## Updated at UTC 2026-10-10T19:08:29.063031

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-106609 7.5 0.00% 2 0 2026-10-10T18:31:27 Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcas
CVE-2026-105889 9.3 0.00% 2 0 2026-10-10T18:31:27 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-103071 7.5 0.00% 2 0 2026-10-10T18:31:26 Improper Control of Generation of Code ('Code Injection') vulnerability in Villa
CVE-2026-104398 9.8 0.00% 2 0 2026-10-10T17:16:59.937000 Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate M
CVE-2026-108546 7.5 0.00% 2 0 2026-10-10T15:30:30 Spotweb through 1.5.8 contains an OS command injection vulnerability in the runc
CVE-2026-105885 8.8 0.00% 2 0 2026-10-10T15:30:29 Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-
CVE-2026-108549 8.1 0.00% 2 0 2026-10-10T15:30:29 cc-connect through 1.5.0 contains a missing authentication vulnerability in the
CVE-2026-108551 9.8 0.00% 2 0 2026-10-10T15:30:29 openapi-typescript-codegen through 0.31.0 contains a code injection vulnerabilit
CVE-2026-108550 8.8 0.00% 2 0 2026-10-10T15:30:24 SkillHub before 0.2.22 contains an incorrect authorization vulnerability in Acco
CVE-2026-108553 7.5 0.00% 2 0 2026-10-10T15:16:58.410000 OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in
CVE-2026-108161 7.5 0.00% 2 0 2026-10-10T14:16:37.223000 FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_r
CVE-2026-104803 9.8 0.45% 2 0 2026-10-10T09:30:37 The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in
CVE-2026-91136 7.5 0.56% 2 0 2026-10-10T09:16:39.360000 The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versi
CVE-2026-96662 7.5 0.39% 2 0 2026-10-10T08:17:08.033000 The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
CVE-2026-93950 7.5 0.20% 2 0 2026-10-10T08:17:07.307000 Missing Authorization vulnerability in StylemixThemes Motors motors allows Explo
CVE-2026-93945 9.8 0.33% 4 0 2026-10-10T08:17:07.057000 Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance a
CVE-2026-93944 9.8 0.31% 2 0 2026-10-10T08:17:06.930000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia cameli
CVE-2026-93941 9.8 0.33% 2 0 2026-10-10T08:17:06.557000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema al
CVE-2026-93940 9.8 0.33% 2 0 2026-10-10T08:17:06.433000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny
CVE-2026-93938 9.8 0.33% 2 0 2026-10-10T08:17:06.310000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwo
CVE-2026-93937 9.8 0.33% 2 0 2026-10-10T08:17:06.187000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia al
CVE-2026-93936 9.8 0.33% 2 0 2026-10-10T08:17:06.060000 Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm
CVE-2026-62046 9.8 0.32% 2 0 2026-10-10T08:17:04.777000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gute
CVE-2026-62045 9.8 0.32% 2 0 2026-10-10T08:17:04.647000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers boo
CVE-2026-97670 9.1 0.37% 1 0 2026-10-10T06:31:08 The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization b
CVE-2026-94589 9.8 0.66% 1 0 2026-10-10T06:31:06 The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirect
CVE-2026-96207 10.0 0.48% 2 0 2026-10-10T04:18:19.870000 Improper certificate validation in Microsoft Partner Center allows an unauthoriz
CVE-2026-94510 9.9 0.40% 2 0 2026-10-10T04:18:19.577000 Authorization bypass through user-controlled key in Microsoft Bookings allows an
CVE-2026-84249 9.8 0.41% 1 0 2026-10-10T04:18:18.437000 IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to e
CVE-2026-84058 8.1 0.36% 1 0 2026-10-10T04:18:17.540000 IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer over
CVE-2026-82344 8.1 0.40% 1 0 2026-10-10T04:18:16.730000 IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer ove
CVE-2026-78406 9.8 0.50% 1 0 2026-10-10T04:18:15.970000 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-18740 8.8 0.35% 1 0 2026-10-10T04:18:12.470000 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-16823 9.1 0.33% 1 0 2026-10-10T04:18:12.110000 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-108474 9.8 0.32% 1 0 2026-10-10T00:17:03.673000 In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped strin
CVE-2026-108268 0 0.13% 1 0 2026-10-09T22:16:59.643000 Enclave OS Virtual runs container workloads inside confidential virtual machines
CVE-2026-75351 7.5 0.40% 1 0 2026-10-09T21:31:18 OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side Et
CVE-2026-75346 7.5 0.54% 1 0 2026-10-09T21:31:17 An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and mast
CVE-2026-92705 7.8 0.13% 1 0 2026-10-09T21:17:06.360000 Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegis
CVE-2026-108264 9.1 0.38% 1 0 2026-10-09T21:17:04.703000 Wizarr is an advanced user invitation and management system for Jellyfin, Plex,
CVE-2026-108259 8.2 0.25% 1 0 2026-10-09T21:17:04.017000 Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads
CVE-2026-107805 7.5 0.44% 1 0 2026-10-09T20:57:10 ## Summary In Nginx UI versions 2.5.0 through 2.5.x, the node-signature authent
CVE-2026-108261 9.3 0.16% 1 0 2026-10-09T20:56:50 ### Summary The TinaCMS admin builds its preview `<iframe src>` from the `/~/*`
CVE-2026-108260 7.6 0.21% 1 0 2026-10-09T20:56:46 ### Summary `<tina-markdown>` renders a rich-text AST into the DOM and, for `a`
CVE-2026-107845 9.3 0.27% 1 0 2026-10-09T20:53:52 An unauthenticated front end visitor can post a comment containing a XSS injecti
CVE-2026-62376 8.1 0.21% 1 0 2026-10-09T20:49:15 ### Summary Vikunja stores password-reset, email-confirmation, and account-dele
CVE-2026-107806 None 0.33% 1 1 2026-10-09T20:45:03 ## Summary An authenticated nginx-ui user can call `POST /api/restore`, upload
CVE-2026-107839 7.5 0.34% 1 0 2026-10-09T20:44:55 ### Summary The AoE3 `POST /game/cloud/getFileURL` handler in `luskaner/ageLANSe
CVE-2026-57458 8.1 0.27% 1 0 2026-10-09T20:40:28 ## Summary A scoped API token can bypass its declared permissions by using the
CVE-2026-107840 7.5 0.44% 1 0 2026-10-09T20:17:09.900000 yopass is a service for securely sharing secrets, passwords, and files. Prior to
CVE-2026-103413 8.8 0.39% 1 0 2026-10-09T18:32:43 Improper input validation vulnerability in Apache Camel Karavan. When a deplo
CVE-2026-75347 7.5 0.42% 1 0 2026-10-09T18:31:53 EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired poi
CVE-2026-108113 8.8 0.64% 1 0 2026-10-09T18:31:48 ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerab
CVE-2026-75349 7.5 0.45% 1 0 2026-10-09T18:31:48 EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bound
CVE-2026-108160 7.5 0.15% 1 0 2026-10-09T18:31:48 AstronRPA through 1.1.6 contains a download of code without integrity check vuln
CVE-2026-104084 8.8 0.25% 1 0 2026-10-09T18:31:47 SmarterMail before build 9777 contains a privilege escalation vulnerability wher
CVE-2026-75345 7.5 0.45% 1 0 2026-10-09T18:31:47 OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected
CVE-2026-90983 8.2 0.26% 1 0 2026-10-09T18:31:47 Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc.
CVE-2026-108157 8.1 0.53% 1 0 2026-10-09T18:31:44 Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vu
CVE-2026-78795 7.5 0.45% 1 0 2026-10-09T18:17:14.903000 An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless route
CVE-2026-75350 7.5 0.48% 1 0 2026-10-09T18:17:14.037000 EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in
CVE-2026-75348 7.5 0.51% 1 0 2026-10-09T18:17:13.893000 An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and mast
CVE-2026-107818 8.4 0.34% 1 0 2026-10-09T18:17:03.373000 MariaDB server is a community developed fork of MySQL server. From 10.6.1 until
CVE-2026-108159 7.5 0.33% 1 0 2026-10-09T17:41:47.060000 AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the des
CVE-2026-107815 8.5 0.57% 1 0 2026-10-09T17:41:29.727000 MariaDB server is a community developed fork of MySQL server. From 10.6.1 until
CVE-2026-107826 7.5 0.46% 1 0 2026-10-09T17:33:55 ### Summary The JSON body processor (`internal/bodyprocessors/json.go`) can be
CVE-2026-15340 9.8 0.60% 1 0 2026-10-09T17:29:33.410000 lwIP SMTP client does not check the size of inputs, potentially allowing a buffe
CVE-2026-107814 8.4 0.28% 1 0 2026-10-09T17:16:45.853000 MariaDB server is a community developed fork of MySQL server. From 10.6.1 until
CVE-2026-107809 8.8 0.18% 1 0 2026-10-09T17:16:45.730000 Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.
CVE-2026-107812 7.5 0.17% 1 0 2026-10-09T17:08:21 ## Summary The self-upgrade downloads the release binary and its checksum (`*.ta
CVE-2026-107808 8.1 0.41% 1 0 2026-10-09T17:08:16 ## Summary nginx-ui supports two second-factor methods — TOTP (OTP) and WebAuth
CVE-2026-107813 8.8 0.30% 1 0 2026-10-09T17:08:07 ## Summary Incomplete fix of GHSA-5v7c-xpfp-p65m: the secure-session (OTP step-
CVE-2026-107807 8.8 0.31% 1 0 2026-10-09T17:07:11 ## 1. Vulnerability Summary nginx-ui's `Node.Secret` is a master credential tha
CVE-2026-107810 8.1 0.36% 1 0 2026-10-09T17:07:06 ### Summary An authenticated user who can create and restore a backup can craft
CVE-2026-108106 7.5 0.37% 1 0 2026-10-09T17:06:17.770000 Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulne
CVE-2026-100730 9.8 0.62% 1 0 2026-10-09T16:41:53.540000 A service console interface on openPDC and openHistorian deserializes a client-s
CVE-2026-107811 8.8 0.36% 1 0 2026-10-09T16:38:57.820000 Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.
CVE-2026-55797 8.8 1.55% 1 0 2026-10-09T16:37:27 ### Impact Argo CD runs a shell command in the repo-server when it clones or fe
CVE-2026-103412 8.8 0.52% 1 0 2026-10-09T16:33:39.007000 Improper limitation of a pathname to a restricted directory ('path traversal') v
CVE-2026-93947 9.3 0.24% 1 0 2026-10-09T16:17:32.090000 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-107375 8.8 0.34% 1 0 2026-10-09T16:17:22.297000 JHipster is a development platform to quickly generate, develop, and deploy mode
CVE-2026-105436 8.8 0.25% 1 0 2026-10-09T16:17:21.427000 Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-ch
CVE-2015-3306 10.0 99.50% 2 18 template 2026-10-09T16:17:18.210000 The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write t
CVE-2026-79842 9.1 0.33% 2 0 2026-10-09T15:32:29 An authentication bypass vulnerability exists in HPE Intelligent Management Cent
CVE-2026-39460 8.1 0.29% 1 0 2026-10-09T15:31:42 Usernames and passwords, including the default factory credentials, are stored i
CVE-2026-108101 7.5 0.39% 1 0 2026-10-09T15:31:38 HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulne
CVE-2026-105281 7.5 0.31% 1 0 2026-10-09T15:31:37 The internal data publisher on openPDC accepts network connections without authe
CVE-2026-28745 7.5 0.22% 1 0 2026-10-09T15:31:35 Usernames and passwords, including the default credentials, are stored in the co
CVE-2026-39453 8.3 0.29% 1 0 2026-10-09T15:31:35 Navigating to a certain URL on the switch’s web server causes the switch to rebo
CVE-2026-33367 8.1 0.29% 1 0 2026-10-09T15:31:35 SNMP can be used to perform administrative actions such as retrieving configurat
CVE-2026-108107 9.8 0.41% 1 0 2026-10-09T15:31:34 PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerabi
