## Updated at UTC 2026-08-16T18:49:29.052633

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-74795 7.5 0.00% 2 0 2026-08-16T15:30:38 Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its rec
CVE-2026-74792 7.5 0.00% 2 0 2026-08-16T15:30:38 Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vuln
CVE-2026-74794 7.5 0.00% 3 0 2026-08-16T14:16:57.450000 Scriban before 6.6.0 contains an infinite recursion vulnerability in object rend
CVE-2026-74791 8.6 0.00% 2 0 2026-08-16T14:16:57.183000 Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when Template
CVE-2026-74790 9.1 0.00% 2 0 2026-08-16T14:16:57.050000 Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering
CVE-2026-74789 7.5 0.00% 2 0 2026-08-16T14:16:56.917000 Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only t
CVE-2026-74788 7.5 0.00% 3 0 2026-08-16T14:16:56.787000 Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memor
CVE-2026-74787 7.5 0.00% 3 0 2026-08-16T14:16:56.653000 Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the obj
CVE-2026-74783 7.5 0.00% 2 0 2026-08-16T14:16:56.133000 Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimi
CVE-2026-73062 7.5 0.00% 2 0 2026-08-16T14:16:55.903000 Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability i
CVE-2026-73061 9.8 0.00% 2 0 2026-08-16T14:16:55.770000 Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedOb
CVE-2026-73060 7.5 0.00% 2 0 2026-08-16T14:16:55.640000 Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerabil
CVE-2026-73057 7.5 0.00% 2 0 2026-08-16T14:16:55.230000 stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy en
CVE-2026-73056 9.8 0.00% 4 0 2026-08-16T14:16:55.083000 SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive
CVE-2026-17087 7.5 0.41% 1 0 2026-08-16T07:16:30.423000 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for W
CVE-2026-18316 9.1 0.32% 2 0 2026-08-16T06:30:37 The Solace Extra plugin for WordPress is vulnerable to unauthorized modification
CVE-2026-18432 9.8 0.45% 3 0 2026-08-16T06:30:32 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege
CVE-2026-16098 9.8 0.64% 3 0 2026-08-16T06:30:32 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U
CVE-2026-16099 8.8 0.59% 1 0 2026-08-16T06:30:32 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi
CVE-2026-19714 0 0.16% 1 0 2026-08-16T06:16:52.300000 The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audien
CVE-2026-17123 8.8 0.36% 1 0 2026-08-16T05:16:48.033000 The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Req
CVE-2026-14524 9.1 0.70% 2 0 2026-08-16T05:16:46.493000 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file d
CVE-2026-14498 8.8 0.55% 1 0 2026-08-16T05:16:46.360000 The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution i
CVE-2026-72362 None 0.20% 1 0 2026-08-15T06:32:29 In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt:
CVE-2026-72439 None 0.16% 1 0 2026-08-15T06:32:26 In the Linux kernel, the following vulnerability has been resolved: md/raid10:
CVE-2026-13196 0 0.10% 1 0 2026-08-14T20:16:49.133000 Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in
CVE-2026-59310 9.8 1.14% 3 0 2026-08-14T05:16:59.407000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-65400 7.1 0.50% 6 0 2026-08-14T03:31:24 An authentication issue was addressed with improved state management. This issue
CVE-2026-58231 10.0 0.73% 1 1 2026-08-12T05:17:56.963000 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent
CVE-2026-12569 9.8 30.20% 1 1 2026-08-01T05:16:55.023000 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-42228 6.5 0.38% 1 1 2026-06-17T10:47:32.723000 n8n is an open source workflow automation platform. Prior to versions 1.123.32,
CVE-2026-33696 9.9 0.77% 2 0 2026-03-26T16:41:02 ## Impact An authenticated user with permission to create or modify workflows co
CVE-2026-65640 0 0.00% 1 1 N/A
CVE-2026-64638 0 0.89% 1 23 N/A

CVE-2026-74795
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T15:30:38

2 posts

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so an attacker who controls template input can supply a deeply nested template (e.g., thousands of nested parentheses or blocks) that exhausts thread stack

thehackerwire@mastodon.social at 2026-08-16T15:01:18.000Z ##

🟠 CVE-2026-74795 - High (7.5)

