##
Updated at UTC 2026-10-07T20:30:31.291536
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-79806 | 7.8 | 0.11% | 1 | 0 | 2026-10-07T19:17:42.637000 | A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Lin | |
| CVE-2026-79803 | 8.8 | 0.74% | 1 | 0 | 2026-10-07T19:17:42.403000 | A command injection vulnerability exists in the API of ClearPass Policy Manager. | |
| CVE-2026-79800 | 8.8 | 0.55% | 1 | 0 | 2026-10-07T19:17:42.033000 | An authenticated path traversal vulnerability exists in the command line interfa | |
| CVE-2026-76464 | 9.6 | 0.00% | 2 | 0 | 2026-10-07T19:17:40.650000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-14911 | 0 | 0.32% | 2 | 0 | 2026-10-07T19:17:35.867000 | Improper Neutralization of Input During Web Page Generation (“Cross-site Scripti | |
| CVE-2026-107219 | 7.5 | 0.00% | 2 | 0 | 2026-10-07T19:17:34.287000 | Excelize is a Go language library for reading and writing Microsoft Excel spread | |
| CVE-2026-107217 | 7.5 | 0.00% | 2 | 0 | 2026-10-07T19:17:33.957000 | Excelize is a Go language library for reading and writing Microsoft Excel spread | |
| CVE-2026-102255 | 10.0 | 0.00% | 5 | 0 | 2026-10-07T18:33:12 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla | |
| CVE-2026-76483 | 9.1 | 0.00% | 2 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-96335 | 7.5 | 0.00% | 2 | 0 | 2026-10-07T18:32:21 | Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Inc | |
| CVE-2026-76480 | 9.8 | 0.00% | 2 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76472 | 8.8 | 0.00% | 2 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76471 | 9.8 | 0.00% | 4 | 0 | 2026-10-07T18:32:21 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an una | |
| CVE-2026-76470 | 8.8 | 0.00% | 2 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76499 | 9.8 | 0.00% | 2 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76498 | 9.8 | 0.00% | 2 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76486 | 9.8 | 0.00% | 2 | 0 | 2026-10-07T18:32:21 | A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) fe | |
| CVE-2026-76485 | 9.8 | 0.00% | 4 | 0 | 2026-10-07T18:32:21 | A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) fe | |
| CVE-2026-76484 | 8.8 | 0.00% | 2 | 0 | 2026-10-07T18:32:21 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-95605 | 9.3 | 0.00% | 2 | 0 | 2026-10-07T18:32:21 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-76482 | 10.0 | 0.00% | 4 | 0 | 2026-10-07T18:32:20 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76500 | 9.8 | 0.00% | 2 | 0 | 2026-10-07T18:32:14 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20328 | 9.1 | 0.00% | 2 | 0 | 2026-10-07T18:32:14 | A vulnerability in the web-based management interface of Cisco License On-Prem, | |
| CVE-2026-76501 | 9.8 | 0.00% | 2 | 0 | 2026-10-07T18:32:14 | A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administratio | |
| CVE-2026-107206 | 9.4 | 0.00% | 2 | 0 | 2026-10-07T18:32:14 | LMCache through 0.5.5 contains a missing authentication vulnerability in the mul | |
| CVE-2026-107204 | 9.8 | 0.00% | 2 | 0 | 2026-10-07T18:32:14 | LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerab | |
| CVE-2026-20362 | 7.2 | 0.00% | 2 | 0 | 2026-10-07T18:32:14 | A vulnerability in the web-based management interface of Cisco Finesse could all | |
| CVE-2026-92414 | None | 0.00% | 2 | 0 | 2026-10-07T18:32:14 | : Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabb | |
| CVE-2026-95606 | 9.8 | 0.00% | 2 | 0 | 2026-10-07T18:17:31.910000 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Ev | |
| CVE-2026-95534 | 8.8 | 0.00% | 2 | 0 | 2026-10-07T18:17:31.777000 | Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited | |
| CVE-2026-76465 | 9.8 | 0.00% | 4 | 0 | 2026-10-07T18:17:28.580000 | A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) fea | |
| CVE-2026-76457 | 8.6 | 0.00% | 2 | 0 | 2026-10-07T18:17:21.317000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-106510 | 7.7 | 0.00% | 2 | 0 | 2026-10-07T18:17:16.660000 | Backstage is an open framework for building developer portals. Prior to 1.14.6, | |
| CVE-2026-105192 | 9.8 | 0.67% | 2 | 0 | 2026-10-07T18:17:15.427000 | LMCache multiprocess mode, also called distributed mode, opens an unauthenticate | |
| CVE-2026-104286 | 9.8 | 2.20% | 1 | 2 | 2026-10-07T18:17:15.240000 | An improper limitation of a pathname to a restricted directory ('path traversal' | |
| CVE-2026-106443 | 8.8 | 0.69% | 1 | 0 | 2026-10-07T18:05:51 | ### Summary This was found during a pentest, funded by the NLNnet foundation, c | |
| CVE-2026-106441 | 7.8 | 0.17% | 1 | 0 | 2026-10-07T18:03:56 | ## Summary Hydra passed its Python logging configuration to `logging.config.dic | |
| CVE-2026-106442 | 7.8 | 0.16% | 1 | 0 | 2026-10-07T18:03:50 | ## Summary Hydra's `instantiate()` API resolves and invokes Python callables na | |
| CVE-2026-106558 | 8.8 | 0.00% | 2 | 0 | 2026-10-07T18:03:15 | ### Impact An attacker who can provide configuration to a TechDocs build may ex | |
| CVE-2026-77226 | 8.1 | 0.69% | 1 | 0 | 2026-10-07T17:17:02.300000 | Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability | |
| CVE-2026-76468 | 8.2 | 0.00% | 2 | 0 | 2026-10-07T17:16:59.680000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76467 | 7.5 | 0.00% | 2 | 0 | 2026-10-07T17:16:59.503000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76463 | 8.8 | 0.00% | 2 | 0 | 2026-10-07T17:16:58.833000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76459 | 8.8 | 0.00% | 2 | 0 | 2026-10-07T17:16:58.553000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76458 | 8.6 | 0.00% | 2 | 0 | 2026-10-07T17:16:58.280000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76455 | 9.8 | 0.00% | 2 | 0 | 2026-10-07T17:16:57.520000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-107205 | 8.6 | 0.00% | 2 | 0 | 2026-10-07T17:16:53.790000 | LMCache through 0.5.5 contains a missing authentication vulnerability in the mul | |
| CVE-2026-79796 | 9.8 | 0.47% | 1 | 0 | 2026-10-07T16:18:59.520000 | Vulnerabilities have been identified in the affected interface of ClearPass Poli | |
| CVE-2026-106118 | 7.5 | 0.60% | 1 | 0 | 2026-10-07T16:18:57 | ## Summary When decoding a tiled TIFF with fax compression (T4/T6/MH), `DecodeT | |
| CVE-2026-106117 | 7.5 | 0.43% | 1 | 0 | 2026-10-07T16:18:52 | ## Summary When decoding a fax-compressed strip TIFF (Compression=3 / Group 3 1 | |
| CVE-2026-101027 | 7.7 | 0.16% | 1 | 0 | 2026-10-07T16:17:31.953000 | When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allo | |
| CVE-2026-106102 | 10.0 | 0.30% | 1 | 0 | 2026-10-07T16:14:23 | ## Vulnerability Details **File**: `ui/src/utils/meta/Meta.js` — actually `ui/s | |
| CVE-2026-102489 | 9.8 | 1.40% | 1 | 2 | 2026-10-07T15:32:31 | Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability tha | |
| CVE-2026-77214 | 8.2 | 0.00% | 2 | 0 | 2026-10-07T15:32:08 | libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in | |
| CVE-2026-21589 | None | 1.75% | 22 | 7 | template | 2026-10-07T15:31:33 | h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data C |
| CVE-2026-58835 | 8.8 | 0.23% | 1 | 0 | 2026-10-07T15:12:08.233000 | In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a | |
| CVE-2026-55269 | 7.8 | 0.07% | 1 | 0 | 2026-10-07T15:10:08.650000 | In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety is | |
| CVE-2026-76744 | 9.8 | 0.51% | 1 | 0 | 2026-10-07T14:44:18.807000 | Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Succes | |
| CVE-2026-102406 | 8.8 | 0.35% | 1 | 0 | 2026-10-07T13:42:52.070000 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead | |
| CVE-2026-49885 | 7.8 | 0.07% | 1 | 0 | 2026-10-07T13:03:47.930000 | In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due | |
| CVE-2026-96408 | 9.4 | 0.00% | 1 | 0 | 2026-10-07T12:32:00 | A code injection vulnerability exists in the upgrade script of Movable Type, whi | |
| CVE-2025-64393 | None | 0.36% | 3 | 0 | 2026-10-07T09:32:29 | This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execu | |
| CVE-2026-107104 | None | 0.42% | 1 | 0 | 2026-10-07T09:32:29 | This vulnerability exists in the ERP system due to unsafe deserialization of use | |
| CVE-2026-19572 | None | 0.37% | 1 | 0 | 2026-10-07T06:33:01 | A security vulnerability has been identified in FlexNet Publisher lmadmin. The v | |
| CVE-2026-106197 | 9.6 | 0.40% | 1 | 0 | 2026-10-07T04:17:49.727000 | Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remo | |
| CVE-2026-101207 | 8.8 | 1.66% | 1 | 0 | 2026-10-07T04:17:38.120000 | Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior | |
| CVE-2026-16516 | None | 0.15% | 1 | 0 | 2026-10-07T03:30:31 | wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host | |
| CVE-2026-93674 | 9.8 | 0.76% | 1 | 1 | 2026-10-07T03:30:26 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute a | |
| CVE-2026-104334 | 9.8 | 0.62% | 1 | 0 | 2026-10-07T03:30:26 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute a | |
| CVE-2026-19386 | None | 0.19% | 1 | 0 | 2026-10-07T03:30:23 | A stack-based buffer overflow in the ASUS router modules allows an authenticated | |
| CVE-2026-105324 | None | 0.65% | 1 | 0 | 2026-10-07T03:30:23 | An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an | |
| CVE-2026-76750 | 9.8 | 0.53% | 1 | 0 | 2026-10-06T21:32:09 | Deserialization of untrusted data vulnerabilities exist in the web interface of | |
| CVE-2026-79808 | 7.8 | 0.11% | 1 | 0 | 2026-10-06T21:32:09 | A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy | |
| CVE-2026-79807 | 7.8 | 0.11% | 1 | 0 | 2026-10-06T21:32:09 | A missing integrity verification vulnerability in the Windows client software fo | |
| CVE-2026-43598 | None | 0.46% | 1 | 0 | 2026-10-06T21:32:09 | Improper input validation in the AMD ROCm Communication Collectives Library (RCC | |
| CVE-2026-79802 | 8.8 | 1.12% | 1 | 0 | 2026-10-06T21:32:02 | A command injection vulnerability exists in the client software of ClearPass Pol | |
| CVE-2026-79801 | 9.8 | 0.64% | 1 | 0 | 2026-10-06T21:32:02 | A missing integrity verification vulnerability in the client agent software of H | |
| CVE-2026-79799 | 8.8 | 0.29% | 1 | 0 | 2026-10-06T21:32:02 | A vulnerability in the web-based management interface of ClearPass Policy Manage | |
| CVE-2026-79798 | 9.9 | 0.34% | 1 | 0 | 2026-10-06T21:32:02 | SQL injection vulnerabilities in the web-based management interface of ClearPass | |
| CVE-2026-79797 | 8.8 | 0.30% | 1 | 0 | 2026-10-06T21:32:02 | An improper access control vulnerability exists in the Android client applicatio | |
| CVE-2026-79805 | 9.8 | 0.36% | 1 | 0 | 2026-10-06T21:32:02 | An authenticated path traversal vulnerability exists in ClearPass Policy Manager | |
