - High (7.5)

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T22:00:55.000Z ##

🟠 CVE-2026-73418 - High (7.5)

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73406
(7.5 HIGH)

EPSS: 0.37%

updated 2026-08-12T20:17:55.617000

2 posts

Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller could query an email or user identifier, distinguish existing users from missing users, and obtain tenant identifiers, user identifiers, email addres

thehackerwire@mastodon.social at 2026-08-12T21:01:12.000Z ##

🟠 CVE-2026-73406 - High (7.5)

Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated cal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T21:01:12.000Z ##

🟠 CVE-2026-73406 - High (7.5)

Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated cal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73300
(9.6 CRITICAL)

EPSS: 0.38%

updated 2026-08-12T20:17:54.023000

2 posts

Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database compromise. This vulnerability is fixed in 3.40.0.

thehackerwire@mastodon.social at 2026-08-12T20:01:00.000Z ##

🔴 CVE-2026-73300 - Critical (9.6)

Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T20:01:00.000Z ##

🔴 CVE-2026-73300 - Critical (9.6)

Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72798
(8.6 HIGH)

EPSS: 0.26%

updated 2026-08-12T20:17:51.543000

1 posts

SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block ty

hugovalters@mastodon.social at 2026-08-13T12:02:21.000Z ##

CVE-2026-72798 - High severity info disclosure in SiYuan. Unpatched v3.7.4 lets anonymous readers access hidden database content via related-database bypass. CVSS 8.6. Update immediately. #CVE #SiYuan #infosec

valtersit.com/cve/CVE-2026-727

##

CVE-2026-58115
(10.0 CRITICAL)

EPSS: 0.65%

updated 2026-08-12T20:17:45.377000

2 posts

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attac

DailyCyberSecurity at 2026-08-12T07:32:31.690Z ##

CVE-2026-58115 is a CVSS 10 flaw letting unauthenticated attackers run code on SIMATIC IoT2050 via Node-RED. Siemens urges an immediate update.

securityonline.info/simatic-io

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T07:32:31.000Z ##

CVE-2026-58115 is a CVSS 10 flaw letting unauthenticated attackers run code on SIMATIC IoT2050 via Node-RED. Siemens urges an immediate update.

#CVE202658115 #Siemens #NodeRED #RCE #SIMATIC #ICS #Cybersecurity

securityonline.info/simatic-io

##

CVE-2026-50060
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-12T20:17:44.970000

1 posts

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.

hugovalters@mastodon.social at 2026-08-12T23:00:39.000Z ##

CVE-2026-50060 - Use-after-free in Solid Edge SE2025/2026. Malicious DFT files can trigger code execution. CVSS 7.8. Patch to latest updates now. #CVE #SolidEdge #infosec

valtersit.com/cve/CVE-2026-500

##

CVE-2026-16756
(7.5 HIGH)

EPSS: 0.42%

updated 2026-08-12T20:17:38.353000

2 posts

Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. To mitigate this issue, users should upgrade to aws-smithy-http-ser

awssecurityfeed at 2026-08-12T19:00:01.936Z ##

CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT
Description:
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and s...

aws.amazon.com/security/securi

##

awssecurityfeed@infosec.exchange at 2026-08-12T19:00:01.000Z ##

CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT
Description:
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and s...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-73327
(7.6 HIGH)

EPSS: 0.85%

updated 2026-08-12T18:31:29

2 posts

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be wr

thehackerwire@mastodon.social at 2026-08-12T20:01:10.000Z ##

🟠 CVE-2026-73327 - High (7.6)

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T20:01:10.000Z ##

🟠 CVE-2026-73327 - High (7.6)

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73325
(7.8 HIGH)

EPSS: 0.26%

updated 2026-08-12T18:31:28

2 posts

Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking Python's pickle machinery during deserialization. Attackers can embed malicious __reduce_

thehackerwire@mastodon.social at 2026-08-12T17:00:05.000Z ##

🟠 CVE-2026-73325 - High (7.8)

Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T17:00:05.000Z ##

🟠 CVE-2026-73325 - High (7.8)

Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65941
(8.8 HIGH)

EPSS: 0.44%

updated 2026-08-12T18:31:21

2 posts

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

thehackerwire@mastodon.social at 2026-08-12T17:01:24.000Z ##

🟠 CVE-2026-65941 - High (8.8)

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T17:01:24.000Z ##

🟠 CVE-2026-65941 - High (8.8)

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69105
(8.1 HIGH)

EPSS: 0.13%

updated 2026-08-12T18:31:19

2 posts

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

thehackerwire@mastodon.social at 2026-08-12T17:01:14.000Z ##

🟠 CVE-2026-69105 - High (8.1)

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T17:01:14.000Z ##

🟠 CVE-2026-69105 - High (8.1)

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18634
(8.4 HIGH)

EPSS: 0.22%

updated 2026-08-12T18:31:15

1 posts

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component.

hugovalters@mastodon.social at 2026-08-13T11:01:26.000Z ##

CVE-2026-18634 - High severity deserialization flaw in GMS 9.5.1 and earlier. Local attacker can trigger unauthorized actions via service. CVSS 8.4. Unpatched - update immediately. #CVE #cybersecurity #GMS

valtersit.com/cve/CVE-2026-186

##

CVE-2026-50656
(7.8 HIGH)

EPSS: 10.75%

updated 2026-08-12T18:31:00

12 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

3 repos

https://github.com/HORKimhab/CVE-2026-50656

https://github.com/0xBlackash/CVE-2026-50656

https://github.com/g0thamRabb1t/CVE-2026-50656-rogueplanet-validation

ottoto2017@prattohome.com at 2026-08-13T07:01:03.000Z ##

「Microsoftに恨みを持つハッカーが、完全にパッチが適用されたWindows上でシステム権限を取得できる新たなゼロデイ脆弱性を発見した。
/水曜日の裏技を使おうぜ、ベイビー 」: #TheRegister

「マイクロソフトに恨みを持つ、ゼロデイ攻撃を専門とするNightmare Eclipseは、マイクロソフトのRoguePlanetパッチ(CVE-2026-50656)を回避すると思われる、Defenderの新たなゼロデイ脆弱性「ShieldBreak」を公開した。これにより、攻撃者は完全にパッチが適用されたWindows 10、Windows 11、およびWindows Serverシステム上でSYSTEM権限を取得できる。

少なくとも他の研究者の一人によると、このエクスプロイトは有効だという。「試してみたところ、最新のWindows 11でも動作しました」と、元マイクロソフト社員でセキュリティ専門家のケビン・ボーモント氏 は述べている 。 」

theregister.com/cyber-crime/20

#prattohome

##

teezeh@ieji.de at 2026-08-13T05:45:44.000Z ##

“Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.”

theregister.com/cyber-crime/20

##

cyberworldops at 2026-08-12T08:10:01.208Z ##

A proof-of-concept for ShieldBreak has been disclosed, showing how to bypass the patch Microsoft issued for CVE-2026-50656 (RoguePlanet). The flaw targets SYSTEM-level privilege escalation on Windows systems protected by Microsoft Defender.

cyberworldops.eu/en/shieldbrea

##

teezeh@ieji.de at 2026-08-12T05:27:04.000Z ##

„Microsoft hat mit dem August 2026-Patchday zwar einige Sicherheitskorrekturen ausgeliefert. Aber die RoguePlanet genannte Schwachstelle (CVE-2026-50656) soll nicht ausreichend abgeschwächt worden sein. Der als Nightmare Eclipse agierende Sicherheitsforscher hat einen ShieldBreak genannten Proof of Concept (PoC) veröffentlicht.“

borncity.com/blog/2026/08/12/s

##

DailyCyberSecurity at 2026-08-12T04:24:39.796Z ##

A public PoC named ShieldBreak bypasses Microsoft's CVE-2026-50656 patch, enabling Windows Defender privilege escalation to SYSTEM.

securityonline.info/shieldbrea

##

ottoto2017@prattohome.com at 2026-08-13T07:01:03.000Z ##

「Microsoftに恨みを持つハッカーが、完全にパッチが適用されたWindows上でシステム権限を取得できる新たなゼロデイ脆弱性を発見した。
/水曜日の裏技を使おうぜ、ベイビー 」: #TheRegister

「マイクロソフトに恨みを持つ、ゼロデイ攻撃を専門とするNightmare Eclipseは、マイクロソフトのRoguePlanetパッチ(CVE-2026-50656)を回避すると思われる、Defenderの新たなゼロデイ脆弱性「ShieldBreak」を公開した。これにより、攻撃者は完全にパッチが適用されたWindows 10、Windows 11、およびWindows Serverシステム上でSYSTEM権限を取得できる。

少なくとも他の研究者の一人によると、このエクスプロイトは有効だという。「試してみたところ、最新のWindows 11でも動作しました」と、元マイクロソフト社員でセキュリティ専門家のケビン・ボーモント氏 は述べている 。 」

theregister.com/cyber-crime/20

#prattohome

##

teezeh@ieji.de at 2026-08-13T05:45:44.000Z ##

“Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.”

theregister.com/cyber-crime/20

##

cyberworldops@infosec.exchange at 2026-08-12T08:10:01.000Z ##

A proof-of-concept for ShieldBreak has been disclosed, showing how to bypass the patch Microsoft issued for CVE-2026-50656 (RoguePlanet). The flaw targets SYSTEM-level privilege escalation on Windows systems protected by Microsoft Defender.

#ShieldBreak #CVE202650656 #PrivilegeEscalation #MicrosoftDefender

cyberworldops.eu/en/shieldbrea

##

teezeh@ieji.de at 2026-08-12T05:27:04.000Z ##

„Microsoft hat mit dem August 2026-Patchday zwar einige Sicherheitskorrekturen ausgeliefert. Aber die RoguePlanet genannte Schwachstelle (CVE-2026-50656) soll nicht ausreichend abgeschwächt worden sein. Der als Nightmare Eclipse agierende Sicherheitsforscher hat einen ShieldBreak genannten Proof of Concept (PoC) veröffentlicht.“

borncity.com/blog/2026/08/12/s

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T04:24:39.000Z ##

A public PoC named ShieldBreak bypasses Microsoft's CVE-2026-50656 patch, enabling Windows Defender privilege escalation to SYSTEM.

#ShieldBreak #CVE202650656 #WindowsDefender #PrivilegeEscalation #PoC #RoguePlanet #Cybersecurity

securityonline.info/shieldbrea

##

AmmarSpaces@infosec.exchange at 2026-08-11T21:36:43.000Z ##

On another news NightmareEclipse (the goat?) returned with a new PoC, after Microsoft failed to fully patch RoguePlanet (CVE-2026-50656), the current PoC only made for latest Windows 11 release, but they said that Windows 10 also still vulnerable. And yeah, it works even after the latest update

github.com/MSNightmare/ShieldB

#cybersecurity #infosec #zeroday #vulnerability #windows #nightmareEclipse

##

DarkWebInformer@infosec.exchange at 2026-08-11T19:57:18.000Z ##

🚨Nightmare Eclipse has released a new zero-day PoC called ShieldBreak

Per the security researcher: "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass."

GitHub: github.com/MSNightmare/ShieldB

##

CVE-2026-73294
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-08-12T17:17:32.527000

2 posts

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/{id}/repositories and scheduled commit-hash polling, allowing a project Manager or Owner to execute arbitrary OS commands in the Semaphore server process. This i

thehackerwire@mastodon.social at 2026-08-12T17:01:02.000Z ##

🔴 CVE-2026-73294 - Critical (9.9)

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/{id}/rep...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T17:01:02.000Z ##

🔴 CVE-2026-73294 - Critical (9.9)

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/{id}/rep...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73122
(7.7 HIGH)

EPSS: 0.21%

updated 2026-08-12T17:17:31.853000

2 posts

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel namespace on the hub, potentially exposing credentials for other tenants' Git and Helm

thehackerwire@mastodon.social at 2026-08-12T06:00:48.000Z ##

🟠 CVE-2026-73122 - High (7.7)

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T06:00:48.000Z ##

🟠 CVE-2026-73122 - High (7.7)

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70468
(8.1 HIGH)

EPSS: 0.59%

updated 2026-08-12T15:30:49

2 posts

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>

thehackerwire@mastodon.social at 2026-08-12T14:00:02.000Z ##

🟠 CVE-2026-70468 - High (8.1)

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiMan...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T14:00:02.000Z ##

🟠 CVE-2026-70468 - High (8.1)

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiMan...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72898
(10.0 CRITICAL)

EPSS: 10.40%

updated 2026-08-12T15:18:30.347000

9 posts

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Nuclei template

1 repos

https://github.com/0xBlackash/CVE-2026-72898

security_crawler_carl at 2026-08-13T13:32:36.161Z ##

🏆 New Achievement! Query of Doom: Prerequisite — Having a Database — Complete!

QUEST UPDATE: Gain Total Administrative Access. Status: Already completed. By someone else. Without you. Metabase, the business intelligence platform, disclosed CVE-2026-72898, a critical SQL injection zero-day scoring a perfect 10 — the platonic ideal of catastrophe. (1/3)

##

thecybermind at 2026-08-13T11:34:47.787Z ##

(CISA TS-SOC) CVE-2026-72898 – Metabase SQL Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to gain administrator access, modify configuration, steal credentials, and exfiltrate data from connected databases via SQL injection....

thecybermind.co/join

##

undercodenews@mastodon.social at 2026-08-12T13:25:58.000Z ##

Metabase Hit by a Critical Zero-Day: CVE-2026-72898 Puts Business Intelligence Data at Risk

Introduction: When the Analytics Layer Becomes the Attack Path Metabase is often treated as the quiet engine behind dashboards, reports, business intelligence, and data-driven decision-making. It may not be the system employees think about every morning, but behind those charts and dashboards can sit connections to production databases, cloud warehouses, customer records,…

undercodenews.com/metabase-hit

##

thecybermind at 2026-08-12T11:45:00.075Z ##

🚨 CRITICAL THREAT: CISA adds CVE-2026-72898 (Metabase SQL Injection) to the KEV catalog due to active exploitation. Unauthenticated attackers can hijack admin rights and steal database credentials. Full TSUITE brief with SPL, KQL, AQL & YARA-L: thecybermind.co/jily

##

security_crawler_carl@infosec.exchange at 2026-08-13T13:32:36.000Z ##

🏆 New Achievement! Query of Doom: Prerequisite — Having a Database — Complete!

QUEST UPDATE: Gain Total Administrative Access. Status: Already completed. By someone else. Without you. Metabase, the business intelligence platform, disclosed CVE-2026-72898, a critical SQL injection zero-day scoring a perfect 10 — the platonic ideal of catastrophe. (1/3)

##

thecybermind@infosec.exchange at 2026-08-13T11:34:47.000Z ##

(CISA TS-SOC) CVE-2026-72898 – Metabase SQL Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to gain administrator access, modify configuration, steal credentials, and exfiltrate data from connected databases via SQL injection....

thecybermind.co/join

##

thecybermind@infosec.exchange at 2026-08-12T11:45:00.000Z ##

🚨 CRITICAL THREAT: CISA adds CVE-2026-72898 (Metabase SQL Injection) to the KEV catalog due to active exploitation. Unauthenticated attackers can hijack admin rights and steal database credentials. Full TSUITE brief with SPL, KQL, AQL & YARA-L: thecybermind.co/jily

#CyberSecurity

##

secdb@infosec.exchange at 2026-08-11T21:00:13.000Z ##

🚨 [CISA-2026:0811] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20349 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-68820 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows Ancillary Function Driver for WinSock
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72898 (secdb.nttzen.cloud/cve/detail/)
- Name: Metabase SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Metabase
- Product: Metabase
- Notes: metabase.com/blog/security-upd ; github.com/metabase/metabase/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260811 #cisa20260811 #cve_2026_20349 #cve_2026_68820 #cve_2026_72898 #cve202620349 #cve202668820 #cve202672898

##

cisakevtracker@mastodon.social at 2026-08-11T20:01:25.000Z ##

CVE ID: CVE-2026-72898
Vendor: Metabase
Product: Metabase
Date Added: 2026-08-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-66147
(9.4 CRITICAL)

EPSS: 1.05%

updated 2026-08-12T15:18:18.370000

1 posts

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

DailyCyberSecurity@infosec.exchange at 2026-08-12T00:45:54.000Z ##

SonicWall patched a critical GMS vulnerability, CVE-2026-66147 (CVSS 9.4), enabling unauthenticated remote code execution. Update to 9.5.2 now.