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T15:01:18.000Z ##

🟠 CVE-2026-74795 - High (7.5)

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74792
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T15:30:38

2 posts

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInitializer) that is not covered by the ExpressionDepthLimit counter added in the fix for GHSA-wgh7-7m3c-fx25. An attacker who can supply untrusted input to Templat

thehackerwire@mastodon.social at 2026-08-16T15:00:30.000Z ##

🟠 CVE-2026-74792 - High (7.5)

Scriban before 7.0.0 (affected versions &lt;= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T15:00:30.000Z ##

🟠 CVE-2026-74792 - High (7.5)

Scriban before 7.0.0 (affected versions &lt;= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74794
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:57.450000

3 posts

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and triggering an uncatchable StackOverflowException that terminates the hosting process.

hugovalters@mastodon.social at 2026-08-16T15:12:50.000Z ##

CVE-2026-74794 – Unpatched DoS in Scriban template engine. Infinite recursion via circular refs crashes host process. CVSS 7.5. Update to 6.6.0 or limit recursion. #CVE #infosec #Scriban

valtersit.com/cve/CVE-2026-747

##

thehackerwire@mastodon.social at 2026-08-16T15:01:06.000Z ##

🟠 CVE-2026-74794 - High (7.5)

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T15:01:06.000Z ##

🟠 CVE-2026-74794 - High (7.5)

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74791
(8.6 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:57.183000

2 posts

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.

thehackerwire@mastodon.social at 2026-08-16T15:00:20.000Z ##

🟠 CVE-2026-74791 - High (8.6)

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T15:00:20.000Z ##

🟠 CVE-2026-74791 - High (8.6)

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74790
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-16T14:16:57.050000

2 posts

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.

thehackerwire@mastodon.social at 2026-08-16T15:00:08.000Z ##

🔴 CVE-2026-74790 - Critical (9.1)

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T15:00:08.000Z ##

🔴 CVE-2026-74790 - Critical (9.1)

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74789
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:56.917000

2 posts

Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | array.size }} — or a memory-amplification expression such as {{ 'A' * 200000000 }} — can force large CPU or memory consumption even when LoopLimit is config

thehackerwire@mastodon.social at 2026-08-16T16:01:00.000Z ##

🟠 CVE-2026-74789 - High (7.5)

Scriban before 7.0.0 (affected &lt;= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T16:01:00.000Z ##

🟠 CVE-2026-74789 - High (7.5)

Scriban before 7.0.0 (affected &lt;= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74788
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:56.787000

3 posts

Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to .NET's String.PadLeft/PadRight. When an application exposes Scriban to untrusted template input, an attacker can supply an arbitrarily large width value (e.g

hugovalters@mastodon.social at 2026-08-16T18:11:43.000Z ##

CVE-2026-74788 - DoS in Scriban templates via string.pad_left/right. Unvalidated width triggers ~1GB allocations, OOM. CVSS 7.5. Unpatched. Update to 7.0.0 or restrict template access. #CVE #infosec #Scriban

valtersit.com/cve/CVE-2026-747

##

thehackerwire@mastodon.social at 2026-08-16T16:00:50.000Z ##

🟠 CVE-2026-74788 - High (7.5)

Scriban before 7.0.0 (affected versions &lt;= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T16:00:50.000Z ##

🟠 CVE-2026-74788 - High (7.5)

Scriban before 7.0.0 (affected versions &lt;= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74787
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:56.653000

3 posts

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process.

hugovalters@mastodon.social at 2026-08-16T17:07:38.000Z ##

CVE-2026-74787 - Uncontrolled recursion in Scriban's object.to_json. Crafted templates cause stack overflow, crashing .NET apps. CVSS 7.5. No patch yet - mitigate by limiting template input. #CVE #Scriban #infosec

valtersit.com/cve/CVE-2026-747

##

thehackerwire@mastodon.social at 2026-08-16T16:00:37.000Z ##

🟠 CVE-2026-74787 - High (7.5)