CVE-2026-108109 9.1 0.39% 1 0 2026-10-09T15:31:34 PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the c
CVE-2026-83943 8.7 0.38% 1 0 2026-10-09T15:31:32 Exposure of sensitive information to an unauthorized actor in Azure API Center a
CVE-2026-86405 9.8 0.20% 1 0 2026-10-09T15:31:30 Improper verification of cryptographic signature vulnerability in Sipay Electron
CVE-2026-107406 None 0.47% 9 3 2026-10-09T15:31:27 Memory overflow vulnerability leading to Remote Code Execution or Denial of Serv
CVE-2026-94503 10.0 0.28% 1 1 2026-10-09T12:31:48 Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify
CVE-2026-15762 9.8 0.52% 1 0 2026-10-09T04:18:09.937000 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.
CVE-2026-14497 8.1 0.59% 1 0 2026-10-09T04:18:05.817000 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.
CVE-2026-69435 9.6 0.39% 2 0 2026-10-09T00:31:56 Missing authorization in Azure SRE Agent allows an authorized attacker to elevat
CVE-2026-83947 7.7 0.37% 1 0 2026-10-09T00:31:56 Missing authorization in Azure Event Grid allows an authorized attacker to perfo
CVE-2026-77900 9.8 0.49% 2 0 2026-10-09T00:31:56 Missing authentication for critical function in Azure App Service allows an unau
CVE-2026-88131 9.8 0.84% 2 0 2026-10-09T00:31:56 Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized
CVE-2026-84057 8.1 0.36% 1 0 2026-10-09T00:31:56 IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to e
CVE-2026-84035 8.1 0.37% 1 0 2026-10-09T00:31:56 IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker
CVE-2026-84875 7.5 0.42% 1 0 2026-10-09T00:31:56 IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker
CVE-2026-89091 8.8 0.48% 1 0 2026-10-09T00:31:56 A flaw was found in ansible-core. When installing a collection with `ansible-gal
CVE-2026-107701 8.2 0.33% 1 0 2026-10-08T21:35:53.890000 dot-access through 1.0.0 contains a prototype pollution vulnerability that allow
CVE-2026-9209 9.8 0.69% 1 1 2026-10-08T21:35:53.890000 mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulne
CVE-2026-19482 8.8 0.42% 1 0 2026-10-08T21:33:42 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-19491 9.1 0.33% 1 0 2026-10-08T21:33:42 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-19493 7.5 0.36% 1 0 2026-10-08T21:33:42 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-78401 9.8 0.57% 1 0 2026-10-08T21:33:42 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-17189 8.2 0.15% 1 0 2026-10-08T21:33:41 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-16916 9.1 0.42% 1 0 2026-10-08T21:33:41 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-19494 8.1 0.29% 1 0 2026-10-08T21:33:41 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-84275 7.5 0.33% 1 0 2026-10-08T21:33:34 IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM fil
CVE-2026-107704 9.8 1.66% 1 0 2026-10-08T21:33:34 The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injectio
CVE-2026-11318 7.8 0.19% 1 1 2026-10-08T21:33:33 Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.
CVE-2026-107703 9.8 1.85% 1 0 2026-10-08T21:33:33 @enmaso/node-convert through 1.0.0 contains an OS command injection vulnerabilit
CVE-2026-107699 9.8 1.47% 1 0 2026-10-08T21:33:33 ppt2png through 0.0.6 contains an OS command injection vulnerability that allows
CVE-2026-107700 9.8 0.50% 1 0 2026-10-08T21:33:33 dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allo
CVE-2026-107782 7.8 0.11% 1 0 2026-10-08T21:33:32 System Informer before 4.0.26241.138 contains an incorrect authorization vulnera
CVE-2026-84244 9.3 0.18% 1 0 2026-10-08T21:33:28 IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulne
CVE-2026-84276 7.5 0.33% 1 0 2026-10-08T21:33:26 IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerabi
CVE-2026-95210 9.1 0.23% 1 0 2026-10-08T21:33:23 Improper certificate validation in gnutls v3.8.13 causes the application to acce
CVE-2026-107779 9.8 0.54% 1 0 2026-10-08T21:27:15.010000 Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains
CVE-2026-107333 8.1 0.98% 1 0 2026-10-08T21:03:43.847000 Malcolm's nginx based reverse proxy contains a URL path normalization inconsiste
CVE-2026-107383 7.5 0.39% 1 0 2026-10-08T20:25:00.647000 MariaDB Connector/Node.js is used to connect applications developed on Node.js t
CVE-2026-107322 7.8 0.13% 1 0 2026-10-08T20:17:31.590000 An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS database
CVE-2026-76463 8.8 0.14% 1 0 2026-10-08T20:08:45.857000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-107384 8.1 0.45% 1 0 2026-10-08T19:42:25 ### Description With the non-default permitSetMultiParamEntries option enabled,
CVE-2015-5477 7.5 99.41% 2 8 2026-10-08T18:32:53 named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote
CVE-2021-3199 9.8 19.35% 2 0 2026-10-08T18:32:52 Directory traversal with remote code execution can occur in /upload in ONLYOFFIC
CVE-2026-104078 7.8 0.29% 1 0 2026-10-08T18:32:32 Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bun
CVE-2026-104077 7.8 0.35% 1 0 2026-10-08T18:32:31 Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability th
CVE-2026-107377 7.5 0.45% 1 0 2026-10-08T17:58:02 ## Summary When processing an attacker-controlled Protobuf schema, vulnerable v
CVE-2026-107303 7.6 0.26% 1 0 2026-10-08T17:40:32 ## Summary Applications generated by generator-jhipster v9.2.0 can persist user-
CVE-2026-107302 7.5 0.43% 1 0 2026-10-08T17:40:11 ### Impact A truncated `map32` header causes an out-of-bounds buffer read and t
CVE-2026-107300 7.5 0.43% 1 0 2026-10-08T17:40:07 ### Impact The streaming decoder recursively invokes itself for every complete
CVE-2026-107295 7.6 0.16% 1 0 2026-10-08T17:16:37 ### Summary The Pydantic AI development web chat UI (`Agent.to_web()`, `clai we
CVE-2026-93017 7.7 0.21% 1 0 2026-10-08T15:33:15 The `insights-operator-gather` ClusterRole grants the operator's service account
CVE-2026-14992 9.8 0.31% 1 0 2026-10-08T15:33:11 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.
CVE-2026-14502 9.8 0.39% 1 0 2026-10-08T15:33:10 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.
CVE-2026-16340 9.8 0.49% 1 0 2026-10-08T15:33:05 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.
CVE-2026-102255 10.0 0.48% 4 0 2026-10-07T18:33:12 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-76471 9.8 0.52% 1 0 2026-10-07T18:32:21 A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an una
CVE-2026-76467 7.5 0.25% 1 0 2026-10-07T18:32:20 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76464 9.6 0.19% 1 0 2026-10-07T18:32:20 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20362 7.2 0.47% 1 0 2026-10-07T18:32:14 A vulnerability in the web-based management interface of Cisco Finesse could all
CVE-2026-107181 8.1 0.34% 7 1 2026-10-07T15:32:07 Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnera
CVE-2026-21589 0 1.77% 4 12 template 2026-10-07T13:17:22.273000 This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira S
CVE-2026-105192 9.8 0.48% 1 1 2026-10-07T12:31:58 LMCache multiprocess mode, also called distributed mode, opens an unauthenticate
CVE-2025-64393 None 0.36% 2 0 2026-10-07T09:32:29 This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execu
CVE-2026-59346 9.3 0.26% 2 1 2026-10-07T06:33:08 VMware Workstation and Fusion contain an integer-overflow vulnerability. A malic
CVE-2026-79820 9.0 0.27% 1 0 2026-10-06T15:15:48.310000 A remote user validation failure vulnerability exists in HPE Integrated Lights-O
CVE-2026-105134 10.0 1.84% 5 1 2026-10-06T15:04:52.637000 A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects
CVE-2026-105133 7.3 0.38% 5 0 2026-10-04T09:30:21 A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the fu
CVE-2026-88467 6.2 0.12% 1 0 2026-10-01T18:33:43 CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification fu
CVE-2026-48710 6.5 7.06% 1 5 template 2026-10-01T18:17:18.153000 Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the H
CVE-2026-46649 0 0.50% 1 0 2026-09-28T21:17:17.733000 Joplin is an open source note-taking and to-do application that organises notes
CVE-2026-88771 9.8 1.08% 3 14 2026-09-28T12:32:08 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-88772 8.1 1.30% 1 8 2026-09-28T12:26:47.670000 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-82077 None 0.74% 3 0 2026-09-24T09:32:00 An improper limitation of a pathname to a restricted directory (path traversal)
CVE-2026-88404 9.8 0.75% 1 0 2026-09-22T15:33:37 A remote code execution (RCE) vulnerability in the UniscriptExecutionService.exe
CVE-2026-88402 9.8 0.47% 1 0 2026-09-22T15:33:36 A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allow
CVE-2026-61647 None 0.32% 1 0 2026-09-22T14:43:27 ## Summary The `vault_batch` MCP tool (and the equivalent `POST /batch-to-vault
CVE-2026-94571 None 0.53% 1 0 2026-09-21T21:32:01 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject c
CVE-2026-92382 4.1 0.14% 1 0 2026-09-21T18:32:14 An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT s
CVE-2026-87491 8.8 3.14% 1 2 2026-09-21T13:17:11.283000 Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo
CVE-2026-93485 7.1 0.38% 1 4 2026-09-18T06:32:17 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-82078 9.1 63.53% 3 2 2026-09-14T00:16:56.777000 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-0310 None 0.37% 1 0 2026-09-10T06:31:55 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2026-80093 7.0 0.32% 1 0 2026-09-09T00:31:34 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized at
CVE-2026-31431 7.8 3.44% 1 100 template 2026-09-08T09:36:36 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-85046 8.8 48.88% 1 8 2026-09-06T03:30:24 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at
CVE-2026-81578 9.8 85.58% 3 2 template 2026-08-31T21:31:56 An improper access control vulnerability exists in the web management interface
CVE-2026-73570 8.9 71.66% 1 10 template 2026-08-21T18:34:48 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-47483 8.2 0.34% 1 0 2026-07-28T18:33:11 NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pp
CVE-2025-31200 9.8 20.90% 1 4 2026-06-17T09:10:00.550000 A memory corruption issue was addressed with improved bounds checking. This issu
CVE-2025-24201 7.1 3.85% 1 3 2025-11-13T21:31:15 An out-of-bounds write issue was addressed with improved checks to prevent unaut
CVE-2025-47818 2.2 0.24% 1 0 2025-10-24T18:32:04 Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for
CVE-2024-3094 10.0 85.97% 1 90 template 2024-03-29T18:30:50 Malicious code was discovered in the upstream tarballs of xz, starting with vers
CVE-2023-22894 7.5 3.61% 2 2 2023-11-07T05:05:45 ### Summary Strapi through 4.7.1 allows unauthenticated attackers to discover s
CVE-2016-3081 8.1 96.05% 6 0 template 2023-11-01T19:47:30 Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when
CVE-2026-85219 0 0.41% 2 0 N/A
CVE-2026-87902 0 39.98% 2 27 template N/A
CVE-2026-108269 0 0.13% 1 0 N/A
CVE-2026-108263 0 0.43% 1 0 N/A
CVE-2026-107821 0 0.48% 1 0 N/A
CVE-2026-107838 0 0.34% 1 0 N/A
CVE-2026-107837 0 0.38% 1 0 N/A
CVE-2026-61746 0 0.40% 1 0 N/A
CVE-2026-72898 0 19.05% 1 10 template N/A
CVE-2026-106433 0 0.27% 1 0 N/A
CVE-2026-107376 0 0.45% 1 0 N/A
CVE-2026-107332 0 0.11% 1 0 N/A