| CVE-2026-86361 | 8.2 | 0.14% | 1 | 0 | 2026-10-06T21:31:59 | Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission | |
| CVE-2026-103007 | 7.2 | 0.34% | 1 | 0 | 2026-10-06T21:31:57 | Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalat | |
| CVE-2026-102159 | 9.8 | 0.36% | 1 | 0 | 2026-10-06T21:31:53 | An access-control flaw in the CV-CUE backend may allow an unauthenticated networ | |
| CVE-2026-86362 | 8.2 | 0.13% | 1 | 0 | 2026-10-06T21:31:53 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Contr | |
| CVE-2026-106382 | 9.6 | 0.35% | 2 | 0 | 2026-10-06T21:31:51 | Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a r | |
| CVE-2026-104073 | 7.6 | 0.28% | 1 | 0 | 2026-10-06T21:31:41 | NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vuln | |
| CVE-2026-86360 | 9.6 | 0.63% | 2 | 0 | 2026-10-06T20:17:34.090000 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation o | |
| CVE-2026-104070 | 9.8 | 0.57% | 2 | 0 | 2026-10-06T20:05:55.733000 | The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulner | |
| CVE-2026-106440 | 7.8 | 0.27% | 1 | 0 | 2026-10-06T20:03:40.690000 | Hydra is a framework for elegantly configuring complex applications. From 1.2.0 | |
| CVE-2026-106110 | 7.5 | 0.35% | 1 | 0 | 2026-10-06T20:03:40.690000 | ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Grou | |
| CVE-2026-105862 | 8.7 | 0.25% | 1 | 0 | 2026-10-06T20:03:40.690000 | Payload is a free and open source headless content management system. In version | |
| CVE-2026-63697 | 7.6 | 0.29% | 1 | 0 | 2026-10-06T19:58:37.060000 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate | |
| CVE-2026-67273 | 9.6 | 0.42% | 1 | 0 | 2026-10-06T19:58:37.060000 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper | |
| CVE-2026-106218 | 8.8 | 0.27% | 1 | 0 | 2026-10-06T18:31:38 | In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leadin | |
| CVE-2026-67270 | 8.2 | 0.12% | 1 | 0 | 2026-10-06T18:31:38 | Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Impro | |
| CVE-2026-76105 | 7.7 | 0.16% | 1 | 0 | 2026-10-06T18:31:38 | Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of In | |
| CVE-2026-61411 | 7.7 | 0.38% | 1 | 0 | 2026-10-06T18:31:37 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertio | |
| CVE-2026-105778 | 9.9 | 0.48% | 1 | 0 | 2026-10-06T18:16:46.563000 | A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this | |
| CVE-2026-105691 | 9.9 | 0.37% | 1 | 0 | 2026-10-06T17:17:18.470000 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the S | |
| CVE-2026-105793 | 9.1 | 0.86% | 1 | 0 | 2026-10-06T16:17:05.703000 | Microsoft UFO is an open-source framework for intelligent automation across devi | |
| CVE-2026-105845 | 9.8 | 0.38% | 1 | 0 | 2026-10-06T16:09:18 | ### Impact A user can submit a request that exploits a SQL Injection vulnerabili | |
| CVE-2026-82531 | 8.1 | 0.82% | 1 | 1 | 2026-10-06T16:00:36.547000 | Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability | |
| CVE-2026-105796 | 8.8 | 0.90% | 1 | 0 | 2026-10-06T15:36:01 | ### Impact An attacker who controls or tampers with an OpenAPI description can | |
| CVE-2026-104850 | 7.5 | 0.18% | 1 | 0 | 2026-10-06T15:35:44 | ### Summary In affected versions, the SDK's OAuth client let the MCP server deci | |
| CVE-2026-63688 | 10.0 | 0.79% | 1 | 0 | 2026-10-06T15:32:11 | Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Miss | |
| CVE-2026-63692 | 10.0 | 0.65% | 1 | 0 | 2026-10-06T15:32:11 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing A | |
| CVE-2026-54472 | 9.8 | 0.54% | 1 | 0 | 2026-10-06T15:32:06 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of H | |
| CVE-2026-91140 | 9.6 | 1.92% | 1 | 0 | 2026-10-06T15:32:06 | An OS command injection vulnerability in the shell-based temporary-file cleanup | |
| CVE-2026-61421 | 9.8 | 0.34% | 1 | 0 | 2026-10-06T15:32:04 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of H | |
| CVE-2026-67269 | 9.9 | 0.53% | 1 | 0 | 2026-10-06T15:18:44.910000 | Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains | |
| CVE-2026-84411 | 9.8 | 0.95% | 1 | 0 | 2026-10-06T15:15:48.310000 | The web management service in affected RouterOS versions contains an integer und | |
| CVE-2026-91107 | 0 | 0.24% | 1 | 0 | 2026-10-06T15:08:38.397000 | openSIS Classic 9.3 allows an authenticated user with the built-in teacher role | |
| CVE-2026-96940 | 8.8 | 0.50% | 2 | 1 | 2026-10-06T15:05:34.080000 | Weak authorization in Microsoft Exchange Server allows an authenticated attacker | |
| CVE-2026-42415 | 9.3 | 0.25% | 1 | 0 | 2026-10-06T15:04:25.990000 | Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions. | |
| CVE-2026-100511 | 8.8 | 0.36% | 1 | 0 | 2026-10-06T15:04:25.990000 | Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Pos | |
| CVE-2026-105642 | 8.8 | 0.25% | 1 | 0 | 2026-10-06T15:03:59.427000 | Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image | |
| CVE-2026-59265 | 8.8 | 0.43% | 1 | 1 | 2026-10-06T14:17:45.660000 | A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and | |
| CVE-2026-41555 | 9.3 | 0.25% | 1 | 0 | 2026-10-06T09:31:35 | Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptio | |
| CVE-2026-42417 | 9.3 | 0.33% | 1 | 0 | 2026-10-06T09:31:35 | Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions. | |
| CVE-2026-94293 | 9.8 | 0.35% | 2 | 0 | 2026-10-06T09:31:31 | An unauthenticated remote attacker can modify Asset Administration Shell submode | |
| CVE-2026-75962 | 7.2 | 0.28% | 1 | 0 | 2026-10-06T06:30:43 | The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, | |
| CVE-2026-105484 | 10.0 | 2.13% | 1 | 0 | 2026-10-06T03:31:28 | A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230 | |
| CVE-2026-103066 | 8.5 | 0.26% | 1 | 0 | 2026-10-05T21:31:46 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-97257 | 8.8 | 0.36% | 1 | 0 | 2026-10-05T21:31:46 | Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Plan | |
| CVE-2026-58841 | 7.8 | 0.07% | 1 | 0 | 2026-10-05T21:31:40 | In multiple functions of VirtualAudioControllerTest.java, there is a possible pe | |
| CVE-2026-58815 | 7.8 | 0.07% | 1 | 0 | 2026-10-05T21:31:40 | In multiple locations, there is a possible out of bounds write due to an incorre | |
| CVE-2026-49933 | 7.8 | 0.07% | 1 | 0 | 2026-10-05T21:31:39 | In handle_le_monitor_device_event of msft.cc, there is a possible control-flow h | |
| CVE-2026-45524 | 8.8 | 0.07% | 1 | 0 | 2026-10-05T21:31:39 | In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due | |
| CVE-2026-49937 | 7.8 | 0.07% | 1 | 0 | 2026-10-05T21:31:39 | In multiple functions of MessageQueueBase.h, there is a possible out of bounds r | |
| CVE-2026-55266 | 7.8 | 0.07% | 1 | 0 | 2026-10-05T21:31:39 | In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write du | |
| CVE-2026-58854 | 7.8 | 0.07% | 1 | 0 | 2026-10-05T21:31:39 | In multiple locations, there is a possible memory corruption due to type confusi | |
| CVE-2026-55286 | 7.8 | 0.07% | 1 | 0 | 2026-10-05T21:31:39 | In stpropnci_process of stpropnci.cc, there is a possible out of bounds write du | |
| CVE-2026-55280 | 8.8 | 0.23% | 1 | 0 | 2026-10-05T21:31:39 | In multiple locations, there is a possible out-of-bounds write due to uninitiali | |
| CVE-2026-55270 | 7.8 | 0.07% | 1 | 0 | 2026-10-05T21:31:39 | In dialInternal in multiple locations, there is a possible permission bypass due | |
| CVE-2026-103334 | 7.5 | 0.32% | 1 | 0 | 2026-10-05T21:31:38 | Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web De | |
| CVE-2026-58859 | 7.8 | 0.07% | 1 | 0 | 2026-10-05T21:31:36 | In multiple places, there is a possible denial of service due to an uncaught ex | |
| CVE-2026-105636 | 9.9 | 0.35% | 1 | 0 | 2026-10-05T19:17:17.827000 | Plane is an open-source project management tool. Prior to 1.4.0, the webhook del | |
| CVE-2026-88779 | 7.5 | 0.59% | 4 | 2 | 2026-10-05T15:33:23 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: b | |
| CVE-2026-63277 | None | 0.14% | 3 | 1 | 2026-10-05T12:31:34 | LibreOffice Calc can link a cell range to an external data source, and the link | |
| CVE-2026-18397 | 0 | 0.34% | 2 | 0 | 2026-10-02T20:17:02.060000 | This vulnerability enables unauthenticated remote code execution (RCE) on a vict | |
| CVE-2026-91135 | 0 | 0.46% | 1 | 0 | 2026-10-02T18:17:06.963000 | Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. | |
| CVE-2026-90970 | 9.9 | 0.94% | 1 | 1 | 2026-10-02T15:31:37 | GitLab has remediated a vulnerability in the GitLab AI Gateway component affecti | |
| CVE-2026-88771 | 9.8 | 1.08% | 3 | 13 | 2026-09-29T04:18:01.603000 | Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc | |
| CVE-2026-88772 | 8.1 | 1.30% | 1 | 8 | 2026-09-28T12:32:09 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue | |
| CVE-2026-93485 | 7.1 | 0.38% | 1 | 4 | 2026-09-18T06:32:17 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2026-68508 | 7.8 | 0.46% | 1 | 0 | 2026-08-21T20:57:32 | ## Summary `hydra.utils.instantiate()` resolves and calls Python objects from c | |
| CVE-2026-61500 | 9.8 | 0.99% | 4 | 1 | 2026-07-13T18:31:00 | Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the | |
| CVE-2025-54769 | 8.8 | 3.33% | 1 | 2 | 2026-06-17T09:40:40.793000 | An authenticated, read-only user can upload a file and perform a directory trave | |
| CVE-2026-35273 | 9.8 | 9.44% | 4 | 4 | template | 2026-06-12T18:31:50 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS |
| CVE-2013-3900 | 7.4 | 44.65% | 1 | 15 | 2025-10-22T03:31:39 | The WinVerifyTrust function in Microsoft Windows XP SP2 and SP3, Windows Server | |
| CVE-2024-7971 | 8.8 | 21.10% | 1 | 2 | 2025-10-22T00:34:11 | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote at | |
| CVE-2021-26085 | 5.3 | 99.94% | 1 | 2 | template | 2025-10-22T00:33:23 | Affected versions of Atlassian Confluence Server allow remote attackers to view |
| CVE-2021-35394 | 9.8 | 99.88% | 1 | 0 | template | 2025-10-22T00:33:23 | Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called |
| CVE-2026-107212 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-107216 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-59816 | 0 | 0.36% | 1 | 0 | N/A | ||
| CVE-2026-107215 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-107214 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-61748 | 0 | 0.42% | 1 | 0 | N/A | ||
| CVE-2026-77459 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-103059 | 0 | 0.16% | 1 | 0 | N/A | ||
| CVE-2026-103416 | 0 | 0.21% | 1 | 0 | N/A | ||
| CVE-2026-106445 | 0 | 0.41% | 1 | 0 | N/A | ||
| CVE-2026-106446 | 0 | 0.64% | 1 | 0 | N/A | ||
| CVE-2026-105797 | 0 | 0.56% | 1 | 0 | N/A | ||
| CVE-2026-61744 | 0 | 0.51% | 1 | 0 | N/A | ||
| CVE-2026-106113 | 0 | 0.35% | 1 | 0 | N/A | ||
| CVE-2026-106112 | 0 | 0.35% | 1 | 0 | N/A | ||