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T16:00:37.000Z ##

🟠 CVE-2026-74787 - High (7.5)

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74783
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:56.133000

2 posts

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an uncatchable StackOverflowException that immediately terminates the host process.

thehackerwire@mastodon.social at 2026-08-16T15:01:29.000Z ##

🟠 CVE-2026-74783 - High (7.5)

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T15:01:29.000Z ##

🟠 CVE-2026-74783 - High (7.5)

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73062
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:55.903000

2 posts

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multiplier in a template to force multi-gigabyte memory allocations, causing resource exhaustion and availability degradation.

thehackerwire@mastodon.social at 2026-08-16T17:00:36.000Z ##

🟠 CVE-2026-73062 - High (7.5)

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T17:00:36.000Z ##

🟠 CVE-2026-73062 - High (7.5)

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73061
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-16T14:16:55.770000

2 posts

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.

thehackerwire@mastodon.social at 2026-08-16T17:00:25.000Z ##

🔴 CVE-2026-73061 - Critical (9.8)

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T17:00:25.000Z ##

🔴 CVE-2026-73061 - Critical (9.8)

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73060
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:55.640000

2 posts

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on lazy sequences to execute billions of uncharged iterations, pinning CPU cores and exhausting garbage collection resources even when LoopLimit is set to 1

thehackerwire@mastodon.social at 2026-08-16T16:02:01.000Z ##

🟠 CVE-2026-73060 - High (7.5)

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T16:02:01.000Z ##

🟠 CVE-2026-73060 - High (7.5)

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73057
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-16T14:16:55.230000

2 posts

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas.

thehackerwire@mastodon.social at 2026-08-16T16:01:49.000Z ##

🟠 CVE-2026-73057 - High (7.5)

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-16T16:01:49.000Z ##

🟠 CVE-2026-73057 - High (7.5)

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73056
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-16T14:16:55.083000

4 posts

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mechanism (NeedCaptcha/WrongAuthCount). As a result, an

thehackerwire@mastodon.social at 2026-08-16T16:01:38.000Z ##

🔴 CVE-2026-73056 - Critical (9.8)

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-16T13:30:26.038Z ##

siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-16T16:01:38.000Z ##

🔴 CVE-2026-73056 - Critical (9.8)

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-16T13:30:26.000Z ##

siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 radar.offseq.com/threat/cve-20 #OffSeq #CVE202673056 #infosec

##

CVE-2026-17087
(7.5 HIGH)

EPSS: 0.41%

updated 2026-08-16T07:16:30.423000

1 posts

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view private booking billing details — including the victim customer's firs

thehackerwire@mastodon.social at 2026-08-16T07:59:50.000Z ##

🟠 CVE-2026-17087 - High (7.5)

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authori...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18316
(9.1 CRITICAL)

EPSS: 0.32%

updated 2026-08-16T06:30:37

2 posts

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wp_localize_script

thehackerwire@mastodon.social at 2026-08-16T06:59:50.000Z ##

🔴 CVE-2026-18316 - Critical (9.1)

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_act...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-16T06:00:23.000Z ##

CVE-2026-18316: CRITICAL auth bypass in Solace Extra WordPress plugin (≤1.6.0). Subscriber-level users can perform destructive actions — no patch yet. Restrict user roles & monitor import_zip() activity. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE202618316

##

CVE-2026-18432
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-08-16T06:30:32

3 posts

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a conditio

offseq at 2026-08-16T12:00:24.622Z ##

CVE-2026-18432 (CVSS 9.8): CRITICAL privilege escalation in DynamiApps Frontend Admin <=3.29.9. Unauthenticated attackers can become admins via flawed user ID checks. Restrict access to vulnerable forms & endpoints. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-16T12:00:24.000Z ##

CVE-2026-18432 (CVSS 9.8): CRITICAL privilege escalation in DynamiApps Frontend Admin <=3.29.9. Unauthenticated attackers can become admins via flawed user ID checks. Restrict access to vulnerable forms & endpoints. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #PrivilegeEscalation #CVE