CVE-2026-106609
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-10T18:31:27

2 posts

Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2.

thehackerwire@mastodon.social at 2026-10-10T17:30:42.000Z ##

🟠 CVE-2026-106609 - High (7.5)

Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T17:30:42.000Z ##

🟠 CVE-2026-106609 - High (7.5)

Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105889
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-10-10T18:31:27

2 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.

thehackerwire@mastodon.social at 2026-10-10T17:30:33.000Z ##

🔴 CVE-2026-105889 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T17:30:33.000Z ##

🔴 CVE-2026-105889 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103071
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-10T18:31:26

2 posts

Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from n/a through 1.2.3.

thehackerwire@mastodon.social at 2026-10-10T17:30:51.000Z ##

🟠 CVE-2026-103071 - High (7.5)

Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T17:30:51.000Z ##

🟠 CVE-2026-103071 - High (7.5)

Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104398
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-10T17:16:59.937000

2 posts

Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.10.

thehackerwire@mastodon.social at 2026-10-10T17:31:32.000Z ##

🔴 CVE-2026-104398 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T17:31:32.000Z ##

🔴 CVE-2026-104398 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108546
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-10T15:30:30

2 posts

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substituted unescaped for $SPOTTITLE and passed to exec() when a user downloads the spot, running commands as

thehackerwire@mastodon.social at 2026-10-10T17:45:49.000Z ##

🟠 CVE-2026-108546 - High (7.5)

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with sh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T17:45:49.000Z ##

🟠 CVE-2026-108546 - High (7.5)

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with sh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105885
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-10T15:30:29

2 posts

Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.

thehackerwire@mastodon.social at 2026-10-10T17:46:26.000Z ##

🟠 CVE-2026-105885 - High (8.8)

Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T17:46:26.000Z ##

🟠 CVE-2026-105885 - High (8.8)

Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108549
(8.1 HIGH)

EPSS: 0.00%

updated 2026-10-10T15:30:29

2 posts

cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host.

thehackerwire@mastodon.social at 2026-10-10T17:46:17.000Z ##

🟠 CVE-2026-108549 - High (8.1)

cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T17:46:17.000Z ##

🟠 CVE-2026-108549 - High (8.1)

cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108551
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-10T15:30:29

2 posts

openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers can embed a single quote in path keys, parameter names, servers[0].url, or info.version to execute arbitrary JavaScript when generated clients are importe

thehackerwire@mastodon.social at 2026-10-10T17:31:50.000Z ##

🔴 CVE-2026-108551 - Critical (9.8)

openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T17:31:50.000Z ##

🔴 CVE-2026-108551 - Critical (9.8)

openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108550
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-10T15:30:24

2 posts

SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge initiate endpoint with a target username or OAuth identity, receive the verification token directly, and confirm the merge to inherit the victim's API tokens

thehackerwire@mastodon.social at 2026-10-10T17:31:41.000Z ##

🟠 CVE-2026-108550 - High (8.8)

SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge init...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T17:31:41.000Z ##

🟠 CVE-2026-108550 - High (8.8)

SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge init...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108553
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-10T15:16:58.410000

2 posts

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user.

thehackerwire@mastodon.social at 2026-10-10T17:45:40.000Z ##

🟠 CVE-2026-108553 - High (7.5)

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T17:45:40.000Z ##

🟠 CVE-2026-108553 - High (7.5)

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108161
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-10T14:16:37.223000

2 posts

FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename template is enabled, attackers can embed shell metacharacters like $(...) in the Caller-ID name or number, executing commands as the web server user once a priv

thehackerwire@mastodon.social at 2026-10-10T17:46:35.000Z ##

🟠 CVE-2026-108161 - High (7.5)

FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename templat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T17:46:35.000Z ##

🟠 CVE-2026-108161 - High (7.5)

FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename templat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104803
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-10-10T09:30:37

2 posts

The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerability exists because the `login` function's social-login flow performs no nonce validation, no OAuth state verification, and no per-visitor namespace isolation i

offseq at 2026-10-10T09:00:24.576Z ##

WPCOM Member plugin (≤1.7.27) suffers CRITICAL auth bypass (CVE-2026-104803, CVSS 9.8) 🛡️. Attackers can impersonate any WordPress user via social-login flaw. Disable social login & check vendor for fixes. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-10T09:00:24.000Z ##

WPCOM Member plugin (≤1.7.27) suffers CRITICAL auth bypass (CVE-2026-104803, CVSS 9.8) 🛡️. Attackers can impersonate any WordPress user via social-login flaw. Disable social login & check vendor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE2026104803

##

CVE-2026-91136
(7.5 HIGH)

EPSS: 0.56%

updated 2026-10-10T09:16:39.360000

2 posts

The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permission callback (SVGAnimatorController::index_permission) returning true unconditionally combined with insufficient validation of the 'svg_image' input — san

thehackerwire@mastodon.social at 2026-10-10T18:00:35.000Z ##

🟠 CVE-2026-91136 - High (7.5)

The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permissi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T18:00:35.000Z ##

🟠 CVE-2026-91136 - High (7.5)

The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permissi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96662
(7.5 HIGH)

EPSS: 0.39%

updated 2026-10-10T08:17:08.033000

2 posts

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to a

thehackerwire@mastodon.social at 2026-10-10T18:00:45.000Z ##

🟠 CVE-2026-96662 - High (7.5)

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient esca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T18:00:45.000Z ##

🟠 CVE-2026-96662 - High (7.5)

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient esca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93950
(7.5 HIGH)

EPSS: 0.20%

updated 2026-10-10T08:17:07.307000

2 posts

Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.

thehackerwire@mastodon.social at 2026-10-10T18:15:24.000Z ##

🟠 CVE-2026-93950 - High (7.5)

Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T18:15:24.000Z ##

🟠 CVE-2026-93950 - High (7.5)

Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93945
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-10T08:17:07.057000

4 posts

Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.

thehackerwire@mastodon.social at 2026-10-10T18:00:54.000Z ##

🔴 CVE-2026-93945 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-10-10T12:00:24.024Z ##

CRITICAL: CVE-2026-93945 in Axiomthemes Balance (<=1.12.0) allows remote object injection via deserialization of untrusted data. No auth or user action needed — full system compromise possible. Restrict access & monitor vendor updates. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-10-10T18:00:54.000Z ##

🔴 CVE-2026-93945 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-10T12:00:24.000Z ##

CRITICAL: CVE-2026-93945 in Axiomthemes Balance (<=1.12.0) allows remote object injection via deserialization of untrusted data. No auth or user action needed — full system compromise possible. Restrict access & monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Vuln

##

CVE-2026-93944
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-10T08:17:06.930000

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.

offseq at 2026-10-10T13:30:24.958Z ##

CVE-2026-93944: CRITICAL deserialization vuln in ThemeREX Camelia (<=1.2.15). Allows remote object injection & full system compromise. No patch yet — limit exposure, monitor vendor. 🔎 radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-10T13:30:24.000Z ##

CVE-2026-93944: CRITICAL deserialization vuln in ThemeREX Camelia (<=1.2.15). Allows remote object injection & full system compromise. No patch yet — limit exposure, monitor vendor. 🔎 radar.offseq.com/threat/cve-20 #OffSeq #Infosec #Vulnerability

##

CVE-2026-93941
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-10T08:17:06.557000

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.

thehackerwire@mastodon.social at 2026-10-10T18:30:45.000Z ##

🔴 CVE-2026-93941 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T18:30:45.000Z ##

🔴 CVE-2026-93941 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93940
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-10T08:17:06.433000

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.

thehackerwire@mastodon.social at 2026-10-10T18:30:36.000Z ##

🔴 CVE-2026-93940 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T18:30:36.000Z ##

🔴 CVE-2026-93940 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93938
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-10T08:17:06.310000

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.

thehackerwire@mastodon.social at 2026-10-10T18:30:26.000Z ##

🔴 CVE-2026-93938 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T18:30:26.000Z ##

🔴 CVE-2026-93938 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93937
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-10T08:17:06.187000

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.

thehackerwire@mastodon.social at 2026-10-10T18:15:43.000Z ##

🔴 CVE-2026-93937 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T18:15:43.000Z ##

🔴 CVE-2026-93937 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93936
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-10T08:17:06.060000

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.

thehackerwire@mastodon.social at 2026-10-10T18:15:33.000Z ##

🔴 CVE-2026-93936 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-10T18:15:33.000Z ##

🔴 CVE-2026-93936 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62046
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-10-10T08:17:04.777000

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.