| CVE-2026-106115 | 0 | 0.35% | 1 | 0 | N/A | ||
| CVE-2026-105859 | 0 | 0.35% | 1 | 0 | N/A | ||
| CVE-2026-105858 | 0 | 0.48% | 1 | 0 | N/A | ||
| CVE-2026-105857 | 0 | 0.43% | 1 | 0 | N/A | ||
| CVE-2026-105865 | 0 | 0.37% | 1 | 0 | N/A | ||
| CVE-2026-100754 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-105763 | 0 | 0.28% | 2 | 0 | N/A | ||
| CVE-2026-105637 | 0 | 0.32% | 1 | 0 | N/A | ||
| CVE-2026-105744 | 0 | 0.30% | 1 | 0 | N/A | ||
| CVE-2026-105740 | 0 | 0.59% | 1 | 0 | N/A | ||
| CVE-2026-105697 | 0 | 0.40% | 1 | 0 | N/A | ||
| CVE-2026-105650 | 0 | 0.33% | 1 | 0 | N/A | ||
| CVE-2026-105675 | 0 | 0.39% | 1 | 0 | N/A | ||
| CVE-2026-105634 | 0 | 0.29% | 1 | 0 | N/A |
updated 2026-10-07T19:17:42.637000
1 posts
🟠 CVE-2026-79806 - High (7.8)
A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79806/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T19:17:42.403000
1 posts
🟠 CVE-2026-79803 - High (8.8)
A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79803/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T19:17:42.033000
1 posts
🟠 CVE-2026-79800 - High (8.8)
An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79800/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T19:17:40.650000
2 posts
🔴 CVE-2026-76464 - Critical (9.6)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76464/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76464 - Critical (9.6)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76464/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T19:17:35.867000
2 posts
ASUS Router XSS (CVE-2026-14911, CRITICAL, CVSS 9.3): Remote attackers can exploit improper input neutralization to execute scripts, alter settings, or cause DoS if visited by authenticated users. No patch yet. Details: https://radar.offseq.com/threat/cve-2026-14911-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-81fca42ab40cabc9 #OffSeq #XSS #Cybersecurity
##Four ASUS router vulnerabilities are fixed, including critical XSS flaw CVE-2026-14911 and code execution bug CVE-2026-19386. Update firmware now.
#ASUS #ASUSRouter #RouterSecurity #CVE202614911 #CVE202619386 #XSS #FirmwareUpdate #Vulnerability
##updated 2026-10-07T19:17:34.287000
2 posts
🟠 CVE-2026-107219 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, agile decryption accepts an attacker-controlled spinCount and performs that many password-key derivation iterations before verifier valid...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107219/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107219 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, agile decryption accepts an attacker-controlled spinCount and performs that many password-key derivation iterations before verifier valid...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107219/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T19:17:33.957000
2 posts
🟠 CVE-2026-107217 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 val...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107217/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107217 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 val...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107217/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:33:12
5 posts
Chat, is it bad if your zero-trust VPN device forwards network requests without auth? Asking for thousands of friends.
SonicWall SMA1000 devices have a SSRF vulnerability that needs patching.
https://ifin.network/t/cve-2026-102255-pre-auth-ssrf-in-sonicwall-sma1000-devices/889
##Chat, is it bad if your zero-trust VPN device forwards network requests without auth? Asking for thousands of friends.
SonicWall SMA1000 devices have a SSRF vulnerability that needs patching.
https://ifin.network/t/cve-2026-102255-pre-auth-ssrf-in-sonicwall-sma1000-devices/889
##Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/
##new SonicWall SMA1000 advisory. Check out CVE-2026-102255 (10.0 critical) Pre-authentication SSRF via unintended forward-proxy. No mention of exploitation, but it's not a good look that your Secure Mobile Access is not secure (including four known exploited vulnerabilities in the past 90 days)
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017
##SonicWall SMA1000 vulnerability CVE-2026-102255 (CVSS 10) allows pre-auth SSRF. Three more flaws fixed. Upgrade to 12.5.0-03082 now.
#SonicWall #SMA1000 #CVE2026102255 #CVE2026102256 #SSRF #RemoteAccess #VPN #Vulnerability
##updated 2026-10-07T18:32:21
2 posts
🔴 CVE-2026-76483 - Critical (9.1)
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76483/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76483 - Critical (9.1)
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76483/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
2 posts
🟠 CVE-2026-96335 - High (7.5)
Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Forminator: from n/a through 1.57.2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-96335/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-96335 - High (7.5)
Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Forminator: from n/a through 1.57.2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-96335/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
2 posts
🔴 CVE-2026-76480 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76480/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76480 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76480/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
2 posts
🟠 CVE-2026-76472 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multipl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76472/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76472 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multipl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76472/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
4 posts
🔴 CVE-2026-76471 - Critical (9.8)
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.
The vulnerabi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76471/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Cisco NX-OS vulnerabilities fixed, including critical NX-API RCE flaw CVE-2026-76471 and CVE-2026-76455, across Nexus, MDS and UCS gear. Patch now.
#Cisco #NXOS #Nexus #CVE202676471 #CVE202676455 #RCE #NetworkSecurity #Vulnerability
##🔴 CVE-2026-76471 - Critical (9.8)
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.
The vulnerabi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76471/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Cisco NX-OS vulnerabilities fixed, including critical NX-API RCE flaw CVE-2026-76471 and CVE-2026-76455, across Nexus, MDS and UCS gear. Patch now.
#Cisco #NXOS #Nexus #CVE202676471 #CVE202676455 #RCE #NetworkSecurity #Vulnerability
##updated 2026-10-07T18:32:21
2 posts
🟠 CVE-2026-76470 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76470/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76470 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76470/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
2 posts
🔴 CVE-2026-76499 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76499/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76499 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76499/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
2 posts
🔴 CVE-2026-76498 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76498 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
2 posts
🔴 CVE-2026-76486 - Critical (9.8)
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76486/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76486 - Critical (9.8)
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76486/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
4 posts
🔴 CVE-2026-76485 - Critical (9.8)
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76485/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Four critical Cisco Nexus vulnerabilities, including CVE-2026-76485 and CVE-2026-76465 (CVSS 9.8), allow root RCE on NX-OS switches. Patch now.
#Cisco #Nexus #NXOS #CVE202676485 #CVE202676465 #RCE #NetworkSecurity #Vulnerability
##🔴 CVE-2026-76485 - Critical (9.8)
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76485/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Four critical Cisco Nexus vulnerabilities, including CVE-2026-76485 and CVE-2026-76465 (CVSS 9.8), allow root RCE on NX-OS switches. Patch now.
#Cisco #Nexus #NXOS #CVE202676485 #CVE202676465 #RCE #NetworkSecurity #Vulnerability
##updated 2026-10-07T18:32:21
2 posts
🟠 CVE-2026-76484 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76484/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76484 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76484/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:21
2 posts
🔴 CVE-2026-95605 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection.
This issue affects WP Data Access: from n/a through 5.5.82.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-95605/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-95605 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection.
This issue affects WP Data Access: from n/a through 5.5.82.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-95605/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:20
4 posts
🔴 CVE-2026-76482 - Critical (10)
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Cisco License On-Prem vulnerabilities include CVSS 10 flaw CVE-2026-76482 and password reset bug CVE-2026-20328. APIC and Meraki also patched.
#Cisco #SmartLicensing #APIC #Meraki #CVE202676482 #CVE202620328 #PatchNow #Vulnerability
##🔴 CVE-2026-76482 - Critical (10)
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Cisco License On-Prem vulnerabilities include CVSS 10 flaw CVE-2026-76482 and password reset bug CVE-2026-20328. APIC and Meraki also patched.
#Cisco #SmartLicensing #APIC #Meraki #CVE202676482 #CVE202620328 #PatchNow #Vulnerability
##updated 2026-10-07T18:32:14
2 posts
🔴 CVE-2026-76500 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76500/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76500 - Critical (9.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in softwar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76500/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:14
2 posts
Cisco License On-Prem vulnerabilities include CVSS 10 flaw CVE-2026-76482 and password reset bug CVE-2026-20328. APIC and Meraki also patched.
#Cisco #SmartLicensing #APIC #Meraki #CVE202676482 #CVE202620328 #PatchNow #Vulnerability
##Cisco License On-Prem vulnerabilities include CVSS 10 flaw CVE-2026-76482 and password reset bug CVE-2026-20328. APIC and Meraki also patched.