##

thehackerwire@mastodon.social at 2026-08-16T05:59:59.000Z ##

🔴 CVE-2026-18432 - Critical (9.8)

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16098
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-08-16T06:30:32

3 posts

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delet

offseq at 2026-08-16T10:30:22.685Z ##

CVE-2026-16098 (CRITICAL): ProSolution WP Client <=2.0.10 lets unauthenticated attackers upload dangerous files via nonce leak, leading to remote code execution. Restrict plugin use & monitor for patches. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-16T10:30:22.000Z ##

CVE-2026-16098 (CRITICAL): ProSolution WP Client <=2.0.10 lets unauthenticated attackers upload dangerous files via nonce leak, leading to remote code execution. Restrict plugin use & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202616098 #Infosec

##

thehackerwire@mastodon.social at 2026-08-16T06:00:11.000Z ##

🔴 CVE-2026-16098 - Critical (9.8)

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Dispo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16099
(8.8 HIGH)

EPSS: 0.59%

updated 2026-08-16T06:30:32

1 posts

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the

thehackerwire@mastodon.social at 2026-08-16T06:00:47.000Z ##

🟠 CVE-2026-16099 - High (8.8)

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authentic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19714
(0 None)

EPSS: 0.16%

updated 2026-08-16T06:16:52.300000

1 posts

The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin before 3.6.8's Google sign-in enabled is affected.

offseq@infosec.exchange at 2026-08-16T07:30:24.000Z ##

CVE-2026-19714 (CRITICAL): Simple JWT Login <3.6.8 for WordPress fails to validate Google token audiences. Sites with Google sign-in enabled risk admin impersonation & takeover. Disable Google sign-in or update ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202619714

##

CVE-2026-17123
(8.8 HIGH)

EPSS: 0.36%

updated 2026-08-16T05:16:48.033000

1 posts

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render (including a Contributor previewing their own draft), and the wpr_form_builder_webhoo

thehackerwire@mastodon.social at 2026-08-16T05:59:49.000Z ##

🟠 CVE-2026-17123 - High (8.8)

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-control...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14524
(9.1 CRITICAL)

EPSS: 0.70%

updated 2026-08-16T05:16:46.493000

2 posts

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-c

offseq@infosec.exchange at 2026-08-16T09:00:23.000Z ##

CRITICAL: CVE-2026-14524 in ProSolution WP Client ≤2.0.8 enables unauthenticated file deletion via path traversal — risking RCE if key files are removed. No patch; restrict or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202614524 #Vuln

##

thehackerwire@mastodon.social at 2026-08-16T06:01:22.000Z ##

🔴 CVE-2026-14524 - Critical (9.1)

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unaut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14498
(8.8 HIGH)

EPSS: 0.55%

updated 2026-08-16T05:16:46.360000

1 posts

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options fully replacing saved query options and being passed directly to call_user_func_arr

thehackerwire@mastodon.social at 2026-08-16T06:00:59.000Z ##

🟠 CVE-2026-14498 - High (8.8)

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_for...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72362(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-08-15T06:32:29

1 posts

In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() The page-table walk framework may pass a NULL *child pointer for unpopulated entries. xe_pt_zap_ptes_entry() called container_of(*child) before checking for NULL, then dereferenced the result, causing a crash. Move the container_of() call after a NULL guard, so t

hugovalters@mastodon.social at 2026-08-16T12:04:04.000Z ##

CVE-2026-72362 - Linux kernel NULL pointer deref in drm/xe/pt. Unpatched, crash risk. No CVSS. Update when patch lands. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-723

##

CVE-2026-72439(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-08-15T06:32:26

1 posts

In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix writes_pending leak on write request failures raid10_make_request() acquires a writes_pending reference with md_write_start() before dispatching write requests. Several failure paths in raid10_write_request() complete the bio and return without reaching the normal write completion path, causing the corresponding m

hugovalters@mastodon.social at 2026-08-16T11:13:08.000Z ##

CVE-2026-72439 - Linux kernel md/raid10 write failure leak. Unpatched, can cause data integrity issues. CVSS N/A. Monitor for patches and update when available. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-724