offseq at 2026-10-10T10:30:24.636Z ##

CVE-2026-62046: CRITICAL deserialization flaw in ThemeREX Gutentype (≤2.1.12) allows object injection — full system compromise possible. Patch status unknown, monitor vendor updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-10T10:30:24.000Z ##

CVE-2026-62046: CRITICAL deserialization flaw in ThemeREX Gutentype (≤2.1.12) allows object injection — full system compromise possible. Patch status unknown, monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #Infosec

##

CVE-2026-62045
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-10-10T08:17:04.647000

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.

offseq at 2026-10-10T07:30:23.705Z ##

Deserialization of untrusted data in ThemeREX Booklovers (<=2.13.0) — CVE-2026-62045 (CRITICAL, CVSS 9.8) enables object injection. No patch yet, so restrict access & monitor. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-10T07:30:23.000Z ##

Deserialization of untrusted data in ThemeREX Booklovers (<=2.13.0) — CVE-2026-62045 (CRITICAL, CVSS 9.8) enables object injection. No patch yet, so restrict access & monitor. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202662045 #WordPress #Vuln #infosec

##

CVE-2026-97670
(9.1 CRITICAL)

EPSS: 0.37%

updated 2026-10-10T06:31:08

1 posts

The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a WordPress action hook whose name is taken from an attacker-supplied form-field value (via the notification email_message [field] placeholder and the {action_hook,...} dynamic-data toke

offseq@infosec.exchange at 2026-10-10T06:00:25.000Z ##

CVE-2026-97670: Avada (Fusion) Builder ≤7.16.1 has a CRITICAL code injection flaw. Unauthenticated attackers can invoke arbitrary WP action hooks — risks include content deletion & DoS. Disable vulnerable forms, await patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE202697670

##

CVE-2026-94589
(9.8 CRITICAL)

EPSS: 0.66%

updated 2026-10-10T06:31:06

1 posts

The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload

offseq@infosec.exchange at 2026-10-10T04:30:25.000Z ##

CVE-2026-94589: CRITICAL RCE in Extensions For CF7 (<=3.4.5) for WordPress. Unauth attackers can upload and run malicious files — full compromise possible. Restrict uploads, monitor activity, and check for fixes. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202694589 #infosec

##

CVE-2026-96207
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-10-10T04:18:19.870000

2 posts

Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T00:00:41.000Z ##

CVE-2026-96207 (CRITICAL, CVSS 10) affects Microsoft Partner Center: improper certificate validation (CWE-295) allows remote privilege escalation. Patch available — apply ASAP. No public exploits seen. radar.offseq.com/threat/cve-20 #OffSeq #Microsoft #CVE202696207 #Infosec

##

CVE-2026-94510
(9.9 CRITICAL)

EPSS: 0.40%

updated 2026-10-10T04:18:19.577000

2 posts

Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T01:30:26.000Z ##

CVE-2026-94510 (CRITICAL, CVSS 9.9) in Microsoft Bookings enables remote privilege escalation via authorization bypass (CWE-639). Apply the official Microsoft patch now: radar.offseq.com/threat/cve-20 #OffSeq #Microsoft #Vuln #CVE #Infosec

##

CVE-2026-84249
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-10-10T04:18:18.437000

1 posts

IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function.

thehackerwire@mastodon.social at 2026-10-08T22:30:58.000Z ##

🔴 CVE-2026-84249 - Critical (9.8)

IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84058
(8.1 HIGH)

EPSS: 0.36%

updated 2026-10-10T04:18:17.540000

1 posts

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM Guardium Collector may cause a denial of service or potentially execute arbitrary code on the Collector appliance.

thehackerwire@mastodon.social at 2026-10-08T22:32:22.000Z ##

🟠 CVE-2026-84058 - High (8.1)

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82344
(8.1 HIGH)

EPSS: 0.40%

updated 2026-10-10T04:18:16.730000

1 posts

IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reassembly buffer, potentially resulting in denial of service or arbitrary code execution on the affected system.

thehackerwire@mastodon.social at 2026-10-08T21:00:48.000Z ##

🟠 CVE-2026-82344 - High (8.1)

IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78406
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-10-10T04:18:15.970000

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

thehackerwire@mastodon.social at 2026-10-08T21:31:12.000Z ##

🔴 CVE-2026-78406 - Critical (9.8)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18740
(8.8 HIGH)

EPSS: 0.35%

updated 2026-10-10T04:18:12.470000

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection.

thehackerwire@mastodon.social at 2026-10-08T22:00:48.000Z ##

🟠 CVE-2026-18740 - High (8.8)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16823
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-10-10T04:18:12.110000

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass security restrictions due to improper authentication.

thehackerwire@mastodon.social at 2026-10-08T21:47:11.000Z ##

🔴 CVE-2026-16823 - Critical (9.1)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass security restrictions due to improper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108474
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-10-10T00:17:03.673000

1 posts

In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions

offseq@infosec.exchange at 2026-10-10T00:00:36.000Z ##

CVE-2026-108474: JetBrains Exposed (<1.5.1) faces CRITICAL SQL injection (CWE-89). Exploitation can fully compromise DBs — upgrade to 1.5.1+ now! CVSS 9.8. radar.offseq.com/threat/cve-20 #OffSeq #SQLi #JetBrains #AppSec

##

CVE-2026-108268
(0 None)

EPSS: 0.13%

updated 2026-10-09T22:16:59.643000

1 posts

Enclave OS Virtual runs container workloads inside confidential virtual machines with end-to-end attestation. Prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, the TDX/GPU RA-TLS certificate issuer placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote o

offseq@infosec.exchange at 2026-10-10T03:00:23.000Z ##

CVE-2026-108268 (CRITICAL, CVSS 9.1): Privasys enclave-os-virtual <0.2.43/<0.6.27 origin validation error lets attackers relay attestation quotes if they have the enclave TLS private key. Upgrade to patched versions ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026108268 #Vuln

##

CVE-2026-75351
(7.5 HIGH)

EPSS: 0.40%

updated 2026-10-09T21:31:18

1 posts

OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remote attacker to cause a denial of service.

thehackerwire@mastodon.social at 2026-10-09T21:47:06.000Z ##

🟠 CVE-2026-75351 - High (7.5)

OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remote attacker to cause a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75346
(7.5 HIGH)

EPSS: 0.54%

updated 2026-10-09T21:31:17

1 posts

An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a denial of service

thehackerwire@mastodon.social at 2026-10-09T22:01:13.000Z ##

🟠 CVE-2026-75346 - High (7.5)

An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a denial of service

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92705
(7.8 HIGH)

EPSS: 0.13%

updated 2026-10-09T21:17:06.360000

1 posts

Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects without asking whether the user trusts the scripts or their authors. An attacker can distribute a crafted `ASS` file together with a referenced malicious Automation script, and opening the `AS`  file execute

thehackerwire@mastodon.social at 2026-10-09T21:32:26.000Z ##

🟠 CVE-2026-92705 - High (7.8)

Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects without asking whether the user trusts the scripts or ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108264
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-10-09T21:17:04.703000

1 posts

Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers. Prior to 2026.9.1, wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py in the application's non-sandboxed Jinja2 environment with application globals exposed. An authenticated user able to create steps, or an administrator

thehackerwire@mastodon.social at 2026-10-09T21:46:57.000Z ##

🔴 CVE-2026-108264 - Critical (9.1)

Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers. Prior to 2026.9.1, wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108259
(8.2 HIGH)

EPSS: 0.25%

updated 2026-10-09T21:17:04.017000

1 posts

Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and interpolates that URL into JavaScript string literals in packages/@tinacms/cli/src/next/codegen/index.ts and packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts. A crafted Git-valid branch name c

thehackerwire@mastodon.social at 2026-10-09T21:45:58.000Z ##

🟠 CVE-2026-108259 - High (8.2)

Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and interpolates that URL into JavaScript string li...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107805
(7.5 HIGH)

EPSS: 0.44%

updated 2026-10-09T20:57:10

1 posts

## Summary In Nginx UI versions 2.5.0 through 2.5.x, the node-signature authentication path staged an attacker-controlled request body in a temporary file and synchronized it to disk before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API can provide syntactically valid signature metadata and cause storage and I/O consumption before t

thehackerwire@mastodon.social at 2026-10-09T22:46:26.000Z ##

🟠 CVE-2026-107805 - High (7.5)

Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108261
(9.3 CRITICAL)

EPSS: 0.16%

updated 2026-10-09T20:56:50

1 posts

### Summary The TinaCMS admin builds its preview `<iframe src>` from the `/~/*` hash-router splat without checking that the value stays same-origin. A fragment with a doubled slash (`#/~//attacker.example/p`) becomes the protocol-relative URL `//attacker.example/p`, so the admin frames an external site. That same unvalidated string derives `expectedOrigin`, the only trust anchor for the admin↔pre

thehackerwire@mastodon.social at 2026-10-09T21:46:15.000Z ##

🔴 CVE-2026-108261 - Critical (9.3)

Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL thr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108260
(7.6 HIGH)

EPSS: 0.21%

updated 2026-10-09T20:56:46

1 posts

### Summary `<tina-markdown>` renders a rich-text AST into the DOM and, for `a` nodes, assigns the node's URL straight to the anchor's `href` with no scheme check. A link authored in the CMS as `javascript:…` renders as a live `javascript:` anchor, so a visitor who clicks it executes attacker-supplied script in the site's origin. Every sibling renderer in the repository already sanitizes these UR

thehackerwire@mastodon.social at 2026-10-09T21:46:07.000Z ##

🟠 CVE-2026-108260 - High (7.6)

Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107845
(9.3 CRITICAL)

EPSS: 0.27%

updated 2026-10-09T20:53:52

1 posts

An unauthenticated front end visitor can post a comment containing a XSS injection. The victim is any back end user who opens the Comments module, and moderation makes exposure certain rather than preventing it. No `Content-Security-Policy` header is sent on the Contao back end, so nothing mitigates the inline handler. ### Impact Anyone on the internet can inject script that executes in the Cont

thehackerwire@mastodon.social at 2026-10-09T20:31:16.000Z ##

🔴 CVE-2026-107845 - Critical (9.3)

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62376
(8.1 HIGH)

EPSS: 0.21%

updated 2026-10-09T20:49:15

1 posts

### Summary Vikunja stores password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in **plaintext**. If an attacker gains read access to the database through a backup leak, misconfigured storage, or SQL-level exposure, they can immediately use pending tokens to take over user accounts without knowing passwords. ### Details `pkg/user/token.go` — `genToken()` st

thehackerwire@mastodon.social at 2026-10-09T21:32:45.000Z ##

🟠 CVE-2026-62376 - High (8.1)

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107806(CVSS UNKNOWN)

EPSS: 0.33%

updated 2026-10-09T20:45:03

1 posts

## Summary An authenticated nginx-ui user can call `POST /api/restore`, upload a forged encrypted backup, restore `app.ini`, set nginx command settings such as `TestConfigCmd`, and then trigger command execution with `POST /api/nginx/test`. This was validated on nginx-ui `2.3.11 2(523) 6c86e5a5` in the local Docker container `uozi/nginx-ui:latest`. ## Impact An authenticated user can overwr

1 repos

https://github.com/murrez/CVE-2026-107806

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:23:53.000Z ##

A critical Nginx UI RCE vulnerability (CVE-2026-107806) is publicly disclosed with PoC exploit code. Admins must patch now to prevent system takeover.