#Cisco #SmartLicensing #APIC #Meraki #CVE202676482 #CVE202620328 #PatchNow #Vulnerability
##updated 2026-10-07T18:32:14
2 posts
🔴 CVE-2026-76501 - Critical (9.8)
A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privilege...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76501/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76501 - Critical (9.8)
A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privilege...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76501/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:14
2 posts
🔴 CVE-2026-107206 - Critical (9.4)
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read envir...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107206/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-107206 - Critical (9.4)
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read envir...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107206/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:14
2 posts
🔴 CVE-2026-107204 - Critical (9.8)
LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected Fast...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107204/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-107204 - Critical (9.8)
LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected Fast...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107204/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:32:14
2 posts
There are 14 Cisco security advisories that came out today. https://sec.cloudapps.cisco.com/security/center/publicationListing.x
A lot of 9.8 and even 10.0 across multiple products. While there's no mention of exploitation, there's zero-day disclosure pre-patch for Cisco Finesse Server-Side Request Forgery Vulnerability CVE-2026-20362 (7.2)
##The Cisco PSIRT is aware that a public announcement is available for the vulnerability that is described in this advisory.
There are 14 Cisco security advisories that came out today. https://sec.cloudapps.cisco.com/security/center/publicationListing.x
A lot of 9.8 and even 10.0 across multiple products. While there's no mention of exploitation, there's zero-day disclosure pre-patch for Cisco Finesse Server-Side Request Forgery Vulnerability CVE-2026-20362 (7.2)
##The Cisco PSIRT is aware that a public announcement is available for the vulnerability that is described in this advisory.
updated 2026-10-07T18:32:14
2 posts
Two Apache Jackrabbit vulnerabilities, including critical session hijack flaw CVE-2026-92414 (CVSS 9.3), are fixed. Upgrade to 2.23.6 now.
#Apache #Jackrabbit #WebDAV #CVE202692414 #CVE202692415 #SessionHijack #Java #Vulnerability
##Two Apache Jackrabbit vulnerabilities, including critical session hijack flaw CVE-2026-92414 (CVSS 9.3), are fixed. Upgrade to 2.23.6 now.
#Apache #Jackrabbit #WebDAV #CVE202692414 #CVE202692415 #SessionHijack #Java #Vulnerability
##updated 2026-10-07T18:17:31.910000
2 posts
🔴 CVE-2026-95606 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection.
This issue affects The Events Calendar: from n/a through 6.17.4.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-95606/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-95606 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection.
This issue affects The Events Calendar: from n/a through 6.17.4.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-95606/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:17:31.777000
2 posts
🟠 CVE-2026-95534 - High (8.8)
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection.
This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-95534/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-95534 - High (8.8)
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection.
This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-95534/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:17:28.580000
4 posts
🔴 CVE-2026-76465 - Critical (9.8)
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76465/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Four critical Cisco Nexus vulnerabilities, including CVE-2026-76485 and CVE-2026-76465 (CVSS 9.8), allow root RCE on NX-OS switches. Patch now.
#Cisco #Nexus #NXOS #CVE202676485 #CVE202676465 #RCE #NetworkSecurity #Vulnerability
##🔴 CVE-2026-76465 - Critical (9.8)
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76465/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Four critical Cisco Nexus vulnerabilities, including CVE-2026-76485 and CVE-2026-76465 (CVSS 9.8), allow root RCE on NX-OS switches. Patch now.
#Cisco #Nexus #NXOS #CVE202676485 #CVE202676465 #RCE #NetworkSecurity #Vulnerability
##updated 2026-10-07T18:17:21.317000
2 posts
🟠 CVE-2026-76457 - High (8.6)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76457 - High (8.6)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:17:16.660000
2 posts
🟠 CVE-2026-106510 - High (7.7)
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by remote code execution via crafted markdown_extensions in techdocs mkdocs.yml. An authenticated user who can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-106510 - High (7.7)
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by remote code execution via crafted markdown_extensions in techdocs mkdocs.yml. An authenticated user who can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:17:15.427000
2 posts
LMCache Flaw Exposes Servers to Remote Code Execution
A newly discovered flaw, CVE-2026-105192, allows hackers to send a single network message that can execute malicious code on vulnerable LMCache multiprocess cache servers, with no patch available yet. This vulnerability can be exploited when the multiprocess server is configured to listen on a routable address, making it a serious threat to…
#RemoteCodeExecution #Zeromq #Lmcache #Cve2026105192 #EmergingThreats
##what. the. fuck.
https://nvd.nist.gov/vuln/detail/cve-2026-105192
sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
##LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as. Official container images run that process as root. The transport binds to localhost unless the operator sets a routable address with --host, which is how multi-node deployments let peers connect.
updated 2026-10-07T18:17:15.240000
1 posts
2 repos
https://github.com/techupdate24/fortimail-zero-day-cve-2026-104286
Recent news highlights critical cybersecurity threats as Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-104286) zero-days are under active exploitation, targeting critical infrastructure and government entities. Apple also patched an exploited CoreGraphics flaw. In geopolitical developments, the Mecca Defense Alliance agreed to immediately implement collective defense commitments. On the technology front, MediaTek showcased advancements in Wi-Fi 8 with its Filogic 8800.
##updated 2026-10-07T18:05:51
1 posts
🟠 CVE-2026-106443 - High (8.8)
WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image d...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106443/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:03:56
1 posts
🟠 CVE-2026-106441 - High (7.8)
Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106441/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:03:50
1 posts
🟠 CVE-2026-106442 - High (7.8)
Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. E...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106442/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T18:03:15
2 posts
🟠 CVE-2026-106558 - High (8.8)
Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106558/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-106558 - High (8.8)
Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106558/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T17:17:02.300000
1 posts
🟠 CVE-2026-77226 - High (8.1)
Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77226/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T17:16:59.680000
2 posts
🟠 CVE-2026-76468 - High (8.2)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76468/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76468 - High (8.2)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76468/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T17:16:59.503000
2 posts
🟠 CVE-2026-76467 - High (7.5)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76467/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76467 - High (7.5)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76467/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T17:16:58.833000
2 posts
🟠 CVE-2026-76463 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76463/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76463 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mult...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76463/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T17:16:58.553000
2 posts
🟠 CVE-2026-76459 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76459/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76459 - High (8.8)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76459/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T17:16:58.280000
2 posts
🟠 CVE-2026-76458 - High (8.6)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76458/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76458 - High (8.6)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76458/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T17:16:57.520000
2 posts
Cisco NX-OS vulnerabilities fixed, including critical NX-API RCE flaw CVE-2026-76471 and CVE-2026-76455, across Nexus, MDS and UCS gear. Patch now.
#Cisco #NXOS #Nexus #CVE202676471 #CVE202676455 #RCE #NetworkSecurity #Vulnerability
##Cisco NX-OS vulnerabilities fixed, including critical NX-API RCE flaw CVE-2026-76471 and CVE-2026-76455, across Nexus, MDS and UCS gear. Patch now.
#Cisco #NXOS #Nexus #CVE202676471 #CVE202676455 #RCE #NetworkSecurity #Vulnerability
##updated 2026-10-07T17:16:53.790000
2 posts
🟠 CVE-2026-107205 - High (8.6)
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to access its HTTP fleet control API listening on all interfaces by default. Attackers can register ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107205/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107205 - High (8.6)
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to access its HTTP fleet control API listening on all interfaces by default. Attackers can register ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107205/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T16:18:59.520000
1 posts
🔴 CVE-2026-79796 - Critical (9.8)
Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79796/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T16:18:57
1 posts
🟠 CVE-2026-106118 - High (7.5)
ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, tiled TIFF decoding allocates a destination buffer using TileWidth but TiffDecompressorsFactory.Create constructs T4, T6, and Modified Huffman decompressors using the full frame width. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106118/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T16:18:52
1 posts
🟠 CVE-2026-106117 - High (7.5)
ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, decoding a strip TIFF using CCITT Group 3 or Modified Huffman compression can pass attacker-expanded runs to BitWriterUtils.WriteBits without first checking the current row width. T4Tiff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106117/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T16:17:31.953000
1 posts
A Gitea security update fixes 27 flaws, including SSRF bug CVE-2026-101027 and SSH key flaw CVE-2026-103059. Upgrade to Gitea 28.1.0 now.
#Gitea #Git #DevSecOps #SSRF #CVE2026101027 #CVE2026103059 #SupplyChainSecurity #Vulnerability
https://securityonline.info/gitea-security-update-28/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-10-07T16:14:23
1 posts
🔴 CVE-2026-106102 - Critical (10)
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, met...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106102/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T15:32:31
1 posts
2 repos
CVE-2026-102489 Deep-Dive: Zammad Session Leak to RCE https://horizon3.ai/attack-research/disclosures/cve-2026-102489-zammad-session-leak-rce/
##updated 2026-10-07T15:32:08
2 posts
🟠 CVE-2026-77214 - High (8.2)
libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77214/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77214 - High (8.2)
libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77214/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T15:31:33
22 posts
7 repos
https://github.com/MarcusProgram/CVE-2026-21589
https://github.com/aduli198/CVE-2026-21589
https://github.com/ynsmroztas/AtlasSniper
https://github.com/tc4dy/CVE-2026-21589-PoC-Exploit
https://github.com/0xBlackash/CVE-2026-21589
https://github.com/BimBoxH4/CVE-2026-21589
https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589
Scans for Atlassian vulnerablity (CVE-2026-21589)
#CVE_2026_21589
https://isc.sans.edu/diary/rss/33406
Recent developments include the US evacuating B-1 bombers from the UK due to an Iranian threat, while Hamas is reportedly plotting attacks in Gaza for October 7th. In cybersecurity, ASOS experienced a cloud breach via its Snowflake platform, and active exploitation of a critical Atlassian flaw (CVE-2026-21589) has begun. An FBI breach was also linked to a contractor error. Microsoft is hosting an AI-focused Surface event today.
##Scans for Atlassian vulnerablity (CVE-2026-21589)
#CVE_2026_21589
https://isc.sans.edu/diary/rss/33406
Recent developments include the US evacuating B-1 bombers from the UK due to an Iranian threat, while Hamas is reportedly plotting attacks in Gaza for October 7th. In cybersecurity, ASOS experienced a cloud breach via its Snowflake platform, and active exploitation of a critical Atlassian flaw (CVE-2026-21589) has begun. An FBI breach was also linked to a contractor error. Microsoft is hosting an AI-focused Surface event today.
##Unauthenticated arbitrary file access in eight self-hosted Atlassian families (CVE-2026-21589) is seeing active probing after public PoC release. Exploitation requires exact file path and is limited to web root, without directory listing. Data Center operators should patch and reduce exposure promptly. #Atlassian #DataCenter #ThreatIntel
https://cyberworldops.eu/en/public-exploit-code-triggers-rapid-probing-of-eight-atlassian-product
##Scans for Atlassian vulnerablity (CVE-2026-21589) https://isc.sans.edu/diary/33406
##Atlassian Warns of Critical Flaw Affecting Eight Self-Managed Products
Atlassian's CVE-2026-21589 lets unauthenticated attackers read files in Confluence and seven other Data Center products.
🔗️ [Thecyberexpress] https://link.is.it/gJ99W6
##Hackers exploit critical Atlassian flaw after public PoC release
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being...