#SonicWall #CVE #RCE #GMS #EmailSecurity #InfoSec

securityonline.info/sonicwall-

##

CVE-2026-68820
(7.0 HIGH)

EPSS: 0.33%

updated 2026-08-12T14:57:30.717000

37 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1 repos

https://github.com/HORKimhab/CVE-2026-68820

thecybermind at 2026-08-13T13:27:21.132Z ##

(CISA TS-SOC) CVE-2026-68820 – Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Severity: HIGH Impact Summary: Allows an authorized attacker to elevate privileges locally via a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock....

thecybermind.co/join

##

undercodenews@mastodon.social at 2026-08-13T09:11:47.000Z ##

Microsoft’s Record Patch Tuesday Exposes a New Cybersecurity Reality as AI Finds More Flaws + Video

A Patch Tuesday That Signals a Bigger Change Microsoft’s latest Patch Tuesday has delivered an extraordinary number of security fixes, with 419 vulnerabilities addressed in a single release, including three zero-day flaws. One vulnerability, CVE-2026-68820, was reportedly exploited in the wild and has been linked to activity associated with the Lazarus Group. The scale…

undercodenews.com/microsofts-r

##

sayzard@mastodon.sayzard.org at 2026-08-12T23:44:03.000Z ##

Lazarus hackers exploited Windows zero-day to target defense firms

북한 연계 Lazarus 그룹이 Windows AFD.sys의 use-after-free 권한 상승 제로데이(CVE-2026-68820)를 악용해 방산·항공우주 기업을 표적화했다. 취약점은 로컬 인증 사용자가 조작된 프로그램으로 레이스 컨디션을 유발해 SYSTEM 권한을 얻을 수 있으며, Microsoft는 8월 Patch Tuesday에서 이를 이미 실제 공격에 악용된 취약점으로 분류해 수정했다. 공격자는 FudModule 커널 루트킷으로 EDR 텔레메트리...

bleepingcomputer.com/news/secu

##

cyberworldops at 2026-08-12T20:20:01.506Z ##

Lazarus Group is exploiting a Windows zero-day (CVE-2026-68820) to escalate to SYSTEM privileges and deploy backdoors. Targets include defense and aerospace firms in France, Germany, Brazil, and India, lured through fake LinkedIn job offers under Operation Dream Job.

cyberworldops.eu/en/lazarus-ex

##

Analyst207@mastodon.social at 2026-08-12T16:01:36.000Z ##

Lazarus Exploits Windows Zero-Day in Targeted Defense Sector Attacks

The notorious Lazarus threat group has been exploiting a newly patched Windows zero-day vulnerability, CVE-2026-68820, to gain SYSTEM privileges and escalate their attacks on high-value targets in the defense sector. This alarming exploit has been active since early July, making it crucial for organizations to stay vigilant.

osintsights.com/lazarus-exploi

#Lazarus #WindowsZeroDay #Cve202668820 #ZeroDay #SupplyChainAttacks

##

oversecurity@mastodon.social at 2026-08-12T16:01:31.000Z ##

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the...

🔗️ [Bleepingcomputer] link.is.it/NpjibN

##

Matchbook3469@mastodon.social at 2026-08-12T15:31:43.000Z ##

🟠 New security advisory:

CVE-2026-68820 affects multiple systems.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #SecurityPatching #HackerNews

##

tugatech@masto.pt at 2026-08-12T15:07:31.000Z ##

Microsoft lança atualização de emergência para corrigir a CVE-2026-68820, uma falha de gravidade elevada no controlador Ancillary Function para WinSock. A vulnerabilidade, que afeta diversas versões do Windows, já está a ser explorada em ataques reais. 🚨

🔗 tugatech.com.pt/t89012-microso

#falha #lan #microsoft #windows 

##

netsecio@mastodon.social at 2026-08-12T15:06:54.000Z ##

📰 Lazarus Group Exploits Windows Zero-Day in Espionage Campaign

Microsoft patches actively exploited Windows zero-day (CVE-2026-68820) used by Lazarus Group. The bug allows SYSTEM-level access and was used in the 'Operation Dream Job' campaign to deploy rootkits against the defense sector. #CVE202668820 #Lazarus ...

🔗 cyber.netsecops.io/articles/la

##

threatnoir at 2026-08-12T13:05:54.489Z ##

⚠️ CRITICAL: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Microsoft patched CVE-2026-68820, a zero-day use-after-free in afd.sys kernel driver actively exploited for SYSTEM privilege escalation. This is the fourth afd.sys zero-day since 2022, with historical links to nation-state actors. All Windows systems running unpatched afd.sys are at immediate risk…

threatnoir.com/focus

🤖 AI generated summary

##

CapTechGroup@mastodon.social at 2026-08-12T12:51:38.000Z ##

Microsoft's newest patch cycle closes nearly 400 security holes, among them CVE-2026-62832, CVE-2026-68820, and CVE-2026-72971. That volume makes triage the hard part, so plan which systems get updated first and confirm the rollout...

captechgroup.com/threat-intell

##

security_crawler_carl at 2026-08-12T12:39:41.495Z ##

🏆 New Achievement! CVE-2026-68820: The Lazarus Rises (Again)!

PHASE ONE BEGINS. Emerging from the shadows of Pyongyang's finest state-sponsored hacking collective, Lazarus has arrived — and they brought a use-after-free bug in afd.sys, the Windows kernel-mode driver, as their opening act. CVE-2026-68820 lets a low-privilege, locally authenticated attacker trigger a race condition, escalate straight to SYSTEM, and basically own the stage. (1/3)

##

offseq at 2026-08-12T09:00:32.200Z ##

CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. radar.offseq.com/threat/fresh-

##

VirusBulletin at 2026-08-12T08:50:09.841Z ##

Check Point researchers look into the latest variant of the Operation Dream Job campaign where the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of Lazarus’s kernel-mode rootkit FudModule. research.checkpoint.com/2026/s

##

thecybermind at 2026-08-12T08:49:26.242Z ##

🚨 THREAT ALERT: CISA adds CVE-2026-68820 (Windows WinSock AFD Use-After-Free) to the KEV catalog due to active exploitation. Local attackers can elevate privileges to system level. Access our TSUITE brief with CrowdStrike CQL telemetry queries: thecybermind.co/jily

##

ottoto2017@prattohome.com at 2026-08-12T06:07:08.000Z ##

「Microsoft 製品の脆弱性対策について(2026年8月)」: #IPA

「 2026年8月12日(日本時間)に Microsoft 製品に関するセキュリティ更新プログラム(月例)が公表されています。
これらの脆弱性を悪用された場合、アプリケーションプログラムが異常終了する、攻撃者によってパソコンを制御される、といった様々な被害が発生するおそれがあります。

この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。 」

ipa.go.jp/security/security-al

#prattohome

##

sayzard@mastodon.sayzard.org at 2026-08-12T05:46:34.000Z ##

Bugs in MS' Patch Tuesday release and NK's Lazarus has hit one already

Microsoft의 2026년 8월 Patch Tuesday는 421개 취약점을 수정했으며, 그중 Windows WinSock Ancillary Function Driver(afd.sys)의 use-after-free 취약점 CVE-2026-68820은 Lazarus 그룹이 패치 전 실제 공격에 사용한 제로데이다. 로컬 인증 사용자가 경쟁 조건을 유발해 사용자 상호작용 없이 SYSTEM 권한 코드 실행을...

theregister.com/security/2026/

##

ottoto2017@prattohome.com at 2026-08-12T04:51:43.000Z ##

「マイクロソフトは、現在攻撃を受けているWindowsドライバーのゼロデイ脆弱性を含む398件の脆弱性を修正した。 」: #TheHackerNews

「マイクロソフトは火曜日に月例のセキュリティアップデートを公開したが、修正された脆弱性の1つが既に攻撃に悪用されている。

このバグは、ネットワークソケット操作を処理するWindowsカーネルの中核ドライバに存在します。既にマシン上でコードを実行している攻撃者は、このバグを利用してSYSTEM権限に昇格できます。このパッチが最初にリリースされます。

この脆弱性は CVE-2026-68820 (CVSSスコア:7.0)として追跡されており、今月のリリースでマイクロソフトが現在悪用されていると警告している唯一の脆弱性です。悪用は、ドライバーの競合状態をトリガーすることによって行われます。マイクロソフトは、この悪用を行った組織を公表していません。」

thehackernews.com/2026/08/micr

#prattohome

##

sayzard@mastodon.sayzard.org at 2026-08-12T03:43:20.000Z ##

Microsoft Plugs Nearly 400 Security Holes

Microsoft가 8월 Patch Tuesday에서 Windows 및 지원 소프트웨어의 취약점 최소 398건을 수정했으며, 이 중 42건은 원격 코드 실행 등으로 이어질 수 있는 Critical 등급이다. 이미 악용 중인 CVE-2026-68820은 거의 모든 Windows 엔드포인트의 소켓 연결에 관여하는 afd.sys의 권한 상승 취약점으로, 초기 침투 후 시스템 장악 체인에 사용될 수 있다. 또한 Windows User Profile Service의 CVE-2026-62832는 공개된 LegacyHive 이슈와 연관 가능성이 있으며 악용 가능성이 높은 것으로...

krebsonsecurity.com/2026/08/mi

##

DailyCyberSecurity at 2026-08-12T02:44:48.174Z ##

Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.

securityonline.info/lazarus-ze

##

DailyCyberSecurity at 2026-08-12T02:21:44.193Z ##

Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild, plus two disclosed bugs.

securityonline.info/microsoft-

##

thecybermind@infosec.exchange at 2026-08-13T13:27:21.000Z ##

(CISA TS-SOC) CVE-2026-68820 – Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Severity: HIGH Impact Summary: Allows an authorized attacker to elevate privileges locally via a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock....

thecybermind.co/join

##

cyberworldops@infosec.exchange at 2026-08-12T20:20:01.000Z ##

Lazarus Group is exploiting a Windows zero-day (CVE-2026-68820) to escalate to SYSTEM privileges and deploy backdoors. Targets include defense and aerospace firms in France, Germany, Brazil, and India, lured through fake LinkedIn job offers under Operation Dream Job.

#LazarusGroup #ZeroDayExploit #WindowsSecurity #OperationDreamJob

cyberworldops.eu/en/lazarus-ex

##

oversecurity@mastodon.social at 2026-08-12T16:01:31.000Z ##

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the...

🔗️ [Bleepingcomputer] link.is.it/NpjibN

##

tugatech@masto.pt at 2026-08-12T15:07:31.000Z ##

Microsoft lança atualização de emergência para corrigir a CVE-2026-68820, uma falha de gravidade elevada no controlador Ancillary Function para WinSock. A vulnerabilidade, que afeta diversas versões do Windows, já está a ser explorada em ataques reais. 🚨

🔗 tugatech.com.pt/t89012-microso

#falha #lan #microsoft #windows 

##

threatnoir@infosec.exchange at 2026-08-12T13:05:54.000Z ##

⚠️ CRITICAL: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Microsoft patched CVE-2026-68820, a zero-day use-after-free in afd.sys kernel driver actively exploited for SYSTEM privilege escalation. This is the fourth afd.sys zero-day since 2022, with historical links to nation-state actors. All Windows systems running unpatched afd.sys are at immediate risk…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

security_crawler_carl@infosec.exchange at 2026-08-12T12:39:41.000Z ##

🏆 New Achievement! CVE-2026-68820: The Lazarus Rises (Again)!

PHASE ONE BEGINS. Emerging from the shadows of Pyongyang's finest state-sponsored hacking collective, Lazarus has arrived — and they brought a use-after-free bug in afd.sys, the Windows kernel-mode driver, as their opening act. CVE-2026-68820 lets a low-privilege, locally authenticated attacker trigger a race condition, escalate straight to SYSTEM, and basically own the stage. (1/3)

##

offseq@infosec.exchange at 2026-08-12T09:00:32.000Z ##

CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. radar.offseq.com/threat/fresh- #OffSeq #ZeroDay #Windows #Cybersecurity

##

VirusBulletin@infosec.exchange at 2026-08-12T08:50:09.000Z ##

Check Point researchers look into the latest variant of the Operation Dream Job campaign where the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of Lazarus’s kernel-mode rootkit FudModule. research.checkpoint.com/2026/s

##

thecybermind@infosec.exchange at 2026-08-12T08:49:26.000Z ##

🚨 THREAT ALERT: CISA adds CVE-2026-68820 (Windows WinSock AFD Use-After-Free) to the KEV catalog due to active exploitation. Local attackers can elevate privileges to system level. Access our TSUITE brief with CrowdStrike CQL telemetry queries: thecybermind.co/jily

#CyberSecurity

##

ottoto2017@prattohome.com at 2026-08-12T06:07:08.000Z ##

「Microsoft 製品の脆弱性対策について(2026年8月)」: #IPA

「 2026年8月12日(日本時間)に Microsoft 製品に関するセキュリティ更新プログラム(月例)が公表されています。
これらの脆弱性を悪用された場合、アプリケーションプログラムが異常終了する、攻撃者によってパソコンを制御される、といった様々な被害が発生するおそれがあります。

この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。 」

ipa.go.jp/security/security-al

#prattohome

##

ottoto2017@prattohome.com at 2026-08-12T04:51:43.000Z ##

「マイクロソフトは、現在攻撃を受けているWindowsドライバーのゼロデイ脆弱性を含む398件の脆弱性を修正した。 」: #TheHackerNews

「マイクロソフトは火曜日に月例のセキュリティアップデートを公開したが、修正された脆弱性の1つが既に攻撃に悪用されている。

このバグは、ネットワークソケット操作を処理するWindowsカーネルの中核ドライバに存在します。既にマシン上でコードを実行している攻撃者は、このバグを利用してSYSTEM権限に昇格できます。このパッチが最初にリリースされます。

この脆弱性は CVE-2026-68820 (CVSSスコア:7.0)として追跡されており、今月のリリースでマイクロソフトが現在悪用されていると警告している唯一の脆弱性です。悪用は、ドライバーの競合状態をトリガーすることによって行われます。マイクロソフトは、この悪用を行った組織を公表していません。」

thehackernews.com/2026/08/micr

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T02:44:48.000Z ##

Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.

#Lazarus #ZeroDay #CVE202668820 #OperationDreamJob #Cybersecurity #DPRK #FudModule #DefenseSector

securityonline.info/lazarus-ze

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T02:21:44.000Z ##

Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild, plus two disclosed bugs.