#NginxUI #RCE #Vulnerability #CVE2026107806 #CyberSecurity

securityonline.info/nginx-ui-r

##

CVE-2026-107839
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-09T20:44:55

1 posts

### Summary The AoE3 `POST /game/cloud/getFileURL` handler in `luskaner/ageLANServer`'s bundled game server decodes an attacker-controlled `names` JSON array and immediately allocates response storage sized directly from the array's length (`make(i.A, len(req.Names.Data))`), with no request body size limit and no cap on the number of array elements anywhere in the request path. Because the default

thehackerwire@mastodon.social at 2026-10-09T18:45:33.000Z ##

🟠 CVE-2026-107839 - High (7.5)

ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Age of Empires and Age of Mythology games. Prior to version 1.15.2, the AoE3 POST /game/cloud/getFileURL handler in the bundled game server has no re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57458
(8.1 HIGH)

EPSS: 0.27%

updated 2026-10-09T20:40:28

1 posts

## Summary A scoped API token can bypass its declared permissions by using the OAuth authorization flow to mint normal session credentials. A token limited to: ```json {"oauth":["authorize"]} ``` can call `/api/v1/oauth/authorize`, receive an OAuth authorization code, exchange it at `/api/v1/oauth/token`, and obtain a normal bearer JWT plus refresh token. The resulting credentials are not rest

thehackerwire@mastodon.social at 2026-10-09T21:32:35.000Z ##

🟠 CVE-2026-57458 - High (8.1)

Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAuth authorization code, and exchange the code at ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107840
(7.5 HIGH)

EPSS: 0.44%

updated 2026-10-09T20:17:09.900000

1 posts

yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_requests_total and yopass_http_request_duration_seconds. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacke

thehackerwire@mastodon.social at 2026-10-09T18:45:43.000Z ##

🟠 CVE-2026-107840 - High (7.5)

yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_req...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103413
(8.8 HIGH)

EPSS: 0.39%

updated 2026-10-09T18:32:43

1 posts

Improper input validation vulnerability in Apache Camel Karavan. When a deployment was started, Karavan unmarshalled a project's `kubernetes.yaml` and applied every resource it contained to the cluster without restricting the resource kinds, without rejecting security-sensitive pod options, and without pinning the target namespace. An authenticated user of any role could therefore have Karavan

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:13:23.000Z ##

Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now.

#ApacheCamel #CyberSecurity #Vulnerability #CVE2026103413 #CVE2026103412

securityonline.info/apache-cam

##

CVE-2026-75347
(7.5 HIGH)

EPSS: 0.42%

updated 2026-10-09T18:31:53

1 posts

EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired pointer dereference vulnerability in the EtherNet/IP Common Packet Format (CPF) handling logic. This allows a remote attacker to cause a denial of service.

thehackerwire@mastodon.social at 2026-10-09T17:30:27.000Z ##

🟠 CVE-2026-75347 - High (7.5)

EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired pointer dereference vulnerability in the EtherNet/IP Common Packet Format (CPF) handling logic. This allows a remote attacker to cause a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108113
(8.8 HIGH)

EPSS: 0.64%

updated 2026-10-09T18:31:48

1 posts

ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server u

thehackerwire@mastodon.social at 2026-10-09T20:01:18.000Z ##

🟠 CVE-2026-108113 - High (8.8)

ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import ri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75349
(7.5 HIGH)

EPSS: 0.45%

updated 2026-10-09T18:31:48

1 posts

EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.

thehackerwire@mastodon.social at 2026-10-09T19:31:06.000Z ##

🟠 CVE-2026-75349 - High (7.5)

EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108160
(7.5 HIGH)

EPSS: 0.15%

updated 2026-10-09T18:31:48

1 posts

AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and server can serve a malicious update manifest and NSIS installer, which electron-updater installs without signature verification, executing code as the d

thehackerwire@mastodon.social at 2026-10-09T17:30:45.000Z ##

🟠 CVE-2026-108160 - High (7.5)

AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104084
(8.8 HIGH)

EPSS: 0.25%

updated 2026-10-09T18:31:47

1 posts

SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refresh-token. Attackers who capture a refresh token issued before an administrator demotion, or a demoted user whose session was not actively polling at the

thehackerwire@mastodon.social at 2026-10-09T20:45:58.000Z ##

🟠 CVE-2026-104084 - High (8.8)

SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75345
(7.5 HIGH)

EPSS: 0.45%

updated 2026-10-09T18:31:47

1 posts

OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.

thehackerwire@mastodon.social at 2026-10-09T19:30:48.000Z ##

🟠 CVE-2026-75345 - High (7.5)

OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90983
(8.2 HIGH)

EPSS: 0.26%

updated 2026-10-09T18:31:47

1 posts

Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass. This issue affects Hayat Mobile: from 3.3.0 before 3.4.0.

thehackerwire@mastodon.social at 2026-10-09T18:46:45.000Z ##

🟠 CVE-2026-90983 - High (8.2)

Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass.

This issue affects Hayat Mobile: from 3.3.0 before 3.4.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108157
(8.1 HIGH)

EPSS: 0.53%

updated 2026-10-09T18:31:44

1 posts

Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing email_verified check in GenericOidcProvider, to sign in as the vi

thehackerwire@mastodon.social at 2026-10-09T17:31:47.000Z ##

🟠 CVE-2026-108157 - High (8.1)

Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can registe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78795
(7.5 HIGH)

EPSS: 0.45%

updated 2026-10-09T18:17:14.903000

1 posts

An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remote attacker to obtain sensitive information

thehackerwire@mastodon.social at 2026-10-09T20:46:08.000Z ##

🟠 CVE-2026-78795 - High (7.5)

An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remote attacker to obtain sensitive information

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75350
(7.5 HIGH)

EPSS: 0.48%

updated 2026-10-09T18:17:14.037000

1 posts

EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in the GetAttributeList() implementation for the EtherNet/IP Get_Attribute_List service. This allows a remote attacker to cause a denial of service

thehackerwire@mastodon.social at 2026-10-09T18:30:51.000Z ##

🟠 CVE-2026-75350 - High (7.5)

EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in the GetAttributeList() implementation for the EtherNet/IP Get_Attribute_List service. This allows a remote attacker to cause a denial of service

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75348
(7.5 HIGH)

EPSS: 0.51%

updated 2026-10-09T18:17:13.893000

1 posts

An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommonPacketFormatStructure() when it parses recognized optional socket address information items of type 0x8000 or 0x8001 without first validating that the remaining CPF buffer contains the complete fixed s

thehackerwire@mastodon.social at 2026-10-09T19:30:57.000Z ##

🟠 CVE-2026-75348 - High (7.5)

An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommonPacketFormatStructure() when it parses recognize...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107818
(8.4 HIGH)

EPSS: 0.34%

updated 2026-10-09T18:17:03.373000

1 posts

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mariadb.service unit used /run/mysqld/wsrep-new-cluster during the next service restart. A database user with FILE privilege and a secure-file-priv configuration permitting writes to /run/mysqld could create that file and inject attacker-controlled environment

thehackerwire@mastodon.social at 2026-10-09T18:46:27.000Z ##

🟠 CVE-2026-107818 - High (8.4)

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mariadb.service unit used /run/mysqld/wsrep-new-cluster during the next service restart. A database user wi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108159
(7.5 HIGH)

EPSS: 0.33%

updated 2026-10-09T17:41:47.060000

1 posts

AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed prompt-injection content in a web page so the model emits HTML event handlers invoking the unrestricted open-path IPC handler with shell metacharacters, execu

thehackerwire@mastodon.social at 2026-10-09T17:30:36.000Z ##

🟠 CVE-2026-108159 - High (7.5)

AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed promp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107815
(8.5 HIGH)

EPSS: 0.57%

updated 2026-10-09T17:41:29.727000

1 posts

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the CONNECT engine's DOS table type used an incorrect boundary check that permitted a one-byte null write beyond a stack buffer at an attacker-controlled offset. An authenticated user able to use the CONNECT engine could cause a crash and potentially remote code e

thehackerwire@mastodon.social at 2026-10-09T17:31:56.000Z ##

🟠 CVE-2026-107815 - High (8.5)

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the CONNECT engine's DOS table type used an incorrect boundary check that permitted a one-byte null write beyon...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107826
(7.5 HIGH)

EPSS: 0.46%

updated 2026-10-09T17:33:55

1 posts

### Summary The JSON body processor (`internal/bodyprocessors/json.go`) can be made to crash the whole process with an unrecoverable `fatal error: stack overflow`, using a request body that is well under the recommended `SecRequestBodyLimit` and the default `SecArgumentsLimit`. ### Root cause `readJSON` (json.go:113-143) runs a bounded, best-effort flattening walk (`readItems`) and *afterwards*

thehackerwire@mastodon.social at 2026-10-09T18:45:52.000Z ##

🟠 CVE-2026-107826 - High (7.5)

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15340
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-10-09T17:29:33.410000

1 posts

lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.

thehackerwire@mastodon.social at 2026-10-09T22:01:22.000Z ##

🔴 CVE-2026-15340 - Critical (9.8)

lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107814
(8.4 HIGH)

EPSS: 0.28%

updated 2026-10-09T17:16:45.853000

1 posts

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home directory. A database user with the FILE privilege could write startup dot-files such as .bash_profile into $HOME, and those files could execute when an a

thehackerwire@mastodon.social at 2026-10-09T20:01:10.000Z ##

🟠 CVE-2026-107814 - High (8.4)

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107809
(8.8 HIGH)

EPSS: 0.18%

updated 2026-10-09T17:16:45.730000

1 posts

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do not universally require a CSRF token or perform Origin or Referer validation, a remote attacker can induce a logged-in administrator's browser to submit authenti

thehackerwire@mastodon.social at 2026-10-09T20:16:14.000Z ##

🟠 CVE-2026-107809 - High (8.8)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do not univ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107812
(7.5 HIGH)

EPSS: 0.17%

updated 2026-10-09T17:08:21

1 posts

## Summary The self-upgrade downloads the release binary and its checksum (`*.tar.gz` and `*.tar.gz.digest`) through the SAME endpoint (`version.GetUrl()`, which is `github_proxy` or, by default, the project's `cloud.nginxui.com` mirror), and verifies the binary ONLY by comparing it to that digest: `digestFileContent == DigestSHA512(tarName)`. Both the binary and the digest come from the same orig

thehackerwire@mastodon.social at 2026-10-09T20:45:50.000Z ##

🟠 CVE-2026-107812 - High (7.5)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgrade mirror. A compromised mirror or network attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107808
(8.1 HIGH)