🔗️ [Bleepingcomputer] https://link.is.it/J8wKmL
##An unauthenticated attacker can exploit CVE-2026-21589 to access specific files in the application's web root directory if they know the file's exact name and path. https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-atlassian-flaw-after-public-poc-release/
##You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
#CVE_2026_21589 #Bitbucket #Confluence #Jira #AtlassianBamboo #AtlassianCrowd
https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
CVE-2026-21589 exploitation is underway against Atlassian servers after researchers published arbitrary file read PoC and technical details.
#Atlassian #Jira #Confluence #Bitbucket #CVE202621589 #PathTraversal #ExploitedInTheWild #Vulnerability
##OK, this is an innovative directory traversal vuln:
GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1
This is from CVE-2026-21589, https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
The "::" gets replaced with "/" by some weird sanitation method, read more about it in the writeup.
Tagging @nynbinary for humorous memeing.
##@watchTowr is a machine that turns funny blog posts about Secure By Design products into future CISA KEV Catalog additions. This time it's Atlassian pre-auth arbitrary file read CVE-2026-21589 (9.3 critical). Given that there's a similar "Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability" (CVE-2021-26085) in CISA's KEV, I'd take patching this seriously before the threat actors find out.
Atlassian warns of critical file-access flaw in Jira, Confluence
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple...
🔗️ [Bleepingcomputer] https://link.is.it/yyKkUz
##You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
##Atlassian has disclosed "arbitrary file access" (cough cough path traversal) in...basically everything. Patches available, but so now is a broad proof-of-concept. Not yet known-exploited, emphasis on "yet."
https://ifin.network/t/cve-2026-21589-arbitrary-file-access-in-multiple-atlassian-products/885
##New.
WatchTower: You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/ @watchTowr #infosec #vulnerability #Atlassian
##https://fawkes.rocks/2026/10/06/atlassian-data-center-flaw-cve-2026-21589-needs-urgent-fix/
##https://thecybersecguru.com/exploits/cve-2026-21589-atlassian-vulnerability/
##Recent cybersecurity threats include Atlassian patching critical vulnerabilities (CVE-2026-21589) in Jira, Confluence, and Bitbucket enabling file access. The FBI removed an Accenture contractor after a ShinyHunters breach of employee data via an unpatched Oracle PeopleSoft flaw (CVE-2026-35273). In technology, OpenAI's GPT-6 Astra model demonstrated supply-chain attack behavior in simulations. Geopolitically, the Mecca Defense Alliance committed to collective defense measures on October 5, 2026.
##Atlassian Data Center vulnerability CVE-2026-21589 (CVSS 9.3) allows arbitrary file access in Jira, Confluence and Bitbucket. Patch now.
#Atlassian #Jira #Confluence #Bitbucket #CVE202621589 #PathTraversal #DataCenter #Vulnerability
##CVE-2026-21589 (CRITICAL, CVSS 9.3) in Atlassian Bamboo Data Center <10.2.24: Unauthenticated path traversal enables arbitrary file read/write (if file path is known). Patch to 10.2.24+ required — no workarounds. Details: https://radar.offseq.com/threat/cve-2026-21589-path-traversal-arbitrary-readwrite-in-atlassian-bamboo-data-center-24a2d0e4e6de8f44 #OffSeq #Atlassian #Infosec
##updated 2026-10-07T15:12:08.233000
1 posts
🟠 CVE-2026-58835 - High (8.8)
In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58835/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T15:10:08.650000
1 posts
🟠 CVE-2026-55269 - High (7.8)
In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55269/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T14:44:18.807000
1 posts
Nine HPE AOS-Switch vulnerabilities, including unauthenticated RCE flaw CVE-2026-76744 (CVSS 9.8), are fixed. Upgrade to AOS-S 16.11.0032.
#HPE #ArubaNetworking #AOSSwitch #CVE202676744 #CVE202676742 #RCE #NetworkSecurity #Vulnerability
##updated 2026-10-07T13:42:52.070000
1 posts
Elastic fixes 14 Elastic Stack vulnerabilities, including Kibana flaw CVE-2026-102406 and Elasticsearch bug CVE-2026-103007. Upgrade now.
#Elastic #Elasticsearch #Kibana #ElasticDefend #CVE2026102406 #CVE2026103007 #DataSecurity #Vulnerability
##updated 2026-10-07T13:03:47.930000
1 posts
🟠 CVE-2026-49885 - High (7.8)
In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49885/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T12:32:00
1 posts
CVE-2026-96408 (CRITICAL): Movable Type Cloud Edition (v2.0 – 9.2.1) hit by code injection in upgrade script — unauthenticated attackers can execute Perl/SQL. No patch yet; restrict script access. https://radar.offseq.com/threat/cve-2026-96408-code-injection-in-six-apart-ltd-movable-type-cloud-edition-535c78e66ddee34d #OffSeq #CVE202696408 #infosec #vuln
##updated 2026-10-07T09:32:29
3 posts
Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 from 10/6
CVE-2025-64393 (9.4 critical) low-privileged RCE
##Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 from 10/6
CVE-2025-64393 (9.4 critical) low-privileged RCE
##Critical Veeam Backup vulnerability CVE-2025-64393 (CVSS 9.4) enables RCE by low-privileged users. Update to 12.3.2 P4 now.
#Veeam #VeeamBackup #CVE202564393 #RCE #Deserialization #Ransomware #BackupSecurity #Vulnerability
##updated 2026-10-07T09:32:29
1 posts
Manacle Technologies Multi-tenant ERP System hit by CVE-2026-107104 (CRITICAL, CVSS 9.3): Unsafe deserialization lets unauthenticated attackers execute code remotely. No fix yet — restrict access & monitor systems. https://radar.offseq.com/threat/cve-2026-107104-cwe-502-deserialization-of-untrusted-data-in-manacle-technologies-multi-tenant-erp-9e646ff6d0c210e4 #OffSeq #CVE2026107104 #ERP #infosec
##updated 2026-10-07T06:33:01
1 posts
Flexera FlexNet Publisher (≤11.19.11) suffers a CRITICAL auth bypass (CVE-2026-19572, CVSS 9.3). SOAP handler flaw allows unauthenticated admin access. Patch not yet available — monitor systems closely. https://radar.offseq.com/threat/cve-2026-19572-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-flexera-flexnet-56f758677e3ccac3 #OffSeq #CVE202619572 #infosec #vuln
##updated 2026-10-07T04:17:49.727000
1 posts
The Chrome 155 security update fixes 247 flaws, including critical use after free bugs CVE-2026-106382 and CVE-2026-106197. Update now.
#Chrome #GoogleChrome #Chrome155 #CVE2026106382 #UseAfterFree #BrowserSecurity #PatchNow #Vulnerability
##updated 2026-10-07T04:17:38.120000
1 posts
🟠 CVE-2026-101207 - High (8.8)
Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-101207/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-07T03:30:31
1 posts
wolfSSH <1.6.0 hit by CRITICAL vuln (CVE-2026-16516): ECDSA curve ID not verified in KEXDH_REPLY, allowing MitM signature bypass with weak key checks. Patch or harden key validation. https://radar.offseq.com/threat/cve-2026-16516-cwe-345-insufficient-verification-of-data-authenticity-in-wolfssl-inc-wolfssh-844e4ddf5288020d #OffSeq #wolfSSH #infosec #CVE202616516
##updated 2026-10-07T03:30:26
1 posts
1 repos
IBM Langflow OSS v1.0.0 – 1.12.2 is affected by CRITICAL code injection (CVE-2026-93674, CVSS 9.8). Remote code exec possible via improper OS command neutralization. No patch yet — restrict network access & monitor activity. https://radar.offseq.com/threat/cve-2026-93674-cwe-94-improper-control-of-generation-of-code-code-injection-in-ibm-langflow-oss-05d9c1873ab3c004 #OffSeq #IBM #Vuln #AppSec
##updated 2026-10-07T03:30:26
1 posts
IBM fixes 25 Langflow vulnerabilities, including critical RCE flaw CVE-2026-104334 (CVSS 9.8). Upgrade to Langflow 1.12.3 now.
#Langflow #IBM #AISecurity #CVE2026104334 #CVE202693674 #RCE #LLM #Vulnerability
##updated 2026-10-07T03:30:23
1 posts
Four ASUS router vulnerabilities are fixed, including critical XSS flaw CVE-2026-14911 and code execution bug CVE-2026-19386. Update firmware now.
#ASUS #ASUSRouter #RouterSecurity #CVE202614911 #CVE202619386 #XSS #FirmwareUpdate #Vulnerability
##updated 2026-10-07T03:30:23
1 posts
Critical ASUSTOR ADM vulnerability CVE-2026-105324 (CVSS 9.2) allows unauthenticated arbitrary file read on NAS devices. Update ADM now.
#ASUSTOR #ADM #NAS #CVE2026105324 #FileRead #HeaderInjection #DataProtection #Vulnerability
##updated 2026-10-06T21:32:09
1 posts
HPE fixes 28 ClearPass Policy Manager vulnerabilities, including unauthenticated RCE flaw CVE-2026-76750 (CVSS 9.8). Upgrade to CPPM 6.14.1.
#HPE #ClearPass #ArubaNetworking #CVE202676750 #CVE202676752 #RCE #NetworkAccessControl #Vulnerability
##updated 2026-10-06T21:32:09
1 posts
🟠 CVE-2026-79808 - High (7.8)
A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code with elevated privileges on the affected host or to disrupt the avai...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79808/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T21:32:09
1 posts
🟠 CVE-2026-79807 - High (7.8)
A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T21:32:09
1 posts
AMD RCCL vulnerability CVE-2026-43598 in the ROCm Communication Collectives Library could allow RCE on Instinct GPUs. Update to ROCm 7.14.
#AMD #ROCm #RCCL #CVE202643598 #AMDInstinct #GPUSecurity #AISecurity #Vulnerability
##updated 2026-10-06T21:32:02
1 posts
🟠 CVE-2026-79802 - High (8.8)
A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79802/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T21:32:02
1 posts
🔴 CVE-2026-79801 - Critical (9.8)
A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79801/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T21:32:02
1 posts
🟠 CVE-2026-79799 - High (8.8)
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful ex...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79799/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T21:32:02
1 posts
🔴 CVE-2026-79798 - Critical (9.9)
SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79798/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T21:32:02
1 posts
🟠 CVE-2026-79797 - High (8.8)
An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthentica...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79797/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T21:32:02
1 posts
🔴 CVE-2026-79805 - Critical (9.8)
An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79805/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T21:31:59
1 posts
🟠 CVE-2026-86361 - High (8.2)
Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86361/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T21:31:57
1 posts
Elastic fixes 14 Elastic Stack vulnerabilities, including Kibana flaw CVE-2026-102406 and Elasticsearch bug CVE-2026-103007. Upgrade now.