#PatchTuesday #Microsoft #ZeroDay #CVE #WindowsSecurity #InfoSec

securityonline.info/microsoft-

##

secdb@infosec.exchange at 2026-08-11T21:00:13.000Z ##

🚨 [CISA-2026:0811] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20349 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-68820 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows Ancillary Function Driver for WinSock
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72898 (secdb.nttzen.cloud/cve/detail/)
- Name: Metabase SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Metabase
- Product: Metabase
- Notes: metabase.com/blog/security-upd ; github.com/metabase/metabase/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260811 #cisa20260811 #cve_2026_20349 #cve_2026_68820 #cve_2026_72898 #cve202620349 #cve202668820 #cve202672898

##

cyberworldops@infosec.exchange at 2026-08-11T20:10:00.000Z ##

Microsoft Patch Tuesday August 2026 patches 421 CVEs including CVE-2026-68820, an actively exploited use-after-free in the kernel driver afd.sys that grants SYSTEM-level privileges. Attacks are ongoing and no operational details have been disclosed yet. Prioritize patching on exposed systems.

#PatchTuesday #ZeroDay #VulnerabilityManagement #Microsoft

cyberworldops.eu/en/microsoft-

##

cisakevtracker@mastodon.social at 2026-08-11T20:01:05.000Z ##

CVE ID: CVE-2026-68820
Vendor: Microsoft
Product: Windows Ancillary Function Driver for WinSock
Date Added: 2026-08-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-73232
(7.5 HIGH)

EPSS: 0.45%

updated 2026-08-12T14:18:38.810000

1 posts

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.ReadAll reads gzip, brotli, deflate, transparently decompressed, or chunked response bodies without a decompressed-size bound. This issue is fixed in vers

thehackerwire@mastodon.social at 2026-08-11T21:00:15.000Z ##

🟠 CVE-2026-73232 - High (7.5)

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.R...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67568
(9.1 CRITICAL)

EPSS: 0.24%

updated 2026-08-12T14:18:33.557000

2 posts

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

thehackerwire@mastodon.social at 2026-08-12T00:01:26.000Z ##

🔴 CVE-2026-67568 - Critical (9.1)

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T00:00:38.000Z ##

CVE-2026-67568 (CRITICAL, CVSS 9.3) in Mira Firmware 1.7.1.47: Hard-coded credentials let remote attackers read/write sensitive health data. No patch yet — restrict network access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #CVE202667568 #infosec #medtech #vuln

##

CVE-2026-70398
(9.6 CRITICAL)

EPSS: 0.22%

updated 2026-08-12T13:17:24.637000

4 posts

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to

thehackerwire@mastodon.social at 2026-08-12T04:00:28.000Z ##

🔴 CVE-2026-70398 - Critical (9.6)

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a te...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-12T03:00:23.878Z ##

CRITICAL CVE-2026-70398 in Red Hat Advanced Cluster Management for Kubernetes 2: Authenticated tenants can redirect bearer tokens via GitOpsCluster controller. No official fix. Restrict privileges & monitor activity. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T04:00:28.000Z ##

🔴 CVE-2026-70398 - Critical (9.6)

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a te...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T03:00:23.000Z ##

CRITICAL CVE-2026-70398 in Red Hat Advanced Cluster Management for Kubernetes 2: Authenticated tenants can redirect bearer tokens via GitOpsCluster controller. No official fix. Restrict privileges & monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Kubernetes #RedHat #CVE202670398

##

CVE-2026-57858
(8.9 HIGH)

EPSS: 0.41%

updated 2026-08-12T13:17:22.943000

4 posts

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to

1 repos

https://github.com/zylideum/CVE-2026-57858

thehackerwire@mastodon.social at 2026-08-12T14:00:23.000Z ##

🟠 CVE-2026-57858 - High (8.9)

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracki...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-12T13:30:27.037Z ##

CVE-2026-57858: CRITICAL stored XSS in Cal.com Self-Hosted (v2.1.1 – 6.2.0). Exploited via BookingPageTagManager by authenticated event owners; affects all booking page visitors. Patch status unknown. Restrict privileges. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T14:00:23.000Z ##

🟠 CVE-2026-57858 - High (8.9)

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracki...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T13:30:27.000Z ##

CVE-2026-57858: CRITICAL stored XSS in Cal.com Self-Hosted (v2.1.1 – 6.2.0). Exploited via BookingPageTagManager by authenticated event owners; affects all booking page visitors. Patch status unknown. Restrict privileges. radar.offseq.com/threat/cve-20 #OffSeq #XSS #SecOps

##

CVE-2026-48763
(8.2 HIGH)

EPSS: 0.31%

updated 2026-08-12T13:17:22.633000

1 posts

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned S3 `PUT` URL for that exact key. Because the endpoint only checks that the referenced typebot is public and that the referenced block is a file input bl

thehackerwire@mastodon.social at 2026-08-11T22:00:20.000Z ##

🟠 CVE-2026-48763 - High (8.2)

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19594
(8.1 HIGH)

EPSS: 0.40%

updated 2026-08-12T13:17:22.180000

2 posts

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `&`/`#`/`=` characters in query string values. An attacker with access to a downstream application bu

thehackerwire@mastodon.social at 2026-08-12T12:00:23.000Z ##

🟠 CVE-2026-19594 - High (8.1)

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T12:00:23.000Z ##

🟠 CVE-2026-19594 - High (8.1)

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19426
(8.2 HIGH)

EPSS: 0.30%

updated 2026-08-12T13:17:21.930000

2 posts

POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.

thehackerwire@mastodon.social at 2026-08-12T11:01:24.000Z ##

🟠 CVE-2026-19426 - High (8.2)

POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T11:01:24.000Z ##

🟠 CVE-2026-19426 - High (8.2)

POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67282(CVSS UNKNOWN)

EPSS: 0.57%

updated 2026-08-12T09:31:30

2 posts

Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.

offseq at 2026-08-12T12:00:27.314Z ##

CRITICAL: CVE-2026-67282 in Joomla Fabrik (v1.0.0 – 4.6.7) allows unauthenticated RCE (CWE-94). No patch yet — disable or restrict Fabrik use and monitor for updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-12T12:00:27.000Z ##

CRITICAL: CVE-2026-67282 in Joomla Fabrik (v1.0.0 – 4.6.7) allows unauthenticated RCE (CWE-94). No patch yet — disable or restrict Fabrik use and monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #Infosec #RCE #CVE202667282

##

CVE-2025-41770
(7.5 HIGH)

EPSS: 0.39%

updated 2026-08-12T09:31:30

4 posts

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.

thehackerwire@mastodon.social at 2026-08-12T11:01:45.000Z ##

🟠 CVE-2025-41770 - High (7.5)

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde at 2026-08-12T08:07:13.931Z ##

VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

##

thehackerwire@mastodon.social at 2026-08-12T11:01:45.000Z ##

🟠 CVE-2025-41770 - High (7.5)

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-08-12T08:07:13.000Z ##

#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2025-41771
(4.3 MEDIUM)

EPSS: 0.16%

updated 2026-08-12T09:31:30

2 posts

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.

certvde at 2026-08-12T08:07:13.931Z ##

VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-12T08:07:13.000Z ##

#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2025-41769
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-08-12T08:17:11.590000

6 posts

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

cR0w at 2026-08-12T14:19:11.037Z ##

BoF in a PROFINET service?! I'm shocked. Shocked! Well, not that shocked.

nvd.nist.gov/vuln/detail/CVE-2

##

thehackerwire@mastodon.social at 2026-08-12T11:01:35.000Z ##

🔴 CVE-2025-41769 - Critical (9.8)

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde at 2026-08-12T08:07:13.931Z ##

VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

##

cR0w@infosec.exchange at 2026-08-12T14:19:11.000Z ##

BoF in a PROFINET service?! I'm shocked. Shocked! Well, not that shocked.

nvd.nist.gov/vuln/detail/CVE-2

##

thehackerwire@mastodon.social at 2026-08-12T11:01:35.000Z ##

🔴 CVE-2025-41769 - Critical (9.8)

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-08-12T08:07:13.000Z ##

#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-64954
(8.2 HIGH)

EPSS: 0.23%

updated 2026-08-12T06:30:49

2 posts

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "inve

thehackerwire@mastodon.social at 2026-08-12T06:00:25.000Z ##

🟠 CVE-2026-64954 - High (8.2)

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the auth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T06:00:25.000Z ##

🟠 CVE-2026-64954 - High (8.2)

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the auth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66807
(7.8 HIGH)

EPSS: 0.36%

updated 2026-08-12T05:19:35.273000

1 posts

Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

hugovalters@mastodon.social at 2026-08-12T14:10:50.000Z ##

CVE-2026-66807 - High severity stack buffer overflow in Microsoft Office. Local code execution risk. CVSS 7.8. Patch reported—update immediately. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-668

##

CVE-2026-62747
(7.8 HIGH)

EPSS: 0.32%

updated 2026-08-12T05:18:29.177000

1 posts

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

hugovalters@mastodon.social at 2026-08-12T17:10:00.000Z ##

CVE-2026-62747 - Heap buffer overflow in Windows Device Association Service. Local privilege escalation. CVSS 7.8. Patch reported—update immediately. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-627

##

CVE-2026-58231
(10.0 CRITICAL)

EPSS: 0.73%

updated 2026-08-12T05:17:56.963000

5 posts

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

jbhall56 at 2026-08-12T12:15:46.790Z ##

The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. thehackernews.com/2026/08/sap-

##

undercodenews@mastodon.social at 2026-08-12T08:29:46.000Z ##

SAP Issues Emergency-Grade Patch for CVSS 100 Commerce Cloud Flaw That Could Enable Unauthenticated Code Execution + Video

A Critical Warning for SAP Enterprise Customers A maximum-severity vulnerability in SAP Commerce Cloud has put enterprise e-commerce environments under renewed security pressure. The newly identified flaw, tracked as CVE-2026-58231, carries the highest possible CVSS score of 10.0 and could allow an unauthenticated attacker to execute arbitrary code…

undercodenews.com/sap-issues-e

##

beyondmachines1 at 2026-08-12T08:01:15.265Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**

beyondmachines.net/event_detai

##

jbhall56@infosec.exchange at 2026-08-12T12:15:46.000Z ##

The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. thehackernews.com/2026/08/sap-

##

beyondmachines1@infosec.exchange at 2026-08-12T08:01:15.000Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-53413
(8.3 HIGH)

EPSS: 0.41%

updated 2026-08-12T05:17:55.123000

1 posts

Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.

1 repos

https://github.com/HORKimhab/CVE-2026-53413

571906@ap.podcastindex.org at 2026-08-12T02:00:02.000Z ##

New Episode: SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

Shownotes:

Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

CVE-2026-18129
(8.1 HIGH)

EPSS: 0.87%

updated 2026-08-12T05:17:42.950000

2 posts

Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.

jbhall56 at 2026-08-12T12:52:08.597Z ##

Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. securityweek.com/ivanti-epm-up

##

jbhall56@infosec.exchange at 2026-08-12T12:52:08.000Z ##

Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. securityweek.com/ivanti-epm-up

##

CVE-2026-6484
(8.2 HIGH)

EPSS: 0.14%

updated 2026-08-12T03:31:23

1 posts

In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-12T01:59:50.000Z ##

🟠 CVE-2026-6484 - High (8.2)

In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72526
(9.9 CRITICAL)

EPSS: 0.30%

updated 2026-08-12T03:31:18

4 posts

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attac

offseq at 2026-08-12T04:30:27.162Z ##

CVE-2026-72526 (CRITICAL, CVSS 9.9) in Red Hat Advanced Cluster Management for Kubernetes 2 lets low-priv hub users escalate to cluster-admin on managed clusters. No official fix. Restrict Application creation permissions now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T04:00:39.000Z ##

🔴 CVE-2026-72526 - Critical (9.9)

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to creat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T04:30:27.000Z ##

CVE-2026-72526 (CRITICAL, CVSS 9.9) in Red Hat Advanced Cluster Management for Kubernetes 2 lets low-priv hub users escalate to cluster-admin on managed clusters. No official fix. Restrict Application creation permissions now. radar.offseq.com/threat/cve-20 #OffSeq #RedHat #Kubernetes #CVE2026_72526

##

thehackerwire@mastodon.social at 2026-08-12T04:00:39.000Z ##

🔴 CVE-2026-72526 - Critical (9.9)

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to creat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66878
(7.7 HIGH)

EPSS: 0.21%

updated 2026-08-12T02:16:37.937000

2 posts

A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure.

thehackerwire@mastodon.social at 2026-08-12T12:00:33.000Z ##

🟠 CVE-2026-66878 - High (7.7)

A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Nam...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T12:00:33.000Z ##

🟠 CVE-2026-66878 - High (7.7)

A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Nam...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68067
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-08-12T00:31:23

2 posts

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.

offseq@infosec.exchange at 2026-08-12T01:30:25.000Z ##

Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE202668067

##

thehackerwire@mastodon.social at 2026-08-12T00:01:04.000Z ##

🔴 CVE-2026-68067 - Critical (9.8)

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66875
(8.8 HIGH)

EPSS: 0.24%

updated 2026-08-12T00:31:23

1 posts

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address

thehackerwire@mastodon.social at 2026-08-12T00:01:15.000Z ##

🟠 CVE-2026-66875 - High (8.8)

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73246
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-11T22:19:05.287000

1 posts

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, which can expose commands, environment variables, HTTP headers, connection details, plaintext credentials, and execution identifiers while the main API o

thehackerwire@mastodon.social at 2026-08-12T00:00:02.000Z ##

🟠 CVE-2026-73246 - High (7.5)

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19579
(5.4 MEDIUM)

EPSS: 0.24%

updated 2026-08-11T22:17:21.750000

2 posts

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ow

AAKL at 2026-08-12T15:58:29.092Z ##

Broadcom has a new advisory for five vulnerabilities, two of them critical support.broadcom.com/web/ecx/s

Posted yesterday:

Tenable Research advisories: CVE-2026-19579: Snipe-IT Checkout Request Cancellation IDOR tenable.com/security/research/ @tenable $infosec

##

AAKL@infosec.exchange at 2026-08-12T15:58:29.000Z ##

Broadcom has a new advisory for five vulnerabilities, two of them critical support.broadcom.com/web/ecx/s #Broadcom

Posted yesterday:

Tenable Research advisories: CVE-2026-19579: Snipe-IT Checkout Request Cancellation IDOR tenable.com/security/research/ @tenable $infosec #vulnerability

##

CVE-2026-73282
(4.8 MEDIUM)

EPSS: 0.16%

updated 2026-08-11T21:33:18

2 posts

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

CVE-2026-18690
(8.1 HIGH)

EPSS: 0.26%

updated 2026-08-11T21:33:12

1 posts

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization.

sayzard@mastodon.sayzard.org at 2026-08-12T19:43:56.000Z ##

A BSON symbol namespace bypasses MongoDB's authorization check (CVE-2026-18690)

MongoDB Server의 CVE-2026-18690은 BSON Symbol 타입으로 컬렉션 이름을 전달할 때, 인가 단계는 데이터베이스 수준 권한을 검사하지만 실행 단계는 실제 system.* 컬렉션을 대상으로 처리하는 권한 우회 취약점이다. 제한된 database-scoped 역할을 가진 인증된 사용자가 보호된 시스템 컬렉션에 대해 파괴적 작업을 시도할 수 있으며, MongoDB 7.0.40·8.0.29·8.3.8에서 수정됐다. 같은 패치 묶음에는 복제본 세트 내부 인증 메커니즘 다운그레이드로 내부...

hellorecon.com/blog/cve-2026-1

##

CVE-2026-20349
(8.6 HIGH)

EPSS: 0.87%

updated 2026-08-11T21:32:37

18 posts

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.&nbsp; This vulnerability is due to insufficient error checking when processing

cyberworldops at 2026-08-12T18:10:01.045Z ##

Cisco confirmed active exploitation of CVE-2026-20349, a high-severity flaw (CVSS 8.6) in ASA and FTD firewalls. Insufficient error handling in HTTP processing allows an unauthenticated remote attacker to trigger a device reboot via the Remote Access SSL VPN service, resulting in denial of service.

cyberworldops.eu/en/cisco-asa-

##

netsecio@mastodon.social at 2026-08-12T15:06:39.000Z ##

📰 Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Cisco patches an actively exploited zero-day (CVE-2026-20349) in ASA and FTD firewalls. The flaw allows a remote, unauthenticated attacker to cause a denial-of-service (DoS). Patch immediately to prevent network disruption. #Cisco #ZeroDay #CyberSecu...