EPSS: 0.41%

updated 2026-10-09T17:08:16

1 posts

## Summary nginx-ui supports two second-factor methods — TOTP (OTP) and WebAuthn passkeys — and reports an account as 2FA-enabled when **either** is configured. However, the password login endpoint (`POST /api/login`) only enforces a second factor when a **TOTP secret** is present. An account that has registered a **passkey but no TOTP** is logged in after password verification alone — the passke

thehackerwire@mastodon.social at 2026-10-09T20:16:06.000Z ##

🟠 CVE-2026-107808 - High (8.1)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107813
(8.8 HIGH)

EPSS: 0.30%

updated 2026-10-09T17:08:07

1 posts

## Summary Incomplete fix of GHSA-5v7c-xpfp-p65m: the secure-session (OTP step-up) requirement added to the nginx, cert, dns, backup, site, and stream mutation routers was not applied to the parallel api/cluster router, so cluster node management and cluster-wide nginx reload/restart run with only a JWT and no step-up. An authenticated user whose JWT is stolen or persisted, but who does not hold

thehackerwire@mastodon.social at 2026-10-09T20:01:00.000Z ##

🟠 CVE-2026-107813 - High (8.8)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without RequireSecur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107807
(8.8 HIGH)

EPSS: 0.31%

updated 2026-10-09T17:07:11

1 posts

## 1. Vulnerability Summary nginx-ui's `Node.Secret` is a master credential that bypasses all JWT/password authentication for the entire API. The application accepts this credential via a **URL query parameter** (`?node_secret=`), causing it to be recorded in plaintext in HTTP access logs, reverse proxy logs, browser history, and HTTP `Referer` headers. Additionally, the official cluster configur

thehackerwire@mastodon.social at 2026-10-09T20:15:56.000Z ##

🟠 CVE-2026-107807 - High (8.8)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Nod...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107810
(8.1 HIGH)

EPSS: 0.36%

updated 2026-10-09T17:07:06

1 posts

### Summary An authenticated user who can create and restore a backup can craft a valid backup archive that causes the restore staging process to write attacker-controlled files into the live Nginx configuration path even when both `restore_nginx` and `restore_nginx_ui` are set to `false`. ### Details The restore flow always extracts the outer archive, verifies the manifest, decrypts `nginx-ui.zi

thehackerwire@mastodon.social at 2026-10-09T20:31:25.000Z ##

🟠 CVE-2026-107810 - High (8.1)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Nginx config...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108106
(7.5 HIGH)

EPSS: 0.37%

updated 2026-10-09T17:06:17.770000

1 posts

Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.uncompress, uncompressString, SnappyInputStream or SnappyFramedInputStream to force allocations up to 2 GB, causing OutOfMemoryError and denial of service

thehackerwire@mastodon.social at 2026-10-09T22:17:09.000Z ##

🟠 CVE-2026-108106 - High (7.5)

Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100730
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-10-09T16:41:53.540000

1 posts

A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which c

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:05:45.000Z ##

Fix critical openPDC openHistorian vulnerabilities like CVE-2026-100730 and CVE-2026-105281. CISA urges patching these severe RCE flaws immediately.

#openPDC #openHistorian #CyberSecurity #Vulnerability #CISA

securityonline.info/openpdc-op

##

CVE-2026-107811
(8.8 HIGH)

EPSS: 0.36%

updated 2026-10-09T16:38:57.820000

1 posts

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node auth

thehackerwire@mastodon.social at 2026-10-09T20:31:34.000Z ##

🟠 CVE-2026-107811 - High (8.8)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55797
(8.8 HIGH)

EPSS: 1.55%

updated 2026-10-09T16:37:27

1 posts

### Impact Argo CD runs a shell command in the repo-server when it clones or fetches an SSH Git repository that has a proxy URL. The proxy host and port are copied into an SSH `ProxyCommand`. A host that contains shell metacharacters breaks out of that command and runs in the repo-server. All versions from v2.11.0 onward are affected, including every currently supported release. v2.10.20 and ear

thehackerwire@mastodon.social at 2026-10-09T17:31:38.000Z ##

🟠 CVE-2026-55797 - High (8.8)

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103412
(8.8 HIGH)

EPSS: 0.52%

updated 2026-10-09T16:33:39.007000

1 posts

Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan. A project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any locat

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:13:23.000Z ##

Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now.

#ApacheCamel #CyberSecurity #Vulnerability #CVE2026103413 #CVE2026103412

securityonline.info/apache-cam

##

CVE-2026-93947
(9.3 CRITICAL)

EPSS: 0.24%

updated 2026-10-09T16:17:32.090000

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through 3.2.9.

offseq@infosec.exchange at 2026-10-09T10:30:25.000Z ##

CVE-2026-93947: CRITICAL SQL Injection in Shinetheme Traveler (0 – 3.2.9). Blind SQLi risk — attackers may access sensitive DB data. Patch when available & monitor your systems. radar.offseq.com/threat/cve-20 #OffSeq #CVE202693947 #SQLInjection #InfoSec

##

CVE-2026-107375
(8.8 HIGH)

EPSS: 0.34%

updated 2026-10-09T16:17:22.297000

1 posts

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. From 7.0.0 until 9.4.0, reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL database pass the attacker-controlled sort request parameter from paginated entity-list endpoints into createOrderByFields in generators/spring-boot/generators/da

thehackerwire@mastodon.social at 2026-10-08T18:30:43.000Z ##

🟠 CVE-2026-107375 - High (8.8)

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. From 7.0.0 until 9.4.0, reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL database ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105436
(8.8 HIGH)

EPSS: 0.25%

updated 2026-10-09T16:17:21.427000

1 posts

Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.

thehackerwire@mastodon.social at 2026-10-08T17:30:39.000Z ##

🟠 CVE-2026-105436 - High (8.8)

Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:02:00.000Z ##

CVE ID: CVE-2015-3306
Vendor: ProFTPD
Product: ProFTPD
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-79842
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-10-09T15:32:29

2 posts

An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713

DailyCyberSecurity@infosec.exchange at 2026-10-09T01:53:05.000Z ##

HPE fixes a critical HPE iLO 7 vulnerability, CVE-2026-79820, and iMC authentication bypass CVE-2026-79842. Update iLO to 1.25.01 now.

#HPE #iLO #iMC #CVE202679820 #CVE202679842 #AuthBypass #ServerSecurity #Vulnerability

securityonline.info/hpe-ilo-7-

##

thehackerwire@mastodon.social at 2026-10-08T21:31:21.000Z ##

🔴 CVE-2026-79842 - Critical (9.1)

An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39460
(8.1 HIGH)

EPSS: 0.29%

updated 2026-10-09T15:31:42

1 posts

Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device through a TFTP transfer from the web interface. A TFTP transfer can be initiated through SNMP which does not require authentication.

thehackerwire@mastodon.social at 2026-10-09T21:01:19.000Z ##

🟠 CVE-2026-39460 - High (8.1)

Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device thro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108101
(7.5 HIGH)

EPSS: 0.39%

updated 2026-10-09T15:31:38

1 posts

HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files via /plants/attachments/add for stored cross-site scripting, or PHP files where .htaccess is unenforced to execute code.

thehackerwire@mastodon.social at 2026-10-09T22:46:17.000Z ##

🟠 CVE-2026-108101 - High (7.5)

HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105281
(7.5 HIGH)

EPSS: 0.31%

updated 2026-10-09T15:31:37

1 posts

The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:05:45.000Z ##

Fix critical openPDC openHistorian vulnerabilities like CVE-2026-100730 and CVE-2026-105281. CISA urges patching these severe RCE flaws immediately.

#openPDC #openHistorian #CyberSecurity #Vulnerability #CISA

securityonline.info/openpdc-op

##

CVE-2026-28745
(7.5 HIGH)

EPSS: 0.22%

updated 2026-10-09T15:31:35

1 posts

Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.

thehackerwire@mastodon.social at 2026-10-09T22:01:33.000Z ##

🟠 CVE-2026-28745 - High (7.5)

Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39453
(8.3 HIGH)

EPSS: 0.29%

updated 2026-10-09T15:31:35

1 posts

Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.

thehackerwire@mastodon.social at 2026-10-09T21:01:10.000Z ##

🟠 CVE-2026-39453 - High (8.3)

Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-33367
(8.1 HIGH)

EPSS: 0.29%

updated 2026-10-09T15:31:35

1 posts

SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication.

thehackerwire@mastodon.social at 2026-10-09T21:01:01.000Z ##

🟠 CVE-2026-33367 - High (8.1)

SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108107
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-10-09T15:31:34

1 posts

PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection.

thehackerwire@mastodon.social at 2026-10-09T22:17:18.000Z ##

🔴 CVE-2026-108107 - Critical (9.8)

PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid par...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108109
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-10-09T15:31:34

1 posts

PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.

thehackerwire@mastodon.social at 2026-10-09T22:16:59.000Z ##

🔴 CVE-2026-108109 - Critical (9.1)

PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer us...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83943
(8.7 HIGH)

EPSS: 0.38%

updated 2026-10-09T15:31:32

1 posts

Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose information over a network.

CVE-2026-86405
(9.8 CRITICAL)

EPSS: 0.20%

updated 2026-10-09T15:31:30

1 posts

Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module allows Signature Spoofing by Improper Validation. This issue affects PrestaShop Virtual POS Module: from 26.8.1 before 26.9.1.

offseq@infosec.exchange at 2026-10-09T13:30:29.000Z ##

CVE-2026-86405 (CRITICAL, CVSS 9.8) in Sipay PrestaShop Virtual POS Module (26.8.1 – 26.9.1): Improper cryptographic signature checks allow spoofing & data tampering. Patch not confirmed — monitor vendor. radar.offseq.com/threat/cve-20 #OffSeq #CVE #vuln #cybersecurity

##

CVE-2026-107406(CVSS UNKNOWN)

EPSS: 0.47%

updated 2026-10-09T15:31:27

9 posts

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:   * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37

3 repos

https://github.com/ApexBreach/CVE-2026-107406-Poc

https://github.com/techupdate24/citrix-netscaler-rce-cve-2026-107406

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

jbhall56@infosec.exchange at 2026-10-09T14:40:50.000Z ##

CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. theregister.com/security/2026/

##

guru@thecybersecguru.com at 2026-10-09T09:41:43.000Z ##

Citrix Patches Critical NetScaler Memory Overflow Flaw (CVSS 9.5) That Enables Remote Code Execution in SAML Deployments

Citrix patches CVE-2026-107406, a critical NetScaler memory overflow flaw rated CVSS 9.5 that can enable remote code execution or denial of service

thecybersecguru.com/uncategori

##

tugatech@masto.pt at 2026-10-09T09:33:45.000Z ##

Citrix emitiu um aviso urgente para corrigir uma vulnerabilidade crítica nas soluções de rede NetScaler ADC e plataformas de acesso remoto NetScaler Gateway. A falha, identificada como CVE-2026-107406, permite a execução remota de código arbitrário ou negação de serviço. 🚨

🔗 tugatech.com.pt/t92412-citrix-

#alerta #falha 

##

cyberworldops@infosec.exchange at 2026-10-09T09:20:27.000Z ##

Citrix NetScaler instances with SAML enabled are affected by CVE-2026-107406, which can cause remote code execution and crash. Exposed ADC and Gateway systems risk takeover or service disruption, so patching and log review for malicious SAML requests is critical. #NetScaler #Citrix #PatchManagement

cyberworldops.eu/en/netscaler-

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T01:39:17.000Z ##

Critical Citrix NetScaler vulnerability CVE-2026-107406 (CVSS 9.5) can lead to RCE on SAML-configured ADC and Gateway. Upgrade now.