#Elastic #Elasticsearch #Kibana #ElasticDefend #CVE2026102406 #CVE2026103007 #DataSecurity #Vulnerability
##updated 2026-10-06T21:31:53
1 posts
Critical Arista CloudVision CUE vulnerability CVE-2026-102159 (CVSS 9.8) and five more flaws hit CV-CUE. Update to WiFi 2026.2.1 now.
#Arista #CloudVision #CVCUE #CVE2026102159 #CVE2026102161 #WiFiSecurity #NetworkSecurity #Vulnerability
##updated 2026-10-06T21:31:53
1 posts
🟠 CVE-2026-86362 - High (8.2)
Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86362/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T21:31:51
2 posts
Chrome 155 patches 247 vulnerabilities, including 4 CRITICAL use-after-free bugs (CVE-2026-106382, - 106197, - 106358, - 106347) across Chromecast, Browser, Navigation & Track. Update on Windows, macOS & Linux. No active exploits. https://radar.offseq.com/threat/chrome-155-update-patches-247-vulnerabilities-28750e8d96fdecb9 #OffSeq #Chrome #Security
##The Chrome 155 security update fixes 247 flaws, including critical use after free bugs CVE-2026-106382 and CVE-2026-106197. Update now.
#Chrome #GoogleChrome #Chrome155 #CVE2026106382 #UseAfterFree #BrowserSecurity #PatchNow #Vulnerability
##updated 2026-10-06T21:31:41
1 posts
🟠 CVE-2026-104073 - High (7.6)
NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Djang...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104073/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T20:17:34.090000
2 posts
🔴 CVE-2026-86360 - Critical (9.6)
Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86360/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Dell PowerEdge : une faille critique permet d’exécuter du code en tant que root sur les serveurs https://www.it-connect.fr/dell-system-update-faille-critique-cve-2026-86360/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Dell
##updated 2026-10-06T20:05:55.733000
2 posts
Someone needs to check on the USMC.
https://nvd.nist.gov/vuln/detail/cve-2026-104070
##The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.
🔴 CVE-2026-104070 - Critical (9.8)
The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104070/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T20:03:40.690000
1 posts
🟠 CVE-2026-106440 - High (7.8)
Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it with hyd...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106440/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T20:03:40.690000
1 posts
🟠 CVE-2026-106110 - High (7.5)
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106110/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T20:03:40.690000
1 posts
🟠 CVE-2026-105862 - High (8.7)
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105862/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T19:58:37.060000
1 posts
🟠 CVE-2026-63697 - High (7.6)
Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63697/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T19:58:37.060000
1 posts
🔴 CVE-2026-67273 - Critical (9.6)
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67273/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T18:31:38
1 posts
🟠 CVE-2026-106218 - High (8.8)
In JetBrains TeamCity before 2026.1.3
2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106218/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T18:31:38
1 posts
🟠 CVE-2026-67270 - High (8.2)
Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, lead...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T18:31:38
1 posts
🟠 CVE-2026-76105 - High (7.7)
Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76105/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T18:31:37
1 posts
🟠 CVE-2026-61411 - High (7.7)
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Informati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61411/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T18:16:46.563000
1 posts
CVE-2026-105778: CRITICAL stack-based buffer overflow in Tenda AC5 (v02.03.01.111_multi). Remote attackers can execute code via the /goform/setWifi endpoint. No patch yet — restrict remote access & monitor for exploits. https://radar.offseq.com/threat/cve-2026-105778-stack-based-buffer-overflow-in-tenda-ac5-d56799a413fc396a #OffSeq #CVE #Infosec #IoT
##updated 2026-10-06T17:17:18.470000
1 posts
🔴 CVE-2026-105691 - Critical (9.9)
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105691/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T16:17:05.703000
1 posts
🔴 CVE-2026-105793 - Critical (9.1)
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105793/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T16:09:18
1 posts
🔴 CVE-2026-105845 - Critical (9.8)
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105845/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T16:00:36.547000
1 posts
1 repos
CVE-2026-82531: CRITICAL code injection bug in smarty-php Smarty (<4.5.8, 5.0.0<5.8.5). Exploitation enables remote PHP code execution via forged nocache markers. Patch to 4.5.8/5.8.5 ASAP. https://radar.offseq.com/threat/cve-2026-82531-improper-control-of-generation-of-code-code-injection-in-smarty-php-smarty-eb57bcca29bb7350 #OffSeq #CVE #infosec #php
##updated 2026-10-06T15:36:01
1 posts
🟠 CVE-2026-105796 - High (8.8)
Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a termin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105796/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T15:35:44
1 posts
🟠 CVE-2026-104850 - High (7.5)
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide whi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104850/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T15:32:11
1 posts
🔴 CVE-2026-63688 - Critical (10)
Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63688/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T15:32:11
1 posts
🔴 CVE-2026-63692 - Critical (10)
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63692/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T15:32:06
1 posts
🔴 CVE-2026-54472 - Critical (9.8)
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Informatio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54472/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T15:32:06
1 posts
Progress DataDirect vulnerability CVE-2026-91140 enables command injection via crafted OpenAPI files in AI agents. Pull version 2.1 now.
#Progress #DataDirect #CVE202691140 #CommandInjection #AIAgents #OpenAPI #DevSecOps #Vulnerability
##updated 2026-10-06T15:32:04
1 posts
🔴 CVE-2026-61421 - Critical (9.8)
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to E...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61421/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T15:18:44.910000
1 posts
🔴 CVE-2026-67269 - Critical (9.9)
Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67269/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T15:15:48.310000
1 posts
🚨 RAPID RESPONSE: CVE-2026-84411 is a critical unauthenticated remote code execution vulnerability affecting MikroTik RouterOS web management.
Censys detects 364,341 Internet-exposed hosts running the RouterOS web management interface. Roughly 19,200 report RouterOS 7.x, and none currently report the patched 7.24 release or later.
The broader exposure count does not represent confirmed-vulnerable devices because the impact to RouterOS 6.x has not yet been established. No public exploitation has been reported.
Full Censys ARC advisory: https://censys.com/advisory/cve-2026-84411/
##updated 2026-10-06T15:08:38.397000
1 posts
CVE-2026-91107: CRITICAL auth bypass in openSIS-Classic 9.3 🛑. Teacher-role users can reset passwords of any staff via the staff_id parameter. No patch yet — restrict permissions & monitor password changes. https://radar.offseq.com/threat/cve-2026-91107-cwe-639-authorization-bypass-through-user-controlled-key-in-os4ed-opensis-classic-f7eb55a7a5a0f52d #OffSeq #Vulnerability #openSIS #CVE202691107
##updated 2026-10-06T15:05:34.080000
2 posts
1 repos
Microsoft Exchange : la faille CVE-2026-96940 permet de lire les boîtes aux lettres des autres utilisateurs https://www.it-connect.fr/exchange-server-cve-2026-96940/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft
##https://thecybersecguru.com/exploits/cve-2026-96940-microsoft-exchange-vulnerability/
##updated 2026-10-06T15:04:25.990000
1 posts
CRITICAL SQL injection (CVE-2026-42415) in p-themes Porto Theme - Functionality ≤3.9.3. Unauthenticated attackers can steal sensitive data. No official patch yet — restrict access ASAP. https://radar.offseq.com/threat/cve-2026-42415-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-3eb4b18a06bf1443 #OffSeq #CVE202642415 #Infosec #WordPress #SQLInjection
##updated 2026-10-06T15:04:25.990000
1 posts
🟠 CVE-2026-100511 - High (8.8)
Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-100511/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T15:03:59.427000
1 posts
🟠 CVE-2026-105642 - High (8.8)
Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105642/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-06T14:17:45.660000
1 posts
1 repos
⚠️ Obrir un full de càlcul i que s'executi codi sense cap avís de macro. Això és.
Afecta LibreOffice (CVE-2026-63277, arreglat a les 26.2.5/26.8.0) i Apache OpenOffice (CVE-2026-59265, encara sense pegat: desactiva Java). L'atac aprofita rangs de base de dades + JDBC per baixar un JAR maliciós. De moment només PoC, però funciona a Windows i Linux.
#ciberseguretat #LibreOffice #OpenOffice
https://blog.elhacker.net/2026/10/vulnerabilidades-en-libreoffice-y.html
updated 2026-10-06T09:31:35
1 posts
Unauthenticated SQL Injection (CVE-2026-41555, CRITICAL, CVSS 9.3) in Weblizar Newsletter Subscription Form <=1.5.9 impacts WordPress sites. Patch status unknown — restrict/disable the component. https://radar.offseq.com/threat/cve-2026-41555-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-07f0f81651ae4a40 #OffSeq #WordPress #Infosec #SQLInjection
##updated 2026-10-06T09:31:35
1 posts
CVE-2026-42417 (CRITICAL): ARMember Premium <= 7.8 is vulnerable to unauthenticated SQL Injection (CWE-89). No mitigation yet — review deployments & monitor databases closely. https://radar.offseq.com/threat/cve-2026-42417-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-559a21ef978d1d38 #OffSeq #Vulnerability #SQLInjection #WordPress
##updated 2026-10-06T09:31:31
2 posts
Murrelektronik won't fix AAS edge client vulnerability CVE-2026-94293 (CVSS 9.8), which allows unauthenticated data changes. Remove it now.
#Murrelektronik #AAS #CVE202694293 #ICS #OTSecurity #Industry40 #MissingAuthentication #Vulnerability
##🔒 New CSAF advisory published
VDE-2026-108
Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data
CVE-2026-94293
The aas-edge-client is a reference implementation of an Asset Administration Shell (AAS) edge application, published by Murrelektronik GmbH on GitHub for…
HTML: https://certvde.com/en/advisories/vde-2026-108/
CSAF JSON: https://murrelektronik.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-108.json
updated 2026-10-06T06:30:43
1 posts
CVE-2026-75962: HIGH severity stored XSS in Post SMTP WordPress plugin (<=4.0.1). Unauthenticated attackers can inject scripts via user_email on multisite with public registration. Patch or restrict registration. https://radar.offseq.com/threat/cve-2026-75962-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-4d025f1757070abe #OffSeq #WordPress #XSS #Infosec
##updated 2026-10-06T03:31:28
1 posts
TOTOLINK X6000R (9.4.0cu.652_B20230116) hit by CRITICAL OS command injection (CVE-2026-105484). Remote, unauthenticated attackers can gain full control. Restrict interface access & monitor /cgi-bin/cstecgi.cgi. Details: https://radar.offseq.com/threat/cve-2026-105484-os-command-injection-in-totolink-x6000r-ffaed0dcf0c90a02 #OffSeq #CVE #IoTSecurity
##updated 2026-10-05T21:31:46
1 posts
🟠 CVE-2026-103066 - High (8.5)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-103066/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:46
1 posts
🟠 CVE-2026-97257 - High (8.8)
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-97257/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:40
1 posts
🟠 CVE-2026-58841 - High (7.8)
In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58841/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:40
1 posts
🟠 CVE-2026-58815 - High (7.8)
In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58815/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:39
1 posts
🟠 CVE-2026-49933 - High (7.8)
In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalation of privilege with no additional execution pr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49933/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:39
1 posts
🟠 CVE-2026-45524 - High (8.8)
In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45524/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:39
1 posts
🟠 CVE-2026-49937 - High (7.8)
In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49937/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:39
1 posts
🟠 CVE-2026-55266 - High (7.8)
In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55266/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:39
1 posts
🟠 CVE-2026-58854 - High (7.8)
In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58854/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:39
1 posts
🟠 CVE-2026-55286 - High (7.8)
In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:39
1 posts
🟠 CVE-2026-55280 - High (8.8)
In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55280/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:39
1 posts
🟠 CVE-2026-55270 - High (7.8)
In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:38
1 posts
🟠 CVE-2026-103334 - High (7.5)
Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservation...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-103334/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T21:31:36
1 posts
🟠 CVE-2026-58859 - High (7.8)
In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58859/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T19:17:17.827000
1 posts
🔴 CVE-2026-105636 - Critical (9.9)
Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105636/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-05T15:33:23
4 posts
2 repos
https://github.com/orjanj/netscaler_threat_hunt_helper
https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
Citrix reveals CVE-2026-88779, a critical memory overflow flaw in NetScaler SAML configurations leading to DoS, following recent RCE zero-day attacks.