🔗 cyber.netsecops.io/articles/ci

##

jbhall56 at 2026-08-12T12:57:51.990Z ##

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. securityweek.com/cisco-patches

##

Matchbook3469@mastodon.social at 2026-08-12T11:00:57.000Z ##

⚠️ New security advisory:

CVE-2026-20349 affects multiple systems.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#CVE #ZeroDay #ThreatIntel

##

Analyst207@mastodon.social at 2026-08-12T08:04:38.000Z ##

Cisco ASA and FTD Flaw Exploited in Wild, Triggers Remote DoS

A high-severity vulnerability in Cisco Secure Firewall ASA and FTD software, known as CVE-2026-20349, is being actively exploited in the wild, allowing attackers to trigger a remote denial-of-service condition with a simple crafted HTTP request. This flaw, with a CVSS score of 8.6, can cause affected devices to reload, leaving networks…

osintsights.com/cisco-asa-and-

#CiscoAsa #Ftd #Cve202620349 #RemoteDos #VulnerabilityExploitation

##

thecybermind at 2026-08-12T07:44:11.997Z ##

🚨 THREAT ALERT: CISA adds CVE-2026-20349 (Cisco ASA/FTD Heap Inspection DoS) to the KEV catalog due to active exploitation. Unauthenticated remote actors can crash perimeter firewalls. Read our full TSUITE brief with SPL, KQL, AQL & Chronicle queries: thecybermind.co/jily

##

undercodenews@mastodon.social at 2026-08-12T06:59:20.000Z ##

Cisco Firewalls Under Pressure: CVE-2026-20349 Exposes a Dangerous Zero-Day Risk While Sandworm-Linked Hackers Weaponize Fake IT Jobs + Video

Introduction: Two Different Attacks, One Bigger Warning Cybersecurity defenders are facing a familiar but increasingly dangerous pattern: attackers do not need to break through every security control if they can find one exposed edge device or convince one trusted employee to install the wrong software. On August 12, 2026, two…

undercodenews.com/cisco-firewa

##

undercodenews@mastodon.social at 2026-08-12T06:58:48.000Z ##

Cisco Secure Firewall Under Active Attack: High-Severity CVE-2026-20349 Puts ASA and FTD Devices on Immediate Patch Alert + Video

A New Warning Has Turned a Firewall Bug Into an Active Security Emergency A firewall is supposed to be the wall between an organization and the hostile internet. When that wall can be forced to restart remotely, without authentication, the problem is no longer a theoretical weakness hidden inside a security scanner. It becomes an operational…

undercodenews.com/cisco-secure

##

ottoto2017@prattohome.com at 2026-08-12T05:39:38.000Z ##

「Ciscoは、ASAおよびFTD VPNの脆弱性が悪用され、デバイスがクラッシュする可能性があると警告している。 」: #BLEEPINGCOMPUTER

「シスコは、Secure Firewall ASAおよびThreat Defense(FTD)ソフトウェアに存在する深刻なサービス拒否攻撃の脆弱性が、影響を受けるデバイスをリモートからクラッシュさせる攻撃で積極的に悪用されていると警告している。

CVE-2026-20349として追跡されているこの脆弱性は、深刻度スコアが8.6であり、特定のリモートアクセスサービスが有効になっているCisco Secure Firewall Adaptive Security Appliance(ASA)またはSecure Firewall Threat Defense(FTD)ソフトウェアを実行しているデバイスに影響を与えます。

シスコは本日公開したセキュリティ勧告の中で、この脆弱性はHTTPリクエスト処理時のエラーチェックが不十分なことに起因すると述べた。 」

bleepingcomputer.com/news/secu

#prattohome

##

cyberworldops@infosec.exchange at 2026-08-12T18:10:01.000Z ##

Cisco confirmed active exploitation of CVE-2026-20349, a high-severity flaw (CVSS 8.6) in ASA and FTD firewalls. Insufficient error handling in HTTP processing allows an unauthenticated remote attacker to trigger a device reboot via the Remote Access SSL VPN service, resulting in denial of service.

#CVE202620349 #CiscoASA #FirewallSecurity #DenialOfService

cyberworldops.eu/en/cisco-asa-

##

jbhall56@infosec.exchange at 2026-08-12T12:57:51.000Z ##

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. securityweek.com/cisco-patches

##

thecybermind@infosec.exchange at 2026-08-12T07:44:11.000Z ##

🚨 THREAT ALERT: CISA adds CVE-2026-20349 (Cisco ASA/FTD Heap Inspection DoS) to the KEV catalog due to active exploitation. Unauthenticated remote actors can crash perimeter firewalls. Read our full TSUITE brief with SPL, KQL, AQL & Chronicle queries: thecybermind.co/jily

#CyberSecurity

##

ottoto2017@prattohome.com at 2026-08-12T05:39:38.000Z ##

「Ciscoは、ASAおよびFTD VPNの脆弱性が悪用され、デバイスがクラッシュする可能性があると警告している。 」: #BLEEPINGCOMPUTER

「シスコは、Secure Firewall ASAおよびThreat Defense(FTD)ソフトウェアに存在する深刻なサービス拒否攻撃の脆弱性が、影響を受けるデバイスをリモートからクラッシュさせる攻撃で積極的に悪用されていると警告している。

CVE-2026-20349として追跡されているこの脆弱性は、深刻度スコアが8.6であり、特定のリモートアクセスサービスが有効になっているCisco Secure Firewall Adaptive Security Appliance(ASA)またはSecure Firewall Threat Defense(FTD)ソフトウェアを実行しているデバイスに影響を与えます。

シスコは本日公開したセキュリティ勧告の中で、この脆弱性はHTTPリクエスト処理時のエラーチェックが不十分なことに起因すると述べた。 」

bleepingcomputer.com/news/secu

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T00:37:09.000Z ##

Cisco confirms CVE-2026-20349, a Cisco ASA and FTD VPN vulnerability (CVSS 8.6), is exploited in the wild to crash firewalls. Patch now.

#Cisco #CVE #DoS #FirewallSecurity #VPN #InfoSec

securityonline.info/cisco-asa-

##

secdb@infosec.exchange at 2026-08-11T21:00:13.000Z ##

🚨 [CISA-2026:0811] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20349 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-68820 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows Ancillary Function Driver for WinSock
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72898 (secdb.nttzen.cloud/cve/detail/)
- Name: Metabase SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Metabase
- Product: Metabase
- Notes: metabase.com/blog/security-upd ; github.com/metabase/metabase/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260811 #cisa20260811 #cve_2026_20349 #cve_2026_68820 #cve_2026_72898 #cve202620349 #cve202668820 #cve202672898

##

Xavier@infosec.exchange at 2026-08-11T20:18:44.000Z ##

This is being actively exploited. CVE-2026-20349. Patch now. Like right now. #infosec #vpn #cisco #cve
bleepingcomputer.com/news/secu

##

cisakevtracker@mastodon.social at 2026-08-11T20:00:49.000Z ##

CVE ID: CVE-2026-20349
Vendor: Cisco
Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
Date Added: 2026-08-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-08-11T17:11:08.000Z ##

Broadcom has several new advisories that include two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

CISA:

Industrial vulnerability: Johnson Controls C-CURE 9000 and Victor application server (Update A) cisa.gov/news-events/ics-advis

Blog post: Cyber Storm X: 20 Years of Readiness, Resilience, and Real‑World Impact cisa.gov/news-events/news/cybe #CISA

Cisco:

High-severity: CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

Yesterday:

Tenable Research Advisories:

Medium-severity: CVE-2026-12879: Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy tenable.com/security/research/ #infosec #Google #vulnerability

##

CVE-2026-73283
(2.5 LOW)

EPSS: 0.08%

updated 2026-08-11T21:17:53.413000

2 posts

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

CVE-2026-73281
(3.5 LOW)

EPSS: 0.16%

updated 2026-08-11T21:17:52.563000

2 posts

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

CVE-2026-18687
(7.1 HIGH)

EPSS: 0.17%

updated 2026-08-11T21:17:31.273000

1 posts

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypte

hugovalters@mastodon.social at 2026-08-13T14:13:46.000Z ##

CVE-2026-18687 - High severity DoS in MongoDB Queryable Encryption. Flawed validation lets authenticated users crash servers or corrupt encrypted indexes via crafted requests. CVSS 7.1. Unpatched—restrict access and monitor. #CVE #MongoDB #infosec

valtersit.com/cve/CVE-2026-186

##

CVE-2026-73226
(8.8 HIGH)

EPSS: 0.39%

updated 2026-08-11T20:18:48.007000

1 posts

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade-func in src/app/server/dispatch-center.js and handleFs in src/app/server/fs.js, exposing Upgrade and fsExport methods that can execute commands, open fi

thehackerwire@mastodon.social at 2026-08-11T20:00:34.000Z ##

🟠 CVE-2026-73226 - High (8.8)

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72971
(5.5 MEDIUM)

EPSS: 0.36%

updated 2026-08-11T20:18:46.067000

1 posts

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

CapTechGroup@mastodon.social at 2026-08-12T12:51:38.000Z ##

Microsoft's newest patch cycle closes nearly 400 security holes, among them CVE-2026-62832, CVE-2026-68820, and CVE-2026-72971. That volume makes triage the hard part, so plan which systems get updated first and confirm the rollout...

captechgroup.com/threat-intell

##

CVE-2021-44228
(10.0 CRITICAL)

EPSS: 100.00%

updated 2026-08-11T19:33:44.513000

1 posts

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is en

Nuclei template

100 repos

https://github.com/logpresso/CVE-2021-44228-Scanner

https://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit

https://github.com/kubearmor/log4j-CVE-2021-44228

https://github.com/future-client/CVE-2021-44228

https://github.com/fullhunt/log4j-scan

https://github.com/giterlizzi/nmap-log4shell

https://github.com/dtact/divd-2021-00038--log4j-scanner

https://github.com/fox-it/log4j-finder

https://github.com/corelight/cve-2021-44228

https://github.com/stripe/log4j-remediation-tools

https://github.com/BinaryDefense/log4j-honeypot-flask

https://github.com/pedrohavay/exploit-CVE-2021-44228

https://github.com/mzlogin/CVE-2021-44228-Demo

https://github.com/Jeromeyoung/log4j2burpscanner

https://github.com/Nanitor/log4fix

https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce

https://github.com/toramanemre/log4j-rce-detect-waf-bypass

https://github.com/bigsizeme/Log4j-check

https://github.com/CodeShield-Security/Log4JShell-Bytecode-Detector

https://github.com/1lann/log4shelldetect

https://github.com/Diverto/nse-log4shell

https://github.com/tippexs/nginx-njs-waf-cve2021-44228

https://github.com/momos1337/Log4j-RCE

https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept

https://github.com/back2root/log4shell-rex

https://github.com/redhuntlabs/Log4JHunt

https://github.com/sec13b/CVE-2021-44228-POC

https://github.com/Kadantte/CVE-2021-44228-poc

https://github.com/justakazh/Log4j-CVE-2021-44228

https://github.com/cyberxml/log4j-poc

https://github.com/darkarnium/Log4j-CVE-Detect

https://github.com/NorthwaveSecurity/log4jcheck

https://github.com/puzzlepeaches/Log4jHorizon

https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator

https://github.com/greymd/CVE-2021-44228

https://github.com/Adikso/minecraft-log4j-honeypot

https://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228

https://github.com/Labout/log4shell-rmi-poc

https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes

https://github.com/MalwareTech/Log4jTools

https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228

https://github.com/DragonSurvivalEU/RCE

https://github.com/mr-r3b00t/CVE-2021-44228

https://github.com/AlexandreHeroux/Fix-CVE-2021-44228

https://github.com/claranet/ansible-role-log4shell

https://github.com/rubo77/log4j_checker_beta

https://github.com/infiniroot/nginx-mitigate-log4shell

https://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab

https://github.com/blake-fm/vcenter-log4j

https://github.com/thecyberneh/Log4j-RCE-Exploiter

https://github.com/NS-Sp4ce/Vm4J

https://github.com/puzzlepeaches/Log4jUnifi

https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words

https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228

https://github.com/puzzlepeaches/Log4jCenter

https://github.com/CERTCC/CVE-2021-44228_scanner

https://github.com/f0ng/log4j2burpscanner

https://github.com/takito1812/log4j-detect

https://github.com/KosmX/CVE-2021-44228-example

https://github.com/hackinghippo/log4shell_ioc_ips

https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes

https://github.com/lfama/log4j_checker

https://github.com/thomaspatzke/Log4Pot

https://github.com/marcourbano/CVE-2021-44228

https://github.com/fireeye/CVE-2021-44228

https://github.com/roxas-tan/CVE-2021-44228

https://github.com/sunnyvale-it/CVE-2021-44228-PoC

https://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228

https://github.com/boundaryx/cloudrasp-log4j2

https://github.com/HynekPetrak/log4shell-finder

https://github.com/cisagov/log4j-scanner

https://github.com/mufeedvh/log4jail

https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs

https://github.com/jas502n/Log4j2-CVE-2021-44228

https://github.com/CreeperHost/Log4jPatcher

https://github.com/mergebase/log4j-detector

https://github.com/ssl/scan4log4j

https://github.com/wortell/log4j

https://github.com/yahoo/check-log4j

https://github.com/dwisiswant0/look4jar

https://github.com/LiveOverflow/log4shell

https://github.com/0xInfection/LogMePwn

https://github.com/0xDexter0us/Log4J-Scanner

https://github.com/leonjza/log4jpwn

https://github.com/lucab85/log4j-cve-2021-44228

https://github.com/kozmer/log4j-shell-poc

https://github.com/qingtengyun/cve-2021-44228-qingteng-online-patch

https://github.com/nu11secur1ty/CVE-2021-44228-VULN-APP

https://github.com/simonis/Log4jPatch

https://github.com/qingtengyun/cve-2021-44228-qingteng-patch

https://github.com/alexbakker/log4shell-tools

https://github.com/alexandre-lavoie/python-log4rce

https://github.com/nccgroup/log4j-jndi-be-gone

https://github.com/christophetd/log4shell-vulnerable-app

https://github.com/mr-vill4in/log4j-fuzzer

https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloads

https://github.com/NCSC-NL/log4shell

https://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell

https://github.com/corretto/hotpatch-for-apache-log4j2

https://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent

cvedatabase@techhub.social at 2026-08-12T10:30:03.000Z ##

Securing your software supply chain shouldn't be manual work. 🤖 Our latest tutorial dives deep into automating dependency scanning within your CI/CD pipelines to block vulnerabilities like CVE-2021-44228. Elevate your DevSecOps game today! cvedatabase.com/blog/automatin #SCA #DevSecOps #CICD #InfoSec #CyberSecurity #Automation

##

CVE-2026-73069
(9.1 CRITICAL)