#Citrix #NetScaler #NetScalerGateway #CVE2026107406 #SAML #RCE #PatchNow #Vulnerability

securityonline.info/citrix-net

##

ssvc@infosec.exchange at 2026-10-08T23:55:22.000Z ##

I thought it was a Sunday because Citrix posted another yet another NetScaler security advisory:

CVE-2026-107406 (9.5 critical) pre-auth memory overflow > RCE or DoS

As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.

support.citrix.com/external/ar
community.citrix.com/techzone-

#citrix #netscaler #cve

##

GossiTheDog@cyberplace.social at 2026-10-08T22:07:42.000Z ##

There’s yet another Citrix Netscaler vuln (new patch today) which allows unauth RCE - CVE-2026-107406

Same attack surface (SAML) as two of the other vulns exploited in the wild during the past month.

##

Creek__@cyberplace.social at 2026-10-08T21:09:21.000Z ##

@GossiTheDog community.citrix.com/techzone-

They did it again :D

##

ifin@infosec.exchange at 2026-10-08T21:09:58.000Z ##

I'm tired, boss.

A new #Citrix CVE affecting SAML IdP/SP-configured devices is out.

ifin.network/t/cve-2026-107406

#ThreatIntel #ThreatIntelligence #IFIN

##

CVE-2026-94503
(10.0 CRITICAL)

EPSS: 0.28%

updated 2026-10-09T12:31:48

1 posts

Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7.

1 repos

https://github.com/Wayang1337/CVE-2026-94503

offseq@infosec.exchange at 2026-10-09T12:00:32.000Z ##

PX-lab Zombify ≤1.7.7 is affected by CVE-2026-94503 (CRITICAL, CVSS 10): unrestricted upload of dangerous files enables remote code execution. No patch yet — restrict uploads & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202694503 #WebSecurity #Infosec

##

CVE-2026-15762
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-10-09T04:18:09.937000

1 posts

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

CVE-2026-14497
(8.1 HIGH)

EPSS: 0.59%

updated 2026-10-09T04:18:05.817000

1 posts

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to bypass security restrictions due to improper verification of cryptographic signatures.

thehackerwire@mastodon.social at 2026-10-08T20:16:28.000Z ##

🟠 CVE-2026-14497 - High (8.1)

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to bypass security restrictions due to improper verification of cryptogr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69435
(9.6 CRITICAL)

EPSS: 0.39%

updated 2026-10-09T00:31:56

2 posts

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T07:30:24.000Z ##

CVE-2026-69435: CRITICAL SSRF (CVSS 9.6) in Microsoft Azure SRE Agent. Missing authorization controls let authorized attackers escalate privileges, risking confidentiality & integrity. Microsoft has issued a fix. radar.offseq.com/threat/cve-20 #OffSeq #Azure #SSRF #Infosec

##

CVE-2026-83947
(7.7 HIGH)

EPSS: 0.37%

updated 2026-10-09T00:31:56

1 posts

Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network.

CVE-2026-77900
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-10-09T00:31:56

2 posts

Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network.

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T04:30:25.000Z ##

Microsoft Azure App Service for Linux hit by CVE-2026-77900 (CRITICAL, CVSS 9.8): missing authentication enables unauthenticated remote code execution. Patch released — update now. radar.offseq.com/threat/cve-20 #OffSeq #Azure #CVE202677900 #Infosec #CloudSecurity

##

CVE-2026-88131
(9.8 CRITICAL)

EPSS: 0.84%

updated 2026-10-09T00:31:56

2 posts

Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T03:00:24.000Z ##

Microsoft Dataverse is affected by CVE-2026-88131 (CRITICAL, CVSS 9.8): deserialization of untrusted data allows unauthenticated RCE. Patch available — apply ASAP! radar.offseq.com/threat/cve-20 #OffSeq #CVE202688131 #Microsoft #RCE #Infosec

##

CVE-2026-84057
(8.1 HIGH)

EPSS: 0.36%

updated 2026-10-09T00:31:56

1 posts

IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-10-08T22:32:13.000Z ##

🟠 CVE-2026-84057 - High (8.1)

IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84035
(8.1 HIGH)

EPSS: 0.37%

updated 2026-10-09T00:31:56

1 posts

IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

thehackerwire@mastodon.social at 2026-10-08T22:32:04.000Z ##

🟠 CVE-2026-84035 - High (8.1)

IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84875
(7.5 HIGH)

EPSS: 0.42%

updated 2026-10-09T00:31:56

1 posts

IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

thehackerwire@mastodon.social at 2026-10-08T22:31:07.000Z ##

🟠 CVE-2026-84875 - High (7.5)

IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89091
(8.8 HIGH)

EPSS: 0.48%

updated 2026-10-09T00:31:56

1 posts

A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink di

thehackerwire@mastodon.social at 2026-10-08T22:30:49.000Z ##

🟠 CVE-2026-89091 - High (8.8)

A flaw was found in ansible-core. When installing a collection with
`ansible-galaxy collection install`, the archive extractor validates member
paths using lexical path normalisation (os.path.abspath) instead of resolving
symbolic links (os.path.r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107701
(8.2 HIGH)

EPSS: 0.33%

updated 2026-10-08T21:35:53.890000

1 posts

dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use __proto__ segments to inject properties into all objects, altering authorization flags and option defaults or crashing the process.

thehackerwire@mastodon.social at 2026-10-08T19:31:00.000Z ##

🟠 CVE-2026-107701 - High (8.2)

dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9209
(9.8 CRITICAL)

EPSS: 0.69%

updated 2026-10-08T21:35:53.890000

1 posts

mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attacke

1 repos

https://github.com/MS-0x404/CVE-2026-92099

thehackerwire@mastodon.social at 2026-10-08T17:32:03.000Z ##

🔴 CVE-2026-9209 - Critical (9.8)

mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19482
(8.8 HIGH)

EPSS: 0.42%

updated 2026-10-08T21:33:42

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of command arguments.

thehackerwire@mastodon.social at 2026-10-08T22:00:59.000Z ##

🟠 CVE-2026-19482 - High (8.8)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of command arguments.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19491
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-10-08T21:33:42

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authentication due to improper authentication.

thehackerwire@mastodon.social at 2026-10-08T21:46:00.000Z ##

🔴 CVE-2026-19491 - Critical (9.1)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authentication due to improper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19493
(7.5 HIGH)

EPSS: 0.36%

updated 2026-10-08T21:33:42

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.

thehackerwire@mastodon.social at 2026-10-08T21:46:09.000Z ##

🟠 CVE-2026-19493 - High (7.5)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78401
(9.8 CRITICAL)

EPSS: 0.57%

updated 2026-10-08T21:33:42

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

thehackerwire@mastodon.social at 2026-10-08T21:31:03.000Z ##

🔴 CVE-2026-78401 - Critical (9.8)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17189
(8.2 HIGH)

EPSS: 0.15%

updated 2026-10-08T21:33:41

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session

thehackerwire@mastodon.social at 2026-10-08T21:47:28.000Z ##

🟠 CVE-2026-17189 - High (8.2)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus alt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16916
(9.1 CRITICAL)

EPSS: 0.42%

updated 2026-10-08T21:33:41

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary code due to a protection mechanism failure.

thehackerwire@mastodon.social at 2026-10-08T21:47:19.000Z ##

🔴 CVE-2026-16916 - Critical (9.1)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary code due to a protection mechanism failure.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19494
(8.1 HIGH)

EPSS: 0.29%

updated 2026-10-08T21:33:41

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.

thehackerwire@mastodon.social at 2026-10-08T21:46:18.000Z ##

🟠 CVE-2026-19494 - High (8.1)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84275
(7.5 HIGH)

EPSS: 0.33%

updated 2026-10-08T21:33:34

1 posts

IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.

thehackerwire@mastodon.social at 2026-10-08T21:00:39.000Z ##

🟠 CVE-2026-84275 - High (7.5)

IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107704
(9.8 CRITICAL)

EPSS: 1.66%

updated 2026-10-08T21:33:34

1 posts

The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Attackers controlling the path, such as an uploaded file name, can append shell metacharacters like ';' that are executed via Ruby backticks with the Ruby pr

thehackerwire@mastodon.social at 2026-10-08T19:31:57.000Z ##

🔴 CVE-2026-107704 - Critical (9.8)

The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11318
(7.8 HIGH)

EPSS: 0.19%

updated 2026-10-08T21:33:33

1 posts

Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the

1 repos

https://github.com/Cr0wld3r/CVE-2026-11318

thehackerwire@mastodon.social at 2026-10-08T22:01:39.000Z ##

🟠 CVE-2026-11318 - High (7.8)

Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107703
(9.8 CRITICAL)

EPSS: 1.85%

updated 2026-10-08T21:33:33

1 posts

@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges.

thehackerwire@mastodon.social at 2026-10-08T19:31:48.000Z ##

🔴 CVE-2026-107703 - Critical (9.8)

@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107699
(9.8 CRITICAL)

EPSS: 1.47%

updated 2026-10-08T21:33:33

1 posts

ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges.

thehackerwire@mastodon.social at 2026-10-08T19:32:08.000Z ##

🔴 CVE-2026-107699 - Critical (9.8)

ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107700
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-10-08T21:33:33

1 posts

dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach constructor.constructor to load child_process and run operating system commands in the Node.js process.

thehackerwire@mastodon.social at 2026-10-08T19:30:51.000Z ##

🔴 CVE-2026-107700 - Critical (9.8)

dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107782
(7.8 HIGH)

EPSS: 0.11%

updated 2026-10-08T21:33:32

1 posts

System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM.

thehackerwire@mastodon.social at 2026-10-08T22:01:27.000Z ##

🟠 CVE-2026-107782 - High (7.8)