#CitrixNetScaler #Cybersecurity #CVE202688779 #SAML #ZeroDay
##Vorfall-Lagebild: Citrix NetScaler: Zero-Day CVE-2026-88779 wird aktiv
Nach 24 Stunden: was bekannt ist, was offen ist und was wahrscheinlich passiert ist – Citrix NetScaler: Zero-Day CVE-2026-88779 wird aktiv ausgenutzt – SAML-G
#OTSecurity #ICS #KRITIS #NIS2 #Cybersicherheit
https://ot-cyber.de/blog/vorfall-lagebild-citrix-netscaler-zero-day-cve-2026-88779-wird-aktiv.html
The new vuln, CVE-2026-88779, is a memory overflow bug that leads to denial of service. https://www.theregister.com/security/2026/10/05/citrix-netscaler-security-snafus-get-even-worse-amid-more-0-day-reports/5301232
##Citrix Patches NetScaler Zero-Day Exploited in Attacks Against Specific Organizations
Citrix released emergency patches for CVE-2026-88779, a high-severity zero-day vulnerability in NetScaler ADC and Gateway that allows attackers to cause denial of service and potentially run arbitrary code. The flaw is under active exploitation and affects appliances configured with SAML authentication.
**If you run your own Citrix NetScaler ADC or Gateway with SAML login turned on, upgrade right away to version 14.1-73.41 or 13.1-64.28 (or later). Do this even if you already patched in September. Attackers are actively exploiting this flaw. If you can't upgrade today, turn on Citrix's virtual-patch signatures and block the attacker address 213.209.159.55 as a stopgap. Then check your login logs for usernames that contain commands, since those mean someone has already tried to break in.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/citrix-patches-netscaler-zero-day-exploited-in-attacks-against-specific-organizations-n-l-k-9-i/gD2P6Ple2L
updated 2026-10-05T12:31:34
3 posts
1 repos
LibreOffice and OpenOffice Patch Critical Remote Code Execution Vulnerabilities
LibreOffice and Apache OpenOffice patched several critical vulnerabilities, including a remote code execution flaw (CVE-2026-63277) that allows attackers to run malicious Java code via manipulated spreadsheet documents.
**If you use LibreOffice, update it to version 26.2.5 or 26.8.0 ASAP, and until you do, don't open documents from unknown senders or unexpected sources. If you use Apache OpenOffice, there's no fix yet, so turn off Java in the program's options now and install version 4.1.17 as soon as it's released. Or better yet, switch to the patched LibreOffice.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/libreoffice-and-openoffice-patch-critical-remote-code-execution-vulnerabilities-1-z-e-q-7/gD2P6Ple2L
⚠️ Obrir un full de càlcul i que s'executi codi sense cap avís de macro. Això és.
Afecta LibreOffice (CVE-2026-63277, arreglat a les 26.2.5/26.8.0) i Apache OpenOffice (CVE-2026-59265, encara sense pegat: desactiva Java). L'atac aprofita rangs de base de dades + JDBC per baixar un JAR maliciós. De moment només PoC, però funciona a Windows i Linux.
#ciberseguretat #LibreOffice #OpenOffice
https://blog.elhacker.net/2026/10/vulnerabilidades-en-libreoffice-y.html
PoC released for LibreOffice Calc vulnerability CVE-2026-63277, which runs code when a file opens. Five more flaws fixed. Upgrade to 26.2.5.
#LibreOffice #LibreOfficeCalc #CVE202663277 #CVE202663266 #PoC #RCE #OpenSource #Vulnerability
##updated 2026-10-02T20:17:02.060000
2 posts
Reward: You've received a Commemorative Tin of "Should Have Patched in August" Hard Candies!
#CyberSecurity #CVE202618397 #RemoteCodeExecution #ThaleSConnect #SWIFT #CriticalHit (3/3)
##🏆 New Achievement! Step Right Up and Get Your Bank Pwned!
LADIES AND GENTLEMEN, feast your eyes on the most astonishing spectacle in modern authentication horror! CVE-2026-18397, a CVSS 9.4 remote code execution flaw in the Thales SConnect browser extension, has been actively hurled at SWIFT banking networks and government identity portals via drive-by attacks — no ticket required, no click needed, just exist near a browser! (1/3)
##updated 2026-10-02T18:17:06.963000
1 posts
Apache Thrift 0.25.0 fixes 61 Apache Thrift vulnerabilities, including critical heap overflow CVE-2026-91135. Upgrade every binding now.
#ApacheThrift #Apache #CVE202683632 #CVE202691135 #RPC #DoS #OpenSource #Vulnerability
##updated 2026-10-02T15:31:37
1 posts
1 repos
https://github.com/techupdate24/gitlab-ai-gateway-cve-2026-90970
⚪️ Critical 9.9-Point Vulnerability Fixed in GitLab AI Gateway
🗨️ GitLab developers have released patches for a critical vulnerability, CVE-2026-90970, affecting AI Gateway. The flaw received a CVSS score of 9.9 and, under certain conditions, allows an authenticated attacker to execute arbitrary commands on the server. The issue affects only…
##updated 2026-09-29T04:18:01.603000
3 posts
13 repos
https://github.com/EXEcution-py/CVE-2026-88771-POC
https://github.com/emilstahl/pitscaler
https://github.com/securekomodo/citrixInspector
https://github.com/SwiftSecur/CVE-2026-88771-HuntScript
https://github.com/orjanj/netscaler_threat_hunt_helper
https://github.com/LETHAL-FORENSICS/Get-NetScalerTimeline
https://github.com/watchtowrlabs/citrix-netscaler-cve-2026-88771-iocs
https://github.com/bkchaudhari/NetScaler-CTX697096-Assessment-Script
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771
https://github.com/craigsblackie/cve-2026-88771-netscaler
https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
https://github.com/techupdate24/citrix-netscaler-cve-2026-88771-rce
eSentire tracks four clusters behind CVE-2026-88771 exploitation, planting NetScaler web shells and backdoor accounts. Learn how to detect them.
#CVE202688771 #CitrixNetScaler #WebShell #ZeroDay #Platypus #eSentire #EdgeSecurity #CyberSecurity
https://securityonline.info/cve-2026-88771-netscaler/?utm_source=mastodon&utm_medium=jetpack_social
##New.
eSentire: More Shells Than a Seafood Buffet: Tracking Citrix NetScaler Exploitation Activities (CVE-2026-88771) https://www.esentire.com/blog/more-shells-than-a-seafood-buffet-tracking-citrix-netscaler-exploitation-activities-cve-2026-88771 #infosec #ClickFix #NetScaler #threatresearch #Citrix
##updated 2026-09-28T12:32:09
1 posts
8 repos
https://github.com/emilstahl/pitscaler
https://github.com/securekomodo/citrixInspector
https://github.com/orjanj/netscaler_threat_hunt_helper
https://github.com/murrez/CVE-2026-88772
https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772
Recent news highlights critical cybersecurity threats as Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-104286) zero-days are under active exploitation, targeting critical infrastructure and government entities. Apple also patched an exploited CoreGraphics flaw. In geopolitical developments, the Mecca Defense Alliance agreed to immediately implement collective defense commitments. On the technology front, MediaTek showcased advancements in Wi-Fi 8 with its Filogic 8800.
##updated 2026-09-18T06:32:17
1 posts
4 repos
https://github.com/HORKimhab/CVE-2026-93485
https://github.com/DeathShotXD/Comment2Shell
Podatność XSS w komentarzach WordPress mogła prowadzić do RCE
Badacz bezpieczeństwa Rafie Muhammad odkrył podatność XSS mogącą eskalować do RCE w systemie komentarzy WordPress. Dowolny nieuwierzytelniony użytkownik mógł dodać komentarz, który umieszczał na stronie ukryty skrypt. Jeśli stronę tę otworzył administrator zalogowany na swoim koncie, skrypt mógł wgrać złośliwą wtyczkę na serwer witryny. Podatność otrzymała numer CVE-2026-93485 i została...
#Aktualności #Podatność #Rce #Wordpress #XSS
https://sekurak.pl/podatnosc-xss-w-komentarzach-wordpress-mogla-prowadzic-do-rce/
##updated 2026-08-21T20:57:32
1 posts
🟠 CVE-2026-106442 - High (7.8)
Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. E...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106442/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-13T18:31:00
4 posts
1 repos
Vulnerability in Rejetto HFS Leads to Remote Code Execution, Actively Exploited
A critical authentication bypass is reported in Rejetto HFS (CVE-2026-61500) that allows remote code execution. Attackers are actively exploiting the flaw to forge administrator sessions and take control of servers.
**If you run Rejetto HTTP File Server (versions 3.0.0 to 3.2.0), update to version 3.2.1 or later right away. Attackers are already using this flaw to take full control of servers. Make sure to isolate the admin panel from internet access (use a VPN or firewall), and check your logs for unexpected admin logins or changes to the `server_code` setting, which would mean you may already be compromised.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/vulnerability-in-rejetto-hfs-leads-to-remote-code-execution-actively-exploited-h-m-g-z-y/gD2P6Ple2L
Discover how Anthropic's Mythos AI synthesized a remote code execution exploit for Rejetto HFS, exposing CVE-2026-61500 through mathematical state recovery.
#Anthropic #MythosAI #CVE202661500 #Cybersecurity #RejettoHFS
##⚠️ CRITICAL: Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Rejetto HFS vulnerability CVE-2026-61500 allows attackers to forge admin sessions and execute code via weak session cookie signing. Active exploitation detected in October 2026 targeting US organizations, despite a patch released in July 2026. Any unpatched HFS instance is immediately compromised.
🤖 AI generated summary
##Rejetto HFS servers now actively scanned for critical RCE flaw
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account...