EPSS: 0.36%

updated 2026-08-11T19:18:49.750000

1 posts

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through PATCH /rest/metadata/fields/:id or the updateOneField GraphQL mutation, causing buildSqlColumnDefinition in packages/twenty-server/src/engine/twenty-orm/

thehackerwire@mastodon.social at 2026-08-11T17:00:46.000Z ##

🔴 CVE-2026-73069 - Critical (9.1)

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20338
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-11T18:54:19.877000

2 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to

ottoto2017@prattohome.com at 2026-08-12T05:43:02.000Z ##

「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER

「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。

これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。

シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」

bleepingcomputer.com/news/secu

#prattohome

##

ottoto2017@prattohome.com at 2026-08-12T05:43:02.000Z ##

「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER

「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。

これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。

シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」

bleepingcomputer.com/news/secu

#prattohome

##

CVE-2026-62901
(7.5 HIGH)

EPSS: 1.08%

updated 2026-08-11T18:53:58

1 posts

## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.WebSockets. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. ## Announcement Announceme

us@newsbeep.org at 2026-08-11T23:40:13.000Z ##

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Tag
CVE ID
CVE Title
Severity
.NET
CVE-2026-58641
.NET Elevation of Privilege Vulnerability
Important
.NET
CVE-2026-62901
.NET Denial…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Technology
newsbeep.com/us/810540/

##

CVE-2026-71398
(10.0 CRITICAL)

EPSS: 0.64%

updated 2026-08-11T18:32:06

2 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

CVE-2026-71362
(9.1 CRITICAL)

EPSS: 0.48%

updated 2026-08-11T18:32:00

9 posts

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

ottoto2017@prattohome.com at 2026-08-13T07:06:11.000Z ##

「ハッカーがAdobe Commerceの重大な脆弱性を悪用し、顧客アカウントを乗っ取る 」: #BLEEPINGCOMPUTER

「AdobeのeコマースプラットフォームであるCommerceとMagentoにおける重大な脆弱性(CVE-2026-71362)を悪用しようとする試みが検出されました。この脆弱性により、攻撃者が顧客アカウントを乗っ取る可能性があります。

この脆弱性は、認証なしに「機密性の高いリソースへの上位アクセス権を取得する」ために悪用される可能性のある、誤った認証の脆弱性と説明されており、Adobeが昨日のセキュリティアップデートで対処した7つの問題のうちの1つです。

ソフトウェアベンダーは 勧告 の中で、修正された脆弱性に対する実際の攻撃事例は把握していないと述べているが、eコマースセキュリティ企業のSansecは、同社のShieldウェブアプリケーションファイアウォール(WAF)が既にCVE-2026-71362の悪用を阻止していると述べている。 」

bleepingcomputer.com/news/secu

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

cyberworldops at 2026-08-12T22:10:00.532Z ##

Active exploitation attempts targeting CVE-2026-71362 have been observed since August 12, 2026, affecting Adobe Commerce and Magento installations. The flaw is an authorization bypass that grants unauthenticated access to sensitive resources due to incorrect identity handling.

cyberworldops.eu/en/adobe-comm

##

oversecurity@mastodon.social at 2026-08-12T21:30:32.000Z ##

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially...

🔗️ [Bleepingcomputer] link.is.it/JJqIH9

##

Analyst207@mastodon.social at 2026-08-12T21:01:42.000Z ##

Hackers Exploit Adobe Commerce Flaw to Hijack Customer Accounts

Hackers can hijack your customer accounts with just a few clicks, thanks to a critical flaw in Adobe Commerce that lets attackers switch to another customer's session, gaining access to sensitive data. This vulnerability, tracked as CVE-2026-71362, is a wake-up call for businesses to take immediate action and protect…

osintsights.com/hackers-exploi

#AdobeCommerce #Cve202671362 #SessionHijacking #CustomerDataBreach #EcommerceSecurity

##

ottoto2017@prattohome.com at 2026-08-13T07:06:11.000Z ##

「ハッカーがAdobe Commerceの重大な脆弱性を悪用し、顧客アカウントを乗っ取る 」: #BLEEPINGCOMPUTER

「AdobeのeコマースプラットフォームであるCommerceとMagentoにおける重大な脆弱性(CVE-2026-71362)を悪用しようとする試みが検出されました。この脆弱性により、攻撃者が顧客アカウントを乗っ取る可能性があります。

この脆弱性は、認証なしに「機密性の高いリソースへの上位アクセス権を取得する」ために悪用される可能性のある、誤った認証の脆弱性と説明されており、Adobeが昨日のセキュリティアップデートで対処した7つの問題のうちの1つです。

ソフトウェアベンダーは 勧告 の中で、修正された脆弱性に対する実際の攻撃事例は把握していないと述べているが、eコマースセキュリティ企業のSansecは、同社のShieldウェブアプリケーションファイアウォール(WAF)が既にCVE-2026-71362の悪用を阻止していると述べている。 」

bleepingcomputer.com/news/secu

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

cyberworldops@infosec.exchange at 2026-08-12T22:10:00.000Z ##

Active exploitation attempts targeting CVE-2026-71362 have been observed since August 12, 2026, affecting Adobe Commerce and Magento installations. The flaw is an authorization bypass that grants unauthenticated access to sensitive resources due to incorrect identity handling.

#CVE202671362 #AdobeCommerce #Magento #AuthorizationBypass

cyberworldops.eu/en/adobe-comm

##

oversecurity@mastodon.social at 2026-08-12T21:30:32.000Z ##

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially...

🔗️ [Bleepingcomputer] link.is.it/JJqIH9

##

CVE-2026-48381
(9.0 None)

EPSS: 0.48%

updated 2026-08-11T18:32:00

2 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not req

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

CVE-2026-27302
(10.0 CRITICAL)

EPSS: 0.57%

updated 2026-08-11T18:32:00

2 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

CVE-2026-71384
(9.6 CRITICAL)

EPSS: 0.24%

updated 2026-08-11T18:31:59

2 posts

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this is

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

CVE-2026-66804
(7.8 HIGH)

EPSS: 3.03%

updated 2026-08-11T18:31:49

3 posts

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/Rat5ak/CVE-2026-66804-CrossDevice-Service-EoP

https://github.com/DavidCarliez/CVE-2026-66804-CrossDevice-LPE

Nadsec@cyberplace.social at 2026-08-13T04:26:52.000Z ##

CVE-2026-66804 - Windows Cross Device Service LPE - Writeup & PoC

Found another cool one!
nadsec.online/blog/cve-2026-66

Not sure who found it first, but shoutout to them. Despite not being FTF, my mom thinks this one is cool, which is the only important metric 😎

##

Nadsec@cyberplace.social at 2026-08-13T02:25:32.000Z ##

@wdormann
CVE-2026-66804

Haha it’s a good one. And yeah not these days, I had thought I might have atleast been first to find but not quite 🤣

##

Nadsec@cyberplace.social at 2026-08-13T02:25:32.000Z ##

@wdormann
CVE-2026-66804

Haha it’s a good one. And yeah not these days, I had thought I might have atleast been first to find but not quite 🤣

##

CVE-2026-62832
(7.8 HIGH)

EPSS: 2.39%

updated 2026-08-11T18:31:33

2 posts

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

CapTechGroup@mastodon.social at 2026-08-12T12:51:38.000Z ##

Microsoft's newest patch cycle closes nearly 400 security holes, among them CVE-2026-62832, CVE-2026-68820, and CVE-2026-72971. That volume makes triage the hard part, so plan which systems get updated first and confirm the rollout...

captechgroup.com/threat-intell

##

sayzard@mastodon.sayzard.org at 2026-08-12T03:43:20.000Z ##

Microsoft Plugs Nearly 400 Security Holes

Microsoft가 8월 Patch Tuesday에서 Windows 및 지원 소프트웨어의 취약점 최소 398건을 수정했으며, 이 중 42건은 원격 코드 실행 등으로 이어질 수 있는 Critical 등급이다. 이미 악용 중인 CVE-2026-68820은 거의 모든 Windows 엔드포인트의 소켓 연결에 관여하는 afd.sys의 권한 상승 취약점으로, 초기 침투 후 시스템 장악 체인에 사용될 수 있다. 또한 Windows User Profile Service의 CVE-2026-62832는 공개된 LegacyHive 이슈와 연관 가능성이 있으며 악용 가능성이 높은 것으로...

krebsonsecurity.com/2026/08/mi

##

CVE-2026-61353
(7.8 HIGH)

EPSS: 0.32%

updated 2026-08-11T18:31:13

1 posts

Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

hugovalters@mastodon.social at 2026-08-12T15:12:11.000Z ##

CVE-2026-61353 - Heap buffer overflow in Windows Telephony Service. Local privilege escalation. CVSS 7.8. Patch reported, apply immediately. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-613

##

CVE-2026-58641
(7.8 HIGH)

EPSS: 0.40%

updated 2026-08-11T18:31:08

1 posts

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

us@newsbeep.org at 2026-08-11T23:40:13.000Z ##

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Tag
CVE ID
CVE Title
Severity
.NET
CVE-2026-58641
.NET Elevation of Privilege Vulnerability
Important
.NET
CVE-2026-62901
.NET Denial…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Technology
newsbeep.com/us/810540/

##

CVE-2026-59124
(9.8 CRITICAL)

EPSS: 1.72%

updated 2026-08-11T18:31:01

2 posts

Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

adulau at 2026-08-12T15:34:19.857Z ##

vulnerability-lookup 6.0 will be released this week with many (really, many!) new features.

One of the smaller, but important, additions is support for multiple SSVC views alongside CVSS. When SSVC information is available from an ADP (such as CISA) , or from additional sources such as GCVE, it is now displayed by default.

This allows users to more easily compare the different severity and prioritization assessments associated with a vulnerability.

The CIRCL vulnerability-lookup instance is running the pre-release of 6.0 -
vulnerability.circl.lu/vuln/cv

@gcve
@circl

##

adulau@infosec.exchange at 2026-08-12T15:34:19.000Z ##

vulnerability-lookup 6.0 will be released this week with many (really, many!) new features.

One of the smaller, but important, additions is support for multiple SSVC views alongside CVSS. When SSVC information is available from an ADP (such as CISA) , or from additional sources such as GCVE, it is now displayed by default.

This allows users to more easily compare the different severity and prioritization assessments associated with a vulnerability.

The CIRCL vulnerability-lookup instance is running the pre-release of 6.0 -
vulnerability.circl.lu/vuln/cv

#cve #gcve #opensource #vulnerabilitylookup #opendata #vulnerabilitymanagement #cyberecurity #ssvc

@gcve
@circl

##

CVE-2026-48362
(10.0 CRITICAL)

EPSS: 2.07%

updated 2026-08-11T18:30:56

2 posts

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

CVE-2026-53414
(6.5 MEDIUM)

EPSS: 0.28%

updated 2026-08-11T18:30:54

1 posts

Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.

571906@ap.podcastindex.org at 2026-08-12T02:00:02.000Z ##

New Episode: SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

Shownotes:

Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

CVE-2026-53415
(8.3 HIGH)

EPSS: 0.39%

updated 2026-08-11T18:30:54

1 posts

Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.

571906@ap.podcastindex.org at 2026-08-12T02:00:02.000Z ##

New Episode: SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

Shownotes:

Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

CVE-2026-67180
(8.4 HIGH)

EPSS: 0.17%

updated 2026-08-11T18:30:53

1 posts

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.

thehackerwire@mastodon.social at 2026-08-11T17:01:35.000Z ##

🟠 CVE-2026-67180 - High (8.4)

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56721
(8.8 HIGH)

EPSS: 0.36%

updated 2026-08-11T18:17:37.757000

2 posts

CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the authorization filter and action body in the UsersController. Attackers can send a PATCH request to the updated_ajax endpoint setting

hugovalters@mastodon.social at 2026-08-12T12:04:36.000Z ##

CVE-2026-56721 - Privilege escalation in CamaleonCMS ≤2.9.2 via IDOR. Authenticated low-priv users can overwrite any credentials. CVSS 8.8. Unpatched - update immediately. #CVE #CamaleonCMS #infosec

valtersit.com/cve/CVE-2026-567

##

thehackerwire@mastodon.social at 2026-08-11T17:01:48.000Z ##

🟠 CVE-2026-56721 - High (8.8)

CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73079
(8.5 HIGH)

EPSS: 0.31%

updated 2026-08-11T17:19:15.747000

1 posts

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts (ChatGPT/Codex OAuth, OpenAI platform keys, or an operator-configured base URL) that belong to the operator, not to the caller. The `POST /responses/*sub

thehackerwire@mastodon.social at 2026-08-11T17:00:18.000Z ##

🟠 CVE-2026-73079 - High (8.5)

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67179
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-11T16:17:34.113000

1 posts

Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.

thehackerwire@mastodon.social at 2026-08-11T17:01:23.000Z ##

🟠 CVE-2026-67179 - High (7.8)

Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registere...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73080
(9.3 CRITICAL)

EPSS: 0.38%

updated 2026-08-11T15:58:24

1 posts

### Impact `VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote endpoint and writes the response into a needle. Before 4.24 this RPC performed no authentication and no validation of the target, so anyone able to reach a volume server's gRPC port could coerce the server into issuing requests to arbitrary hosts — including loopback, link-local, RFC 1918, and cloud metadata endpoints s

thehackerwire@mastodon.social at 2026-08-11T17:00:34.000Z ##

🔴 CVE-2026-73080 - Critical (9.3)

SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72922
(8.2 HIGH)

EPSS: 0.27%

updated 2026-08-11T15:17:38.350000

1 posts

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected get_webhook_manager(provider) from the untrusted provider URL segment without verifying webhook.provider, allowing a request to /compass/webho

thehackerwire@mastodon.social at 2026-08-11T16:01:34.000Z ##

🟠 CVE-2026-72922 - High (8.2)

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic rout...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72921
(8.1 HIGH)

EPSS: 0.24%

updated 2026-08-11T15:17:38.217000

1 posts

SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, enabling cross-tenant reads and writes with a valid scoped token. This issue is fixed in version 4.24

thehackerwire@mastodon.social at 2026-08-11T16:01:19.000Z ##

🟠 CVE-2026-72921 - High (8.1)

SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths suc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72914
(7.5 HIGH)

EPSS: 0.45%

updated 2026-08-11T14:17:15.200000

2 posts

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionController checked authorization only after beginning expensive calculations. Anonymous callers could submit keys, start_at, and end_at parameters that caused

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

CVE-2026-46670
(9.8 CRITICAL)

EPSS: 1.65%

updated 2026-08-11T14:17:13.863000

1 posts

YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue.

Nuclei template

Matchbook3469@mastodon.social at 2026-08-12T08:02:20.000Z ##

🔴 New security advisory:

CVE-2026-46670 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #SecurityPatching #HackerNews

##

CVE-2026-19418(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-08-11T09:32:42

1 posts

The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory. Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory

hugovalters@mastodon.social at 2026-08-12T17:53:02.000Z ##

About 52 of your CVEs were missing from our OSV.dev cache, which we use as an independent confirmation source. OSV has them now; they just hadn't synced into our local DB yet.