##

CVE-2026-13196
(0 None)

EPSS: 0.10%

updated 2026-08-14T20:16:49.133000

1 posts

Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker with device configuration access to write attacker-controlled data outside the bounds of the process-image buffer and corrupt adjacent kernel memory, resulting in kernel memory corruption and denia

hugovalters@mastodon.social at 2026-08-16T14:10:55.000Z ##

CVE-2026-13196 - OOB write in KUNBUS piControl 2.6.2. Local auth attacker can corrupt kernel memory, cause DoS. No CVSS yet, unpatched. Update immediately. #CVE #KUNBUS #infosec

valtersit.com/cve/CVE-2026-131

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-08-14T05:16:59.407000

3 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

patrickcmiller at 2026-08-16T12:12:01.214Z ##

vCenter Flaw Exploited Just Five Days After Disclosure infosecurity-magazine.com/news

##

patrickcmiller@infosec.exchange at 2026-08-16T12:12:01.000Z ##

vCenter Flaw Exploited Just Five Days After Disclosure infosecurity-magazine.com/news

##

threatnoir@infosec.exchange at 2026-08-16T05:15:04.000Z ##

2026-W33 — Weekly Threat Roundup

🔥 VMware vCenter RCE (CVE-2026-59310) under active APT exploitation across 47 countries, patch and hunt for persistence now.
🤖 Near-autonomous AI cyberattack observed against Taiwan's government, adapting mid-operation without human direction.
💀 Lazarus Group's Operation Dream Job exploits Windo…

threatnoir.com/weekly/2026-w33

#infosec #cybersecurity #threatintel

🤖 AI generated summary

##

CVE-2026-65400
(7.1 HIGH)

EPSS: 0.50%

updated 2026-08-14T03:31:24

6 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

threatnoir at 2026-08-16T15:05:44.646Z ##

⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…

threatnoir.com/focus

🤖 AI generated summary

##

tomshardware@mastodon.online at 2026-08-16T13:04:06.000Z ##

Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks

The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
#hardware
tomshardware.com/tech-industry

##

beyondmachines1 at 2026-08-16T11:01:08.666Z ##

Apple Patches Actively Exploited macOS Screen Sharing Vulnerability Used in Crypto Mining Attacks

Apple patched a macOS Screen Sharing vulnerability (CVE-2026-65400) that allows remote attackers to bypass authentication and gain root access. Attackers are actively exploiting the flaw to install Monero crypto miners on systems with port 5900 exposed to the internet.

**If you use a Mac, update macOS now to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 to fix CVE-2026-65400, which attackers are already using to take full control of Macs without a password. Also turn off Screen Sharing when you don't need it and make sure port 5900 is not reachable from the internet.**

beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-08-16T15:05:44.000Z ##

⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

tomshardware@mastodon.online at 2026-08-16T13:04:06.000Z ##

Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks

The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
#hardware
tomshardware.com/tech-industry

##

beyondmachines1@infosec.exchange at 2026-08-16T11:01:08.000Z ##

Apple Patches Actively Exploited macOS Screen Sharing Vulnerability Used in Crypto Mining Attacks

Apple patched a macOS Screen Sharing vulnerability (CVE-2026-65400) that allows remote attackers to bypass authentication and gain root access. Attackers are actively exploiting the flaw to install Monero crypto miners on systems with port 5900 exposed to the internet.