🔗️ [Bleepingcomputer] https://link.is.it/CsBrJG
##updated 2026-06-17T09:40:40.793000
1 posts
2 repos
🚨 PoC released for an authenticated LPAR2RRD remote code execution vulnerability; CVE-2025-54769
PoC: https://github.com/tunahantekeoglu/CVE-2025-54769
The flaw allows an authenticated read-only user to abuse the LPAR2RRD upgrade functionality to upload a crafted file and achieve remote code execution through directory traversal.
CVSS: 8.8
Affected: LPAR2RRD ≤ 8.04
Fixed: LPAR2RRD ≥ 8.05
The PoC builds and uploads a minimal upgrade archive, then verifies successful code execution by retrieving the output of whoami.
##updated 2026-06-12T18:31:50
4 posts
4 repos
https://github.com/0xBlackash/CVE-2026-35273
https://github.com/HORKimhab/CVE-2026-35273
ShinyHunters Extorted Boeing Spin-Off Prior to Arrests
ShinyHunters 구성원으로 추정되는 인물이 요르단에서 구금되어 FBI 수사에 협조 중이며, 체포 직전 Boeing에서 분리된 Jeppesen ForeFlight에 대한 데이터 탈취·갈취를 진행했던 것으로 보도됐다. 이 그룹은 Oracle PeopleSoft의 CVE-2026-35273을 제로데이로 악용해 다수 조직에서 데이터를 탈취했으며, 패치가 어려운 환경을 위해 제시된 Mandiant WAF 규칙도 URL 인코딩 우회 기법으로 회피한 것으로 알려졌다. AI 서비스 개발 조직을 포함해 PeopleSoft를 운영...
https://krebsonsecurity.com/2026/10/shinyhunters-extorted-boeing-spin-off-prior-to-arrests/
##Accenture, acting as a contractor for the FBI, allegedly failed to install updates for Oracle Peoplesoft after CVE-2026-35273 was published.
This was a "Missing Authentication for Critical Function" vulnerability and scored 9.8. If this didn't raise any flags, the CISA KEV listing should have. It was an n-day at release.
But no, interestingly enough the FBI is exempt from BOD 26-04 and wasn't even obliged to update?!
Man, if not even federal agencies fix their vulns, this is all pointless.
##Recent cybersecurity threats include Atlassian patching critical vulnerabilities (CVE-2026-21589) in Jira, Confluence, and Bitbucket enabling file access. The FBI removed an Accenture contractor after a ShinyHunters breach of employee data via an unpatched Oracle PeopleSoft flaw (CVE-2026-35273). In technology, OpenAI's GPT-6 Astra model demonstrated supply-chain attack behavior in simulations. Geopolitically, the Mecca Defense Alliance committed to collective defense measures on October 5, 2026.
##https://thecybersecguru.com/news/fbi-shinyhunters-breach-peoplesoft-waf-bypass/
##updated 2025-10-22T03:31:39
1 posts
15 repos
https://github.com/malaya-m/cve-2013-3900-remediation-report
https://github.com/kingsrule50/nessus-vulnerability-scanning-lab
https://github.com/pkblanks/Remediating-CVE-2013-3900-EnableCertPaddingCheck-
https://github.com/AdenilsonSantos/WinVerifyTrust
https://github.com/snoopopsec/vulnerability-CVE-2013-3900
https://github.com/Securenetology/CVE-2013-3900
https://github.com/oukridrig772/-WinVerifyTrust-Signature-Validation-CVE-2013-3900-Mitigation
https://github.com/Sabecomoeh/CVE-2013-3900
https://github.com/OtisSymbos/CVE-2013-3900-WinTrustVerify
https://github.com/CyberCondor/Fix-WinVerifyTrustSignatureValidationVuln
https://github.com/norvethil/CVE-2013-3900-PowerShell-PoC
https://github.com/ksgassama-lab/vulnerability-remediation-cve-2013-3900
https://github.com/piranhap/CVE-2013-3900_Remediation_PowerShell
https://github.com/SDimitri05/cve-2013-3900-winverifytrust-mitigation
https://github.com/DavidBr27/CVE-2013-3900-Remediation-Script
🚨 EUVD-2013-3832
📊 Score: 5.5/10 (CVSS v3.1)
📦 Product: Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2016 (Server Core installation) (+24 more)
🏢 Vendor: Microsoft
📅 Published: 2013-12-11 | Updated: 2026-10-07
📝 Why is Microsoft republishing a CVE from 2013?
We are republishing CVE-2013-3900 in the Security Update Guide to...
updated 2025-10-22T00:34:11
1 posts
2 repos
Un simple message Twitch a suffi à exécuter du code sur la machine d'un streamer : overlay affichant le chat en HTML brut, Chromium embarqué dans OBS sans sandbox, faille V8 déjà exploitée (CVE-2024-7971). ⬇️
https://news.humancoders.com/t/securite/items/67445-comment-un-message-twitch-a-permis-l-execution-de
updated 2025-10-22T00:33:23
1 posts
2 repos
@watchTowr is a machine that turns funny blog posts about Secure By Design products into future CISA KEV Catalog additions. This time it's Atlassian pre-auth arbitrary file read CVE-2026-21589 (9.3 critical). Given that there's a similar "Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability" (CVE-2021-26085) in CISA's KEV, I'd take patching this seriously before the threat actors find out.
updated 2025-10-22T00:33:23
1 posts
⚠️ CRITICAL: Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Threat actors are actively exploiting CVE-2021-35394 in Realtek Jungle SDK to deploy the Cling botnet, which uses STUN protocol traffic to hide C2 communications as legitimate NAT traversal. Affected devices include routers and DVRs running vulnerable Realtek firmware. The malware achieves persiste…
🤖 AI generated summary
##🟠 CVE-2026-107212 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Row...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107212/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107212 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Row...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107212/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107216 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassing in-fl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107216/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107216 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassing in-fl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107216/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-59816 Joplin Server path traversal (CVSS 4.3) lets authenticated users escape the transcription path via crafted job IDs when TRANSCRIBE_ENABLED=true. Fix in 3.7.7 pending review. Track it at https://www.valtersit.com/cve/CVE-2026-59816/ #CVE #infosec #Joplin
##🟠 CVE-2026-107215 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or si...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107215 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or si...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107214 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107214/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107214 - High (7.5)
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107214/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-61748 InvenTree: missing permission checks in report/label print endpoints leak business data to any authenticated user. CVSS 4.3. Patch under review, restrict access now. https://www.valtersit.com/cve/CVE-2026-61748/ #CVE #infosec #cybersecurity
##Four critical Argo CD vulnerabilities, including AppProject bypass CVE-2026-77459, threaten the repo-server and clusters. Upgrade to v3.5.4 now.
#ArgoCD #Kubernetes #GitOps #CVE202677459 #Kustomize #Jsonnet #DevSecOps #Vulnerability
##Four critical Argo CD vulnerabilities, including AppProject bypass CVE-2026-77459, threaten the repo-server and clusters. Upgrade to v3.5.4 now.
#ArgoCD #Kubernetes #GitOps #CVE202677459 #Kustomize #Jsonnet #DevSecOps #Vulnerability
##A Gitea security update fixes 27 flaws, including SSRF bug CVE-2026-101027 and SSH key flaw CVE-2026-103059. Upgrade to Gitea 28.1.0 now.
#Gitea #Git #DevSecOps #SSRF #CVE2026101027 #CVE2026103059 #SupplyChainSecurity #Vulnerability
https://securityonline.info/gitea-security-update-28/?utm_source=mastodon&utm_medium=jetpack_social
##CVE-2026-103416: CRITICAL out-of-bounds write in Eclipse ThreadX NetX Duo (≤6.5.1.202602). Exploitable pre-cert auth; risk of code execution or DoS. Patch not released — check vendor updates. https://radar.offseq.com/threat/cve-2026-103416-cwe-787-out-of-bounds-write-in-eclipse-foundation-eclipse-threadx-netx-duo-509a4f871398c232 #OffSeq #CVE2026103416 #infosec #vuln
##Two Handlebars.js vulnerability disclosures (CVE-2026-106445, CVE-2026-106446) enable RCE. Details and PoC are public. Update to 4.7.10 now.
#Handlebars #HandlebarsJS #NodeJS #CVE2026106445 #CVE2026106446 #RCE #JavaScript #Vulnerability
##Two Handlebars.js vulnerability disclosures (CVE-2026-106445, CVE-2026-106446) enable RCE. Details and PoC are public. Update to 4.7.10 now.
#Handlebars #HandlebarsJS #NodeJS #CVE2026106445 #CVE2026106446 #RCE #JavaScript #Vulnerability
##🟠 CVE-2026-105797 - High (8.8)
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-pri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105797/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-61744 InvenTree: authenticated barcode API lets attackers read arbitrary model records via crafted JSON, exposing full serializer output. CVSS 6.5. Patch still under review, so restrict API access now. https://www.valtersit.com/cve/CVE-2026-61744/ #CVE #infosec #InvenTree
##🟠 CVE-2026-106113 - High (7.5)
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106113/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-106112 - High (7.5)
ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vector4. When...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106112/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-106115 - High (7.5)
ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes be...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106115/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-105859 - Critical (9.8)
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105859/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-105858 - High (8.1)
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authenticatio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105858/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-105857 - Critical (10)
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105857/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-105865 - High (8.1)
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove unin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105865/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##A ChatGPT macOS vulnerability, CVE-2026-100754, let local code run commands through a trusted OpenAI process. OpenAI fixed it on Sept 25.
#ChatGPT #macOS #OpenAI #CVE2026100754 #PatrickWardle #AppSecurity #Vulnerability #MacSecurity
https://meterpreter.org/chatgpt-macos-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
##Twenty CRM vulnerability CVE-2026-105763 (CVSS 9.6) enables plaintext password disclosure of IMAP and SMTP accounts. Upgrade to 2.7.0.
#TwentyCRM #CRM #CVE2026105763 #GraphQL #CredentialLeak #OpenSource #EmailSecurity #Vulnerability
##CVE-2026-105763 (CRITICAL): twentyhq twenty CRM v1.20.10 – 2.7.0 exposes plaintext IMAP/SMTP/CalDAV creds to any workspace user via GraphQL. Upgrade to 2.7.0 to prevent mail/calendar compromise. https://radar.offseq.com/threat/cve-2026-105763-cwe-522-insufficiently-protected-credentials-in-twentyhq-twenty-8c5491429285ac63 #OffSeq #Vuln #CRM #twentyhq
##🔴 CVE-2026-105637 - Critical (9.6)
Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105637/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-105744 - High (7.5)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.94.0 until 2.132.0, callers that opt into LatexBackendOptions(tikz_engine="tectonic") invoke docling/backend/late...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105744/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-105740 - Critical (9.9)
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-suppl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105740/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-105697 - Critical (9.9)
Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrappe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105697/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-105650 - High (8.1)
Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the publishe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105650/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-105675 - High (7.5)
Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites for roles with higher privileges than their own....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105675/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-105634 - High (8.1)
Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization chec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105634/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##