What we fixed today:

Fixed the version range parser in our consolidator to correctly detect TYPO3's format
Re-synced all 99 TYPO3 CVEs against OSV.dev
Result: 73 now show as PATCHED / FIX AVAILABLE, 25 as PATCH UNDER REVIEW (awaiting OSV confirmation), 1 brand new (yesterday's CVE-2026-19418)

##

CVE-2026-8917(CVSS UNKNOWN)

EPSS: 0.11%

updated 2026-08-11T03:31:59

1 posts

Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation. Refer to the '  Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin   ' section on the ASUS Security Advisory fo

AAKL@infosec.exchange at 2026-08-11T19:02:36.000Z ##

Asus posted an advisory today. Scroll down for the full list:

CVE-2026-8917: Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin asus.com/security-advisory/

PC Gamer: It's time to update Asus Armoury Crate and several other Asus software tools again, as another high severity security vulnerability has been discovered pcgamer.com/software/security/ #infosec #vulnerability #Asus

##

CVE-2026-34265
(9.8 CRITICAL)

EPSS: 0.44%

updated 2026-08-11T03:31:57

2 posts

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.

beyondmachines1 at 2026-08-12T08:01:15.265Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-12T08:01:15.000Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-44758
(9.1 CRITICAL)

EPSS: 0.51%

updated 2026-08-11T03:31:55

2 posts

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability

beyondmachines1 at 2026-08-12T08:01:15.265Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-12T08:01:15.000Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-66058
(0 None)

EPSS: 0.22%

updated 2026-08-10T13:19:52.897000

1 posts

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.

sayzard@mastodon.sayzard.org at 2026-08-12T09:45:39.000Z ##

ERPNext's Document Follow feature exposed unauthorized data

Frappe/ERPNext의 Document Follow 기능에서 권한 검증이 누락된 취약점 체인 3건(CVE-2026-66058, CVE-2026-66059, CVE-2026-66000)이 공개됐다. 인증된 Desk 사용자는 읽기 권한이 없는 문서를 팔로우할 수 있었고, 이후 변경 시 민감한 필드가 포함된 diff 정보를 이메일로 지속 수신할 수 있었다. 또한 문서 권한이 사후 철회돼도 기존 팔로우 구독이 유지되는 문제가 있어 데이터 유출이 지속될 수 있었다. Frappe v16.23.0 및 v15.112.0에서 수정됐으므로 ERPNext/HRMS 운영자는...

robinroy.xyz/blog/frappe-docum

##

CVE-2026-64564
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-08-09T04:17:43.283000

1 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds

4 repos

https://github.com/HackSpeak/CVE-2026-64564

https://github.com/suominen/sctphantom

https://github.com/yandex-cloud-examples/yc-mk8s-sctphantom-mitigation

https://github.com/ethanolgolf/CVE-2026-64564

sigint@fosstodon.org at 2026-08-12T23:45:08.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-08-13

An 18-year-old SCTP use-after-free hitting Debian 13, Ubuntu 24.04, and RHEL. If SCTP modules load by default on your hosts, blacklist them or patch now, container isolation is not a real security boundary against a kernel root bug.

🔗 cybersecurityjournal.ca/techta

#Ubuntu #Linux #infosec

##

CVE-2026-66059
(0 None)

EPSS: 0.27%

updated 2026-08-08T04:17:50.503000

1 posts

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0.

sayzard@mastodon.sayzard.org at 2026-08-12T09:45:39.000Z ##

ERPNext's Document Follow feature exposed unauthorized data

Frappe/ERPNext의 Document Follow 기능에서 권한 검증이 누락된 취약점 체인 3건(CVE-2026-66058, CVE-2026-66059, CVE-2026-66000)이 공개됐다. 인증된 Desk 사용자는 읽기 권한이 없는 문서를 팔로우할 수 있었고, 이후 변경 시 민감한 필드가 포함된 diff 정보를 이메일로 지속 수신할 수 있었다. 또한 문서 권한이 사후 철회돼도 기존 팔로우 구독이 유지되는 문제가 있어 데이터 유출이 지속될 수 있었다. Frappe v16.23.0 및 v15.112.0에서 수정됐으므로 ERPNext/HRMS 운영자는...

robinroy.xyz/blog/frappe-docum

##

CVE-2026-66000
(0 None)

EPSS: 0.26%

updated 2026-08-07T19:18:51.847000

1 posts

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by email. This issue is fixed in versions 16.23.0 and 15.112.0.

sayzard@mastodon.sayzard.org at 2026-08-12T09:45:39.000Z ##

ERPNext's Document Follow feature exposed unauthorized data

Frappe/ERPNext의 Document Follow 기능에서 권한 검증이 누락된 취약점 체인 3건(CVE-2026-66058, CVE-2026-66059, CVE-2026-66000)이 공개됐다. 인증된 Desk 사용자는 읽기 권한이 없는 문서를 팔로우할 수 있었고, 이후 변경 시 민감한 필드가 포함된 diff 정보를 이메일로 지속 수신할 수 있었다. 또한 문서 권한이 사후 철회돼도 기존 팔로우 구독이 유지되는 문제가 있어 데이터 유출이 지속될 수 있었다. Frappe v16.23.0 및 v15.112.0에서 수정됐으므로 ERPNext/HRMS 운영자는...

robinroy.xyz/blog/frappe-docum

##

CVE-2026-20337
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-07T18:31:52

2 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A success

ottoto2017@prattohome.com at 2026-08-12T05:43:02.000Z ##

「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER

「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。

これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。

シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」

bleepingcomputer.com/news/secu

#prattohome

##

ottoto2017@prattohome.com at 2026-08-12T05:43:02.000Z ##

「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER

「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。

これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。

シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」

bleepingcomputer.com/news/secu

#prattohome

##

CVE-2026-71319
(9.6 CRITICAL)

EPSS: 0.32%

updated 2026-08-07T05:17:03.660000

2 posts

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://<host>:<port>/, subprotocol vite-hmr) can call RPC methods, with no token, ha

DailyCyberSecurity at 2026-08-12T13:19:37.895Z ##

CVE-2026-71319 lets attackers run arbitrary commands via unauthenticated Nuxt DevTools RPC. CVSS 9.6, 7.3M monthly downloads. Patch now.

securityonline.info/nuxt-devto

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T13:19:37.000Z ##

CVE-2026-71319 lets attackers run arbitrary commands via unauthenticated Nuxt DevTools RPC. CVSS 9.6, 7.3M monthly downloads. Patch now.

#Nuxt #VueJS #CVE #RCE #CyberSecurity

securityonline.info/nuxt-devto

##

CVE-2026-63456
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-06T15:40:50.227000

2 posts

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.

DailyCyberSecurity at 2026-08-13T14:38:57.478Z ##

CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.

securityonline.info/edgeconnec

##

DailyCyberSecurity@infosec.exchange at 2026-08-13T14:38:57.000Z ##

CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.

#HPE #Aruba #SDWAN #CVE #CyberSecurity

securityonline.info/edgeconnec

##

CVE-2026-63455
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-06T15:40:50.227000

2 posts

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.

DailyCyberSecurity at 2026-08-13T14:38:57.478Z ##

CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.

securityonline.info/edgeconnec

##

DailyCyberSecurity@infosec.exchange at 2026-08-13T14:38:57.000Z ##

CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.

#HPE #Aruba #SDWAN #CVE #CyberSecurity

securityonline.info/edgeconnec

##

CVE-2026-67261
(9.8 CRITICAL)

EPSS: 1.60%

updated 2026-08-06T15:32:56

2 posts

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete sys

CVE-2026-34966
(7.6 HIGH)

EPSS: 0.31%

updated 2026-08-05T21:31:47

2 posts

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints

nyanbinary@infosec.exchange at 2026-08-11T16:58:03.000Z ##

ACTUALLY...

CVE-2026-34966 -> github.com/go-gitea/gitea/secu -> CVE-2026-59765

... did they double assign without retraction?

##

nyanbinary@infosec.exchange at 2026-08-11T16:53:26.000Z ##

motherf... nvd.nist.gov/vuln/detail/cve-2

Why is this a vulncheck CVE, gitea got their own CNA!

##

CVE-2026-20272
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-05T18:31:45

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of specia

dailytechfeed@mastodon.social at 2026-08-13T07:04:05.000Z ##

Cisco has released critical security updates for IOS XE Software, addressing vulnerabilities that could expose network devices to remote attacks. Immediate patching is essential due to the severity and lack of workarounds. Affected versions include IOS XE 17.9, 17.12, 17.15, 17.18, and 26.1. Notably, CVE-2026-20272 carries a CVSS score of 9.8, involving improper neutralization of special elements,…

#Cisco #IOSXE #CyberSecurity #NetworkSecurity #Vulnerabilities #Patching

https://thedailytechfe…

##

CVE-2026-61515
(9.8 CRITICAL)

EPSS: 1.58%

updated 2026-08-05T14:17:08.690000

2 posts

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary com

DailyCyberSecurity at 2026-08-12T12:45:44.778Z ##

PoC exploit code is public for CVE-2026-61515, an unauthenticated command injection in Puwell IP Camera firmware. CVSS 9.3. Details inside.

securityonline.info/puwell-ip-

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T12:45:44.000Z ##

PoC exploit code is public for CVE-2026-61515, an unauthenticated command injection in Puwell IP Camera firmware. CVSS 9.3. Details inside.

#IPCamera #IoT #CVE #CommandInjection #CyberSecurity

securityonline.info/puwell-ip-

##

CVE-2026-71209
(7.5 HIGH)

EPSS: 1.76%

updated 2026-08-05T09:31:27

1 posts

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences URL-encoded. Express's router decodes the :id route parameter before handler code runs, so a %2F-encoded '../' sequence in :id (e.g. ..%2f..%2f..%2ftmp%

Nuclei template

halildeniz@mastodon.social at 2026-08-12T17:55:25.000Z ##

🚨 Critical flaw in Audiobookshelf!
CVE-2026-71209 allows unauthenticated remote attackers to bypass auth and read arbitrary host files via path traversal. Check out the technical deep dive and remediation guide now:

denizhalil.com/2026/08/12/cve-

#CyberSecurity #Vulnerability #Audiobookshelf

##

CVE-2026-18577
(8.1 HIGH)

EPSS: 4.10%

updated 2026-08-04T15:33:20

2 posts

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

3 repos

https://github.com/CreamyG31337/ncentral-compromise-ioc-triage

https://github.com/HORKimhab/CVE-2026-18577

https://github.com/Yash-Dalvee/stormencryptor-ncentral-defense

hackmag at 2026-08-12T20:00:05.182Z ##

⚪️ N-able Releases Two Patches for N-central Authentication Bypass Vulnerability

🗨️ N-able developers have released a second emergency patch for the N-central remote monitoring and management platform. The follow-up update was required due to ongoing attacks exploiting CVE-2026-18577: attackers are gaining administrator privileges on N-central servers and infiltrating customers’…

🔗 hackmag.com/news/n-central-0da

##

hackmag@infosec.exchange at 2026-08-12T20:00:05.000Z ##

⚪️ N-able Releases Two Patches for N-central Authentication Bypass Vulnerability

🗨️ N-able developers have released a second emergency patch for the N-central remote monitoring and management platform. The follow-up update was required due to ongoing attacks exploiting CVE-2026-18577: attackers are gaining administrator privileges on N-central servers and infiltrating customers’…

🔗 hackmag.com/news/n-central-0da

#news

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-30T16:17:15.073000

3 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

beyondmachines1 at 2026-08-13T10:01:21.207Z ##

Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access

German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).

**If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.**

beyondmachines.net/event_detai

##

netsecio@mastodon.social at 2026-08-12T15:06:48.000Z ##

📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi

Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday

🔗 cyber.netsecops.io/articles/vm

##

beyondmachines1@infosec.exchange at 2026-08-13T10:01:21.000Z ##

Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access

German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).

**If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-47876
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-07-30T15:31:54

1 posts

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

netsecio@mastodon.social at 2026-08-12T15:06:48.000Z ##

📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi

Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday

🔗 cyber.netsecops.io/articles/vm

##

CVE-2026-64560
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-30T12:19:03.630000

1 posts

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_timer_del() // Observes old leader p = pid_task(pid, pid_type); de_thread() switch_leader(); release

1 repos

https://github.com/villager1314/CVE-2026-64560-Analysis

DailyCyberSecurity@infosec.exchange at 2026-08-12T01:02:34.000Z ##

CVE-2026-64560: Linux Kernel CPU Timer Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed

securityonline.info/linux-kern

##

CVE-2025-4318
(0 None)

EPSS: 0.93%

updated 2026-07-29T16:17:47.997000

2 posts

The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.

awssecurityfeed at 2026-08-12T19:00:01.531Z ##

Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin....

aws.amazon.com/security/securi

##

awssecurityfeed@infosec.exchange at 2026-08-12T19:00:01.000Z ##

Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin....

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-64747
(7.8 HIGH)

EPSS: 0.14%

updated 2026-07-29T05:17:03.413000

2 posts

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to execute arbitrary code with kernel privileges.

1 repos

https://github.com/jiuyi155/agxprobe

Mndell@mastodon.social at 2026-08-12T05:57:41.000Z ##

@jurjen_heeck @malwaretech it might be not so much agentic yet. There is however a growing number of CVE’s with AI, like CVE-2026-64747 and the early release by Apple recently of multiple fixes as a result reuters.com/business/apple-say

##

Mndell@mastodon.social at 2026-08-12T05:57:41.000Z ##

@jurjen_heeck @malwaretech it might be not so much agentic yet. There is however a growing number of CVE’s with AI, like CVE-2026-64747 and the early release by Apple recently of multiple fixes as a result reuters.com/business/apple-say

##

CVE-2026-43723
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-28T19:31:46.327000

2 posts

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.

DailyCyberSecurity at 2026-08-13T13:16:52.105Z ##

PoC exploit code is public for CVE-2026-43723, an Apple mediaremoted flaw that lets an app gain root privileges. CVSS 7.8. Patch now.

securityonline.info/apple-medi

##

DailyCyberSecurity@infosec.exchange at 2026-08-13T13:16:52.000Z ##

PoC exploit code is public for CVE-2026-43723, an Apple mediaremoted flaw that lets an app gain root privileges. CVSS 7.8. Patch now.

#Apple #macOS #iOS #CVE #CyberSecurity

securityonline.info/apple-medi

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 99.91%

updated 2026-07-28T14:54:01.770000

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

Nuclei template

100 repos

https://github.com/badsectorlabs/copyfail-go

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/rvzsec/CVE-2026-31431

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/b5null/CVE-2026-31431-C

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/gagaltotal/cve-2026-31431-copy-fail

https://github.com/malwarekid/CVE-2026-31431

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/luotian2/CVE-2026-31431

https://github.com/tgies/copy-fail-c

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4

https://github.com/Boos4721/copyfail-rs

https://github.com/cs8425/copy-fail-go

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/mrunalp/block-copyfail

https://github.com/st4rburn/public-passwd

https://github.com/atgreen/block-copyfail

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/Huchangzhi/autorootlinux

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/wgnet/wg.copyfail.patch

https://github.com/abdullaabdullazade/CVE-2026-31431

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/diemoeve/copyfail-rs

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/0xShe/CVE-2026-31431

https://github.com/xeloxa/copyfail-exploit

https://github.com/wesmar/CVE-2026-31431

https://github.com/adysec/cve-2026-31431

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/samanzamani/copy-fail-checker

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/desultory/CVE-2026-31431

https://github.com/sgkdev/ptrace_may_dream

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/Qengineering/RK35xx-CopyFail-Hotfix

https://github.com/pedromizz/copy-fail

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/sgkdev/page_inject

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/Smarttfoxx/copyfail

https://github.com/sammwyy/copyfail-rs

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/povzayd/CVE-2026-31431

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/cozystack/copy-fail-blocker

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/ncmprbll/copy-fail-rs

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/Juguitos/copy-fail

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/cyber-joker/copy-fail-python

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/rootsecdev/cve_2026_31431

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

sigint@fosstodon.org at 2026-08-11T23:45:08.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-08-12

A 732-byte script reportedly roots any Linux since 2017 via a logic flaw, not memory corruption. If accurate this hits every homelab box and container host regardless of distro. Patch fast, verify your kernel version against the advisory.