**If you use a Mac, update macOS now to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 to fix CVE-2026-65400, which attackers are already using to take full control of Macs without a password. Also turn off Screen Sharing when you don't need it and make sure port 5900 is not reachable from the internet.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-58231
(10.0 CRITICAL)

EPSS: 0.73%

updated 2026-08-12T05:17:56.963000

1 posts

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

1 repos

https://github.com/HORKimhab/CVE-2026-58231

netsecio@mastodon.social at 2026-08-16T15:05:54.000Z ##

📰 Critical SAP Commerce Cloud Flaw (CVE-2026-58231) Under Active Attack

Max-severity SAP Commerce Cloud flaw (CVE-2026-58231, CVSS 10.0) is under active attack just days after patch release. The unauthenticated RCE affects major e-commerce platforms. #SAP #RCE #PatchNow

🔗 cyber.netsecops.io/articles/cr

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 30.20%

updated 2026-08-01T05:16:55.023000

1 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

netsecio@mastodon.social at 2026-08-16T15:05:32.000Z ##

📰 Clop Group Claims Massive Data Heist from Shell, Philips, GE via PTC Flaw

Clop ransomware group claims massive data theft from Shell, Philips, GE, and 40+ others by exploiting a critical PTC Windchill vulnerability (CVE-2026-12569). #Clop #Ransomware #SupplyChainAttack

🔗 cyber.netsecops.io/articles/cl

##

CVE-2026-42228
(6.5 MEDIUM)

EPSS: 0.38%

updated 2026-06-17T10:47:32.723000

1 posts

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized to interact with the target execution. An unauthenticated remote attacker who could identify a valid execution ID for a workflow in a waiting state could attach

1 repos

https://github.com/rudSarkar/CVE-2026-42228

sayzard@mastodon.sayzard.org at 2026-08-16T17:39:34.000Z ##

Breaking AI Orchestration: Hijacking N8n HITL Chat Sessions

n8n의 HITL Chat 노드에서 인증 없이 활성 WebSocket 채팅 세션을 탐색·도청·메시지 주입할 수 있는 취약점이 발견됐다. 순차적인 executionId와 공개된 `/form-waiting` 상태 오라클, 클라이언트가 임의 지정 가능한 sessionId가 결합돼 실행 중인 에이전트 대화를 탈취할 수 있으며, 에이전트가 반환하는 도구 결과·검색 컨텍스트 등의 노출 및 대화 조작으로 이어질 수 있다. 이 이슈는 CVE-2026-42228(CVSS 6.3, Moderate)로 수정됐으며, n...

zerolabs.rubrik.com/blog/break

##

CVE-2026-33696
(9.9 CRITICAL)

EPSS: 0.77%

updated 2026-03-26T16:41:02

2 posts

## Impact An authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the GSuiteAdmin node. By supplying a crafted parameter as part of node configuration, an attacker could write attacker-controlled values onto `Object.prototype`. An attacker could use this prototype pollution to achieve remote code execution on the n8n instance. ## Pa

CVE-2026-65640
(0 None)

EPSS: 0.00%

1 posts

N/A

1 repos

https://github.com/jobusa755-a11y/CVE-2026-65640-

cyberveille@mastobot.ping.moi at 2026-08-16T12:00:05.000Z ##

📢 Vulnérabilité critique d'exécution de code à distance dans WordPress (CVE-2026-65640)

Le CERT-FR a publié le 13 août 2026 l'avis CERTFR-2026-AVI-1018 signalant une vulnérabilité dans WordPress, basé sur le bulletin de sécurité officiel WordPress du 12 août 2026. CVE : CVE-2026-65640 Impact : Exécution de code arbitraire à distance (RCE) Produit affecté…

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : cert.ssi.gouv.fr/avis/CERTFR-2
🟡 vérification factuelle moyenne
#WordPress #CERTFR #Cyberveille

##

cyberveille@mastobot.ping.moi at 2026-08-16T12:00:05.000Z ##

📢 xss2shell (CVE-2026-64638) : XSS réfléchie non authentifiée menant à RCE sur WordPress < 7.0.3

📅 Source : flawfence.com, publié le 10 août 2026. Analyse technique détaillée de la vulnérabilité CVE-2026-64638, baptisée xss2shell, découverte par l'équipe de recherche pwn.ai et corrigée dans WordPress 7.0.3 le 6 août 2026.

📖 cyberveille : cyberveille.ch/posts/2026-08-1
🌐 source : flawfence.com/blog/xss2shell-f
🟡 vérification factuelle moyenne
#RCE #WordPress #Cyberveille

##

Visit counter For Websites