🔗 bugcrowd.com/blog/what-we-know

#Ubuntu #Linux #infosec

##

CVE-2026-53360
(8.8 HIGH)

EPSS: 0.18%

updated 2026-07-22T19:07:37.640000

2 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared buffer. Note, things like Page State Change (PSC) requests _rely_ on this behavior, as the guest can't provide a length when making the request, i.e. the size of

1 repos

https://github.com/0xCyberstan/CVE-2026-53360-POC

CVE-2026-53361
(7.1 HIGH)

EPSS: 0.13%

updated 2026-07-18T09:32:17

3 posts

In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running: Thread 1 Thread 2 Thread 3 -------- -------- -------- unix_schedule_gc()

1 repos

https://github.com/sgkdev/bad_garbage

sayzard@mastodon.sayzard.org at 2026-08-12T07:41:56.000Z ##

CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape

공개 PoC 저장소는 Linux 커널 AF_UNIX 소켓 가비지 컬렉터와 `MSG_PEEK`의 경쟁 조건으로 발생하는 use-after-free(CVE-2026-53361)를 이용해 비권한 사용자 권한 상승 및 컨테이너 탈출이 가능하다고 주장합니다. 핵심은 GC가 순환 참조 소켓을 수집하는 동안 `MSG_PEEK`가 획득한 참조를 정확히 반영하지 못해, 살아 있는 소켓과 연결된 `sk_buff`가 해제되는 문제입니다. 저장소는 Debian trixie, RHEL/CentOS Stream 10, Ubuntu 24.04 HWE 등의 특정 커널 빌드가 영향을 받는다고 열거하며, Linux 6...

github.com/sgkdev/bad_garbage

##

CuratedHackerNews@mastodon.social at 2026-08-12T06:39:04.000Z ##

CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape

github.com/sgkdev/bad_garbage

#github

##

CuratedHackerNews@mastodon.social at 2026-08-12T06:39:04.000Z ##

CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape

github.com/sgkdev/bad_garbage

#github

##

CVE-2026-55040
(9.1 CRITICAL)

EPSS: 2.96%

updated 2026-07-14T18:32:38

19 posts

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

2 repos

https://github.com/l0ggg/CVE-2026-55040

https://github.com/sfewer-r7/CVE-2026-55040

ottoto2017@prattohome.com at 2026-08-13T07:17:47.000Z ##

「公開された概念実証(PoC)リリース後、攻撃者がSharePointの認証バイパスを悪用 」: #TheHackerNews

「攻撃者は、概念実証(PoC)コードの公開を受けて、新たに明らかになったMicrosoft SharePointの脆弱性を悪用し始めている。

問題となっている脆弱性は CVE-2026-55040 (CVSSスコア:9.1)で、認証の脆弱性に起因する重大なセキュリティ機能のバイパスに関するものです。この脆弱性は、マイクロソフトが2026年7月のパッチチューズデーアップデートの一環として修正しました。

マイクロソフトは先月、この脆弱性に関する勧告の中で、「この脆弱性によりなりすましが可能になるため、認証機能が回避される可能性がある」と述べた。「この脆弱性を悪用すると、攻撃者はファイルを漏洩させたりデータを改ざんしたりできる可能性があるが、システムの可用性に影響を与えることはできない」としている。 」

thehackernews.com/2026/08/atta

#prattohome

##

Analyst207@mastodon.social at 2026-08-13T07:01:46.000Z ##

Attackers Exploit SharePoint Flaw After Public PoC Release

Microsoft warned that a critical SharePoint flaw, patched in July 2026, could allow attackers to bypass authentication and disclose files or modify data. This vulnerability, tracked as CVE-2026-55040, has now been exploited by attackers following the public release of a proof-of-concept exploit.

osintsights.com/attackers-expl

#Cve202655040 #SharepointFlaw #Microsoft #AuthenticationBypass #SupplyChain

##

undercodenews@mastodon.social at 2026-08-13T06:40:18.000Z ##

Microsoft SharePoint Under Attack: Critical CVE-2026-55040 Exploitation Surges After Public PoC Release + Video

A New SharePoint Warning Is Turning Into a Real-World Security Crisis Microsoft SharePoint administrators are facing another serious warning as attackers appear to be testing a critical authentication-bypass vulnerability that can allow unauthenticated users to impersonate legitimate SharePoint accounts. The situation became more urgent after security…

undercodenews.com/microsoft-sh

##

dailytechfeed@mastodon.social at 2026-08-13T06:18:57.000Z ##

Cybercriminals are exploiting SharePoint vulnerability CVE-2026-55040, allowing authentication bypass and unauthorized access. Organizations should apply patches immediately to mitigate this risk.

#CyberSecurity #SharePoint #CVE202655040 #AuthenticationBypass #DataBreach #Microsoft

thedailytechfeed.com/attackers

##

cyberworldops at 2026-08-13T04:10:00.996Z ##

Rapid7 released a proof-of-concept for CVE-2026-55040, a critical SharePoint vulnerability, on August 12. Within hours, Defused observed the exploit weaponized against SharePoint honeypots. Microsoft patched the flaw in July, yet Shadowserver still reports over 8,500 exposed servers. Patching is no longer optional.

cyberworldops.eu/en/sharepoint

##

undercodenews@mastodon.social at 2026-08-12T21:52:31.000Z ##

Microsoft SharePoint Under Attack: Hackers Exploit CVE-2026-55040 Shortly After Rapid7 Releases a Proof of Concept + Video

A Dangerous Window Opens for SharePoint Administrators A new Microsoft SharePoint security incident is highlighting one of the most dangerous realities in modern cybersecurity: the moment a working proof of concept becomes public, attackers can move from research to exploitation with astonishing speed. On August 12, 2026, reports emerged that…

undercodenews.com/microsoft-sh

##

undercodenews@mastodon.social at 2026-08-12T13:04:33.000Z ##

Microsoft SharePoint Under Attack: Critical JWT Authentication Flaw Exploited After Rapid7 Releases Public PoC

A Dangerous SharePoint Vulnerability Has Crossed a Critical Line Microsoft SharePoint administrators are facing another serious cybersecurity warning after a critical authentication-bypass vulnerability moved rapidly from public disclosure to observed exploitation. The flaw, tracked as CVE-2026-55040, affects the way SharePoint validates JSON Web Tokens (JWTs)…

undercodenews.com/microsoft-sh

##

jbhall56 at 2026-08-12T12:48:27.512Z ##

Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. bleepingcomputer.com/news/micr

##

Analyst207@mastodon.social at 2026-08-12T12:31:45.000Z ##

Hackers Exploit New Microsoft SharePoint Vulnerability in Attacks

Hackers are already exploiting a newly discovered critical flaw in Microsoft SharePoint, with over 8,500 servers exposed online and vulnerable to attacks. This authentication bypass vulnerability, known as CVE-2026-55040, allows hackers to disclose files, modify data, and wreak havoc on your system.

osintsights.com/hackers-exploi

#MicrosoftSharepoint #Cve202655040 #AuthenticationBypass #VulnerabilityExploitation #EmergingThreats

##

cyberworldops at 2026-08-12T06:20:01.341Z ##

Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

cyberworldops.eu/en/sharepoint

##

DailyCyberSecurity at 2026-08-12T06:14:46.899Z ##

Rapid7 published full details and a PoC for CVE-2026-55040, a critical SharePoint authentication bypass that forges JWT tokens. Patch now.

securityonline.info/sharepoint

##

ottoto2017@prattohome.com at 2026-08-12T04:55:06.000Z ##

「研究者らが、認証不要のリモートコード実行(RCE)を実現するAI支援型SharePointエクスプロイトチェーンを公開 」: #TheHackerNews

「セキュリティ研究者らは、有効なアカウントを持たずに、管理者を含むあらゆるユーザーとしてMicrosoft SharePointサーバーに侵入する方法を発見した。この発見に大きく貢献したのが、AIエージェントを用いた作業だった。

CVE-2026-55040 (CVSS 9.1)として追跡されているこの脆弱性は 、SharePoint Server Subscription Edition、SharePoint Server 2019、およびSharePoint Server 2016に影響します。マイクロソフトの影響を受ける製品リストには、これら3つのオンプレミス版のみが含まれており、SharePoint Onlineは含まれていません。

この攻撃手法は、認証されていないリモート攻撃者が、選択したユーザーの身元を偽装することを可能にします。 」

thehackernews.com/2026/08/rese

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T07:17:47.000Z ##

「公開された概念実証(PoC)リリース後、攻撃者がSharePointの認証バイパスを悪用 」: #TheHackerNews

「攻撃者は、概念実証(PoC)コードの公開を受けて、新たに明らかになったMicrosoft SharePointの脆弱性を悪用し始めている。

問題となっている脆弱性は CVE-2026-55040 (CVSSスコア:9.1)で、認証の脆弱性に起因する重大なセキュリティ機能のバイパスに関するものです。この脆弱性は、マイクロソフトが2026年7月のパッチチューズデーアップデートの一環として修正しました。

マイクロソフトは先月、この脆弱性に関する勧告の中で、「この脆弱性によりなりすましが可能になるため、認証機能が回避される可能性がある」と述べた。「この脆弱性を悪用すると、攻撃者はファイルを漏洩させたりデータを改ざんしたりできる可能性があるが、システムの可用性に影響を与えることはできない」としている。 」

thehackernews.com/2026/08/atta

#prattohome

##

cyberworldops@infosec.exchange at 2026-08-13T04:10:00.000Z ##

Rapid7 released a proof-of-concept for CVE-2026-55040, a critical SharePoint vulnerability, on August 12. Within hours, Defused observed the exploit weaponized against SharePoint honeypots. Microsoft patched the flaw in July, yet Shadowserver still reports over 8,500 exposed servers. Patching is no longer optional.

#SharePoint #CVE2026 #VulnerabilityManagement #PatchTuesday

cyberworldops.eu/en/sharepoint

##

jbhall56@infosec.exchange at 2026-08-12T12:48:27.000Z ##

Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. bleepingcomputer.com/news/micr

##

cyberworldops@infosec.exchange at 2026-08-12T06:20:01.000Z ##

Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

#SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability

cyberworldops.eu/en/sharepoint

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T06:14:46.000Z ##

Rapid7 published full details and a PoC for CVE-2026-55040, a critical SharePoint authentication bypass that forges JWT tokens. Patch now.

#CVE202655040 #SharePoint #AuthenticationBypass #JWT #Rapid7 #PoC #Cybersecurity

securityonline.info/sharepoint

##

ottoto2017@prattohome.com at 2026-08-12T04:55:06.000Z ##

「研究者らが、認証不要のリモートコード実行(RCE)を実現するAI支援型SharePointエクスプロイトチェーンを公開 」: #TheHackerNews

「セキュリティ研究者らは、有効なアカウントを持たずに、管理者を含むあらゆるユーザーとしてMicrosoft SharePointサーバーに侵入する方法を発見した。この発見に大きく貢献したのが、AIエージェントを用いた作業だった。

CVE-2026-55040 (CVSS 9.1)として追跡されているこの脆弱性は 、SharePoint Server Subscription Edition、SharePoint Server 2019、およびSharePoint Server 2016に影響します。マイクロソフトの影響を受ける製品リストには、これら3つのオンプレミス版のみが含まれており、SharePoint Onlineは含まれていません。

この攻撃手法は、認証されていないリモート攻撃者が、選択したユーザーの身元を偽装することを可能にします。 」

thehackernews.com/2026/08/rese

#prattohome

##

AAKL@infosec.exchange at 2026-08-11T17:25:10.000Z ##

New.

Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) rapid7.com/blog/post/ra-micros @Rapid7Official #Microsoft #infosec #threatresearch #SharePoint #vulnerability

##

CVE-2026-12879
(0 None)

EPSS: 0.19%

updated 2026-07-09T16:39:17.737000

1 posts

An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.

AAKL@infosec.exchange at 2026-08-11T17:11:08.000Z ##

Broadcom has several new advisories that include two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

CISA:

Industrial vulnerability: Johnson Controls C-CURE 9000 and Victor application server (Update A) cisa.gov/news-events/ics-advis

Blog post: Cyber Storm X: 20 Years of Readiness, Resilience, and Real‑World Impact cisa.gov/news-events/news/cybe #CISA

Cisco:

High-severity: CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

Yesterday:

Tenable Research Advisories:

Medium-severity: CVE-2026-12879: Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy tenable.com/security/research/ #infosec #Google #vulnerability

##

CVE-2026-45659
(8.8 HIGH)

EPSS: 9.86%

updated 2026-07-01T21:35:53

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

2 repos

https://github.com/HORKimhab/CVE-2026-45659

https://github.com/WismanSec/sharepoint-2026-poc

cyberworldops@infosec.exchange at 2026-08-11T16:10:00.000Z ##

CISA has confirmed active ransomware exploitation of CVE-2026-45659, a remote code execution flaw in Microsoft SharePoint. The vulnerability was added to the Known Exploited Vulnerabilities catalog on July 1st with a mandatory 3-day remediation deadline for federal agencies.

#SharePoint #Ransomware #CISA #CVE202645659

cyberworldops.eu/en/sharepoint

##

CVE-2026-49473
(8.8 HIGH)

EPSS: 0.28%

updated 2026-06-30T18:09:14

2 posts

### Summary @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. An issue exists where, under certain circumstances, the middleware matches incoming requests against Cedar action mappings usin

thehackerwire@mastodon.social at 2026-08-13T03:01:09.000Z ##

🟠 CVE-2026-49473 - High (8.8)

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing request...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T03:01:09.000Z ##

🟠 CVE-2026-49473 - High (8.8)

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing request...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-7771
(0 None)

EPSS: 6.83%

updated 2026-06-17T10:05:37.643000

1 posts

ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrary kernel functions with ring-0 privileges. The vulnerability enables local attackers to execute arbit

12 repos

https://github.com/fxrstor/ThrottleStopPoC

https://github.com/xM0kht4r/CVE-2025-7771

https://github.com/D4rkks/CVE-2025-7771-Vulnerability-Exploration

https://github.com/Demoo1337/ThrottleStop

https://github.com/lzty/CVE-2025-7771

https://github.com/Gabriel-Lacorte/CVE-2025-7771

https://github.com/mein-0/cve-2025-7771

https://github.com/DeathShotXD/0xKern3lCrush

https://github.com/v31l0x1/ThrottleStopPPL

https://github.com/AmrHuss/throttlestop-exploit-rw

https://github.com/I3r1h0n/Sigurd

https://github.com/enessakircolak/CVE-2025-7771

obivan@infosec.exchange at 2026-08-11T15:13:19.000Z ##

CVE-2025-7771 — ThrottleStop.sys Arbitrary Physical Memory R/W github.com/enessakircolak/CVE-

##

CVE-2026-47717
(7.5 HIGH)

EPSS: 1.20%

updated 2026-05-27T22:51:19

2 posts

### Summary The GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. ### Details File: `server/api/projects/index.js` ```javascript prjApp.get("/api/project", secureFnc, function(req, res) { const permission = checkGroupsFnc(req); runtime.project.getProject(req.userId, permission).then(result => { i

Nuclei template

thehackerwire@mastodon.social at 2026-08-13T00:00:28.000Z ##

🟠 CVE-2026-47717 - High (7.5)

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Versio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-13T00:00:28.000Z ##

🟠 CVE-2026-47717 - High (7.5)

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Versio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-22185(CVSS UNKNOWN)

EPSS: 0.13%

updated 2026-01-08T18:31:46

2 posts

OpenLDAP Lightning Memory-Mapped Database (LMDB) mdb_load contains a heap buffer underflow vulnerability in the readline() function. When processing malformed input, an unsigned offset calculation can underflow a heap pointer, resulting in an out-of-bounds read of one byte before the allocated heap buffer. This may allow a local attacker to cause a denial of service and potentially disclose limite

hyc@mastodon.social at 2026-08-12T11:57:12.000Z ##

As an example of how ridiculous the CVE ecosystem has become... researchers claimed a CVE this year against an LMDB commandline tool (not a server) for a bug fixed in 0.9.15, which was released 2015-06-19 - eleven years ago.

openeuler.org/zh/security/cve/

##

hyc@mastodon.social at 2026-08-12T11:57:12.000Z ##

As an example of how ridiculous the CVE ecosystem has become... researchers claimed a CVE this year against an LMDB commandline tool (not a server) for a bug fixed in 0.9.15, which was released 2015-06-19 - eleven years ago.

openeuler.org/zh/security/cve/

##

CVE-2025-24472
(8.1 HIGH)

EPSS: 3.87%

updated 2025-10-22T00:34:17

1 posts

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

1 repos

https://github.com/razureink/cve-2025-24472-fortinet_authbypass_reproduction

CapTechGroup@mastodon.social at 2026-08-12T18:16:05.000Z ##

Gunra ransomware operators are exploiting two Fortinet vulnerabilities, CVE-2024-55591 and CVE-2025-24472, in campaigns tied to Conti and Golden Community. Reported tooling includes Mega and OpenSSH alongside Conti and Gunra...

captechgroup.com/threat-intell

##

CVE-2024-55591
(9.8 CRITICAL)

EPSS: 98.26%

updated 2025-10-22T00:34:16

3 posts

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Nuclei template

9 repos

https://github.com/UMChacker/CVE-2024-55591-POC

https://github.com/exfil0/CVE-2024-55591-POC

https://github.com/0x7556/CVE-2024-55591

https://github.com/binarywarm/exp-cmd-add-admin-vpn-CVE-2024-55591

https://github.com/sysirq/fortios-auth-bypass-poc-CVE-2024-55591

https://github.com/virus-or-not/CVE-2024-55591

https://github.com/sysirq/fortios-auth-bypass-exploit-CVE-2024-55591

https://github.com/watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591

https://github.com/watchtowrlabs/fortios-auth-bypass-poc-CVE-2024-55591

CapTechGroup@mastodon.social at 2026-08-12T18:16:05.000Z ##

Gunra ransomware operators are exploiting two Fortinet vulnerabilities, CVE-2024-55591 and CVE-2025-24472, in campaigns tied to Conti and Golden Community. Reported tooling includes Mega and OpenSSH alongside Conti and Gunra...

captechgroup.com/threat-intell

##

Analyst207@mastodon.social at 2026-08-12T14:03:19.000Z ##

Gunra Ransomware Targets Infrastructure via Fortinet Flaws

Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

osintsights.com/gunra-ransomwa

#GunraRansomware #Fortinet #Cve202455591 #Ransomware #SupplyChain

##

Analyst207@mastodon.social at 2026-08-12T14:03:19.000Z ##

Gunra Ransomware Targets Infrastructure via Fortinet Flaws

Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

osintsights.com/gunra-ransomwa

#GunraRansomware #Fortinet #Cve202455591 #Ransomware #SupplyChain

##

CVE-2025-24994
(7.3 HIGH)

EPSS: 1.18%

updated 2025-03-11T18:32:28

2 posts

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

CVE-2025-24076
(7.3 HIGH)

EPSS: 3.15%

updated 2025-03-11T18:32:27

2 posts

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

1 repos

https://github.com/mbanyamer/CVE-2025-24076

CVE-2026-65640
(0 None)

EPSS: 0.00%

7 posts

N/A

1 repos

https://github.com/jobusa755-a11y/CVE-2026-65640-

decio at 2026-08-13T14:34:22.236Z ##

…et encore une vulnérabilité critique dans , trouvée une nouvelle fois par pwn.ai, qui a nécessité la publication en urgence de la mise à jour 7.0.4

La CVE-2026-65640 est une RCE assez intéressante côté traitement d’images. (ImageMagick)

Un utilisateur avec le rôle Author peut envoyer un fichier nommé comme une innocente image .png, alors que son contenu est en réalité du PostScript/EPS.
WordPress se fiait trop à l’extension ; ImageMagick, lui, regarde le contenu et peut transmettre le fichier à Ghostscript… avec à la clé une exécution de code.

Ce n’est donc pas une RCE pré-auth : il faut déjà disposer d’un compte Author. Mais sur un site multi-auteurs, communautaire ou avec des comptes peu maîtrisés, le risque devient nettement plus concret.
👇
wordpress.org/news/2026/08/wor
⬇️
github.com/WordPress/wordpress

##

raul@mastodon.in4matics.cat at 2026-08-13T11:30:15.000Z ##

🖼️ RCE a WordPress via PNG maliciosos. CVE-2026-65640, fix a 7.0.4.

Atacant amb rol Autor puja `EPS:innocent.png` o un PNG amb PostScript ocult. `Imagick::load()` confiava en l'extensió; ImageMagick llegeix el contingut real → Ghostscript executa. XML-RPC i portades MP3 saltaven la validació.

El patch inspecciona bytes reals: bloqueja PostScript/EPS, PDF sense `%PDF-` i gzip/bzip2.
blog.elhacker.net/2026/08/vuln
#WordPress #SecOps #ImageMagick

##

DailyCyberSecurity at 2026-08-13T07:35:31.550Z ##

WordPress 7.0.4 patches CVE-2026-65640, an Author-level remote code execution bug on sites using Imagick and Ghostscript. Update now.

securityonline.info/wordpress-

##

guru@thecybersecguru.com at 2026-08-13T07:31:35.000Z ##

WordPress 7.0.4 Fixes Critical Imagick RCE: How a Malicious PNG Could Become Server-Side Code Execution

WordPress 7.0.4 fixes CVE-2026-65640, an authenticated RCE affecting sites using Imagick and Ghostscript. Learn how malicious PNG reach code execution

thecybersecguru.com/news/wordp

##

decio@infosec.exchange at 2026-08-13T14:34:22.000Z ##

…et encore une vulnérabilité critique dans #WordPress, trouvée une nouvelle fois par pwn.ai, qui a nécessité la publication en urgence de la mise à jour 7.0.4

La CVE-2026-65640 est une RCE assez intéressante côté traitement d’images. (ImageMagick)

Un utilisateur avec le rôle Author peut envoyer un fichier nommé comme une innocente image .png, alors que son contenu est en réalité du PostScript/EPS.
WordPress se fiait trop à l’extension ; ImageMagick, lui, regarde le contenu et peut transmettre le fichier à Ghostscript… avec à la clé une exécution de code.

Ce n’est donc pas une RCE pré-auth : il faut déjà disposer d’un compte Author. Mais sur un site multi-auteurs, communautaire ou avec des comptes peu maîtrisés, le risque devient nettement plus concret.
👇
wordpress.org/news/2026/08/wor
⬇️
github.com/WordPress/wordpress

#CyberVeille

##

raul@mastodon.in4matics.cat at 2026-08-13T11:30:15.000Z ##

🖼️ RCE a WordPress via PNG maliciosos. CVE-2026-65640, fix a 7.0.4.

Atacant amb rol Autor puja `EPS:innocent.png` o un PNG amb PostScript ocult. `Imagick::load()` confiava en l'extensió; ImageMagick llegeix el contingut real → Ghostscript executa. XML-RPC i portades MP3 saltaven la validació.

El patch inspecciona bytes reals: bloqueja PostScript/EPS, PDF sense `%PDF-` i gzip/bzip2.
blog.elhacker.net/2026/08/vuln
#WordPress #SecOps #ImageMagick

##

DailyCyberSecurity@infosec.exchange at 2026-08-13T07:35:31.000Z ##

WordPress 7.0.4 patches CVE-2026-65640, an Author-level remote code execution bug on sites using Imagick and Ghostscript. Update now.

#WordPress #CVE202665640 #RCE #Imagick #Ghostscript #WebSecurity #Cybersecurity

securityonline.info/wordpress-

##

CVE-2026-48273
(0 None)

EPSS: 0.00%

2 posts

N/A

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

ottoto2017@prattohome.com at 2026-08-13T06:49:16.000Z ##

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

##

CVE-2026-49481
(0 None)

EPSS: 0.88%

4 posts

N/A

offseq at 2026-08-13T06:00:25.000Z ##

CVE-2026-49481 | UpSnap (<5.4.0) has a CRITICAL OS command injection flaw (CVSS 9.6). Authenticated low-priv users can execute arbitrary commands on the server. Patch: upgrade to 5.4.0. Details: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-13T00:00:19.000Z ##

🔴 CVE-2026-49481 - Critical (9.6)

UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac field...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-13T06:00:25.000Z ##

CVE-2026-49481 | UpSnap (<5.4.0) has a CRITICAL OS command injection flaw (CVSS 9.6). Authenticated low-priv users can execute arbitrary commands on the server. Patch: upgrade to 5.4.0. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202649481 #remotecodeexecution

##

thehackerwire@mastodon.social at 2026-08-13T00:00:19.000Z ##

🔴 CVE-2026-49481 - Critical (9.6)

UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac field...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49819
(0 None)

EPSS: 0.61%

4 posts

N/A

thehackerwire@mastodon.social at 2026-08-13T03:01:18.000Z ##

🔴 CVE-2026-49819 - Critical (9.8)

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-13T00:00:35.472Z ##

CVE-2026-49819: UpSnap (4.4.1 – 5.3.5) has a CRITICAL flaw (CVSS 9.8) — unauthenticated attackers can register a superuser & achieve root RCE via POST /api/upsnap/init-superuser. Upgrade to 5.4.0 ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-13T03:01:18.000Z ##

🔴 CVE-2026-49819 - Critical (9.8)

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-13T00:00:35.000Z ##

CVE-2026-49819: UpSnap (4.4.1 – 5.3.5) has a CRITICAL flaw (CVSS 9.8) — unauthenticated attackers can register a superuser & achieve root RCE via POST /api/upsnap/init-superuser. Upgrade to 5.4.0 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Infosec #RCE

##

CVE-2026-73501
(0 None)

EPSS: 0.34%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T23:00:00.000Z ##

🔴 CVE-2026-73501 - Critical (9.1)

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T23:00:00.000Z ##

🔴 CVE-2026-73501 - Critical (9.1)

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19654
(0 None)

EPSS: 0.40%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T22:02:00.000Z ##

🟠 CVE-2026-19654 - High (7.5)

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T22:02:00.000Z ##

🟠 CVE-2026-19654 - High (7.5)

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73299
(0 None)

EPSS: 1.21%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T20:00:26.000Z ##

🔴 CVE-2026-73299 - Critical (10)

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled templat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T20:00:26.000Z ##

🔴 CVE-2026-73299 - Critical (10)

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled templat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18952
(0 None)

EPSS: 0.32%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T20:00:06.000Z ##

🟠 CVE-2026-18952 - High (8.1)

Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the thr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T20:00:06.000Z ##

🟠 CVE-2026-18952 - High (8.1)

Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the thr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73293
(0 None)

EPSS: 0.40%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T17:00:25.000Z ##

🟠 CVE-2026-73293 - High (8.8)

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to use POST /api/project/{id}/roles to create a cust...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T17:00:25.000Z ##

🟠 CVE-2026-73293 - High (8.8)

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to use POST /api/project/{id}/roles to create a cust...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73292
(0 None)

EPSS: 0.19%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T17:00:15.000Z ##

🟠 CVE-2026-73292 - High (8.3)

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T17:00:15.000Z ##

🟠 CVE-2026-73292 - High (8.3)

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73225
(0 None)

EPSS: 0.31%

2 posts

N/A

hugovalters@mastodon.social at 2026-08-12T11:07:26.000Z ##

CVE-2026-73225 - Path traversal in electerm FTP/SFTP client. Malicious server writes files outside download dir. CVSS 8.1. Update to 3.15.120 now. #CVE #infosec #electerm

valtersit.com/cve/CVE-2026-732

##

thehackerwire@mastodon.social at 2026-08-11T20:00:22.000Z ##

🟠 CVE-2026-73225 - High (8.1)

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to write attacker-controlled content outside the selected download directory because recurs...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44772
(0 None)

EPSS: 0.00%

2 posts

N/A

beyondmachines1 at 2026-08-12T08:01:15.265Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-12T08:01:15.000Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-72916
(0 None)

EPSS: 0.36%

2 posts

N/A

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

CVE-2026-72915
(0 None)

EPSS: 0.28%

2 posts

N/A

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

CVE-2026-12234
(0 None)

EPSS: 0.08%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T06:00:36.000Z ##

🟠 CVE-2026-12234 - High (7.8)

The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the still-li...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T06:00:36.000Z ##

🟠 CVE-2026-12234 - High (7.8)

The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the still-li...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48765
(0 None)

EPSS: 0.26%

3 posts

N/A

offseq at 2026-08-12T06:00:27.764Z ##

CVE-2026-48765 (CRITICAL, CVSS 9.9): TypeBot.io <3.17.0 suffers from an auth bypass, letting read collaborators hijack OAuth credentials across workspaces. Upgrade to 3.17.0+ ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-12T06:00:27.000Z ##

CVE-2026-48765 (CRITICAL, CVSS 9.9): TypeBot.io <3.17.0 suffers from an auth bypass, letting read collaborators hijack OAuth credentials across workspaces. Upgrade to 3.17.0+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202648765 #TypeBot #OAuth #Security

##

thehackerwire@mastodon.social at 2026-08-11T22:01:20.000Z ##

🔴 CVE-2026-48765 - Critical (9.9)

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredent...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73247
(0 None)

EPSS: 0.30%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T00:00:12.000Z ##

🟠 CVE-2026-73247 - High (8.6)

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73249
(0 None)

EPSS: 0.25%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T00:00:22.000Z ##

🟠 CVE-2026-73249 - High (7.5)

calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_wr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73234
(0 None)

EPSS: 0.16%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T21:00:33.000Z ##

🟠 CVE-2026-73234 - High (7.8)

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data attribute from Document.xml with the document trans...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73231
(0 None)

EPSS: 0.15%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T21:00:03.000Z ##

🟠 CVE-2026-73231 - High (7.8)

Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through fakeEval.re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73224
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T20:00:08.000Z ##

🟠 CVE-2026-73224 - High (8.8)

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder and invokes Properties...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59765
(0 None)

EPSS: 0.00%

2 posts

N/A

nyanbinary@infosec.exchange at 2026-08-11T16:58:40.000Z ##

wait, the CVE-2026-59765 doesn't exist? wtf

##

nyanbinary@infosec.exchange at 2026-08-11T16:58:03.000Z ##

ACTUALLY...

CVE-2026-34966 -> github.com/go-gitea/gitea/secu -> CVE-2026-59765

... did they double assign without retraction?

##

CVE-2026-72920
(0 None)

EPSS: 0.41%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T16:01:00.000Z ##

🔴 CVE-2026-72920 - Critical (9.8)

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

_r_netsec@infosec.exchange at 2026-08-11T15:43:04.000Z ##

CopyEscape: Container-to-host arbitrary file write via docker cp (CVE-2026-17106) imperva.com/blog/copyescape-ta

##

Visit counter For Websites