System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Micr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84244
(9.3 CRITICAL)

EPSS: 0.18%

updated 2026-10-08T21:33:28

1 posts

IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute malicious script in the browser of an authenticated Guardium user.

thehackerwire@mastodon.social at 2026-10-08T21:00:57.000Z ##

🔴 CVE-2026-84244 - Critical (9.3)

IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84276
(7.5 HIGH)

EPSS: 0.33%

updated 2026-10-08T21:33:26

1 posts

IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers an unchecked type assertion, causing the edge-controller process to terminate unexpectedly.

thehackerwire@mastodon.social at 2026-10-08T19:30:41.000Z ##

🟠 CVE-2026-84276 - High (7.5)

IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95210
(9.1 CRITICAL)

EPSS: 0.23%

updated 2026-10-08T21:33:23

1 posts

Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.

thehackerwire@mastodon.social at 2026-10-08T19:46:45.000Z ##

🔴 CVE-2026-95210 - Critical (9.1)

Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107779
(9.8 CRITICAL)

EPSS: 0.54%

updated 2026-10-08T21:27:15.010000

1 posts

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor ho

thehackerwire@mastodon.social at 2026-10-08T22:01:47.000Z ##

🔴 CVE-2026-107779 - Critical (9.8)

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107333
(8.1 HIGH)

EPSS: 0.98%

updated 2026-10-08T21:03:43.847000

1 posts

Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially formatted request path to bypass role-based restrictions and reach administrative or role gated endpoints they should not have access to. This affects all res

thehackerwire@mastodon.social at 2026-10-08T18:46:18.000Z ##

🟠 CVE-2026-107333 - High (8.1)

Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially forma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107383
(7.5 HIGH)

EPSS: 0.39%

updated 2026-10-08T20:25:00.647000

1 posts

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop sk

thehackerwire@mastodon.social at 2026-10-08T19:45:45.000Z ##

🟠 CVE-2026-107383 - High (7.5)

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation fro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107322
(7.8 HIGH)

EPSS: 0.13%

updated 2026-10-08T20:17:31.590000

1 posts

An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted database command value introduced in the agent context. To remediate this issue, users should upgrade to databases-on-aws plugin version 1.7.1 or later a

thehackerwire@mastodon.social at 2026-10-08T19:46:37.000Z ##

🟠 CVE-2026-107322 - High (7.8)

An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted dat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76463
(8.8 HIGH)

EPSS: 0.14%

updated 2026-10-08T20:08:45.857000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76463 are related to improper access control issues that are group

AAKL@infosec.exchange at 2026-10-08T15:52:31.000Z ##

Two more Cisco advisories today addressing critical vulnerabilities:

- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability

##

CVE-2026-107384
(8.1 HIGH)

EPSS: 0.45%

updated 2026-10-08T19:42:25

1 posts

### Description With the non-default permitSetMultiParamEntries option enabled, an object passed as a query parameter is expanded into a SET clause, each key becoming a column name. The three code paths implementing that expansion built the backtick-quoted identifier by hand and wrote the key out unescaped, while only the value was escaped. A key containing a backtick therefore closed the identif

thehackerwire@mastodon.social at 2026-10-08T19:45:55.000Z ##

🟠 CVE-2026-107384 - High (8.1)

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2015-5477
(7.5 HIGH)

EPSS: 99.41%

updated 2026-10-08T18:32:53

2 posts

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

8 repos

https://github.com/likekabin/ShareDoc_cve-2015-5477

https://github.com/elceef/tkeypoc

https://github.com/robertdavidgraham/cve-2015-5477

https://github.com/knqyf263/cve-2015-5477

https://github.com/tintinweb/pub

https://github.com/ilanyu/cve-2015-5477

https://github.com/xycloops123/TKEY-remote-DoS-vulnerability-exploit

https://github.com/hmlio/vaas-cve-2015-5477

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:00:57.000Z ##

CVE ID: CVE-2015-5477
Vendor: ISC
Product: BIND
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2021-3199
(9.8 CRITICAL)

EPSS: 19.35%

updated 2026-10-08T18:32:52

2 posts

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:01:44.000Z ##

CVE ID: CVE-2021-3199
Vendor: ONLYOFFICE
Product: Docs
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-104078
(7.8 HIGH)

EPSS: 0.29%

updated 2026-10-08T18:32:32

1 posts

Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formul

thehackerwire@mastodon.social at 2026-10-08T17:31:54.000Z ##

🟠 CVE-2026-104078 - High (7.8)

Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterU...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104077
(7.8 HIGH)

EPSS: 0.35%

updated 2026-10-08T18:32:31

1 posts

Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because No

thehackerwire@mastodon.social at 2026-10-08T17:31:44.000Z ##

🟠 CVE-2026-104077 - High (7.8)

Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107377
(7.5 HIGH)

EPSS: 0.45%

updated 2026-10-08T17:58:02

1 posts

## Summary When processing an attacker-controlled Protobuf schema, vulnerable versions of `datamodel-code-generator` could write a generated weak-import stub outside the intended `__weak_imports__` temporary directory. Absolute import paths and relative paths containing `..` could escape this directory. An attacker could create directories and new files at locations writable by the process. Rela

thehackerwire@mastodon.social at 2026-10-08T18:30:33.000Z ##

🟠 CVE-2026-107377 - High (7.5)

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_mi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107303
(7.6 HIGH)

EPSS: 0.26%

updated 2026-10-08T17:40:32

1 posts

## Summary Applications generated by generator-jhipster v9.2.0 can persist user-controlled Blob ContentType values and later use those values as the MIME type for client-side Blob objects. The shared generated `openFile` helper creates an object URL from the Blob and opens it in a new window. For Blob-bearing entities writable by normal authenticated users, this creates a stored XSS chain: attack

thehackerwire@mastodon.social at 2026-10-08T18:46:09.000Z ##

🟠 CVE-2026-107303 - High (7.6)

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107302
(7.5 HIGH)

EPSS: 0.43%

updated 2026-10-08T17:40:11

1 posts

### Impact A truncated `map32` header causes an out-of-bounds buffer read and throws `RangeError` instead of `IncompleteBufferError`. Applications that rely on `IncompleteBufferError` to wait for additional bytes may terminate a request, stream, or worker unexpectedly. No adjacent memory is disclosed because the buffer implementation checks bounds. ### Patches The decoder now validates the comp

thehackerwire@mastodon.social at 2026-10-08T18:46:00.000Z ##

🟠 CVE-2026-107302 - High (7.5)

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore caus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107300
(7.5 HIGH)

EPSS: 0.43%

updated 2026-10-08T17:40:07

1 posts

### Impact The streaming decoder recursively invokes itself for every complete value remaining in a chunk. A single chunk containing many small valid MessagePack values can exhaust the JavaScript call stack and interrupt the process or stream. ### Patches The streaming decoder now drains concatenated values iteratively with constant call-stack depth. ### Workarounds Limit the number of Messag

thehackerwire@mastodon.social at 2026-10-08T17:30:20.000Z ##

🟠 CVE-2026-107300 - High (7.5)

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107295
(7.6 HIGH)

EPSS: 0.16%

updated 2026-10-08T17:16:37

1 posts

### Summary The Pydantic AI development web chat UI (`Agent.to_web()`, `clai web`) did not check the content type of requests to its chat endpoint. This allowed a website visited by a developer to submit a request to a chat UI running on that developer's machine, causing the served agent to run and to execute its tools with the privileges and credentials of the local process. Binding the web UI

thehackerwire@mastodon.social at 2026-10-08T17:30:30.000Z ##

🟠 CVE-2026-107295 - High (7.6)

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A webs...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93017
(7.7 HIGH)

EPSS: 0.21%

updated 2026-10-08T15:33:15

1 posts

The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster. Ref: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373 ``` - apiGroups:

thehackerwire@mastodon.social at 2026-10-08T19:46:54.000Z ##

🟠 CVE-2026-93017 - High (7.7)

The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.

...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14992
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-08T15:33:11

1 posts

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.

thehackerwire@mastodon.social at 2026-10-08T20:16:18.000Z ##

🔴 CVE-2026-14992 - Critical (9.8)

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14502
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-10-08T15:33:10

1 posts

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP authentication.

thehackerwire@mastodon.social at 2026-10-08T20:16:38.000Z ##

🔴 CVE-2026-14502 - Critical (9.8)

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16340
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-10-08T15:33:05

1 posts

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word parser.

CVE-2026-102255
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-10-07T18:33:12

4 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

oversecurity@mastodon.social at 2026-10-09T13:51:04.000Z ##

Max severity SonicWall SMA1000 flaw now exploited in attacks

Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days...

🔗️ [Bleepingcomputer] link.is.it/pvDc7j

##

jbhall56@infosec.exchange at 2026-10-09T13:41:19.000Z ##

Tracked as CVE-2026-102255, the flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, but does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. bleepingcomputer.com/news/secu

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T10:55:44.000Z ##

Attackers target a critical SonicWall SMA1000 vulnerability in the wild. Apply vendor hotfixes to secure remote access gateways against CVE-2026-102255.

#SonicWall #CVE2026102255 #CyberSecurity #InfoSec #SSRF

securityonline.info/sonicwall-

##

beyondmachines1@infosec.exchange at 2026-10-08T14:01:49.000Z ##

SonicWall Patches Critical Pre-Auth SSRF in SMA 1000 Series Appliances

SonicWall patched four vulnerabilities in its SMA 1000 series appliances, including a critical pre-authentication SSRF (CVE-2026-102255) with a CVSS score of 10.0. The flaws allow unauthenticated attackers to access internal services and authenticated users to execute arbitrary code.

**If you use SonicWall SMA 1000 series appliances (SMA 6210, SMA 7210 or SMA 8200v), update them ASAP to firmware 12.4.3-03670 or 12.5.0-03082 or newer. Make sure the management console is reachable only from trusted internal networks, and check the appliance logs for unusual activity, since these gateways are a favorite entry point for ransomware groups.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-76471
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-10-07T18:32:21

1 posts

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.&nbsp; The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP req

AAKL@infosec.exchange at 2026-10-08T15:52:31.000Z ##

Two more Cisco advisories today addressing critical vulnerabilities:

- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability

##

CVE-2026-76467
(7.5 HIGH)

EPSS: 0.25%

updated 2026-10-07T18:32:20

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76467 are related to issues concerning improper control of a resourc

AAKL@infosec.exchange at 2026-10-08T15:52:31.000Z ##

Two more Cisco advisories today addressing critical vulnerabilities:

- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability

##

CVE-2026-76464
(9.6 CRITICAL)

EPSS: 0.19%

updated 2026-10-07T18:32:20

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by this CVE-2026-76464 are related to buffer management issues that are grouped

AAKL@infosec.exchange at 2026-10-08T15:52:31.000Z ##

Two more Cisco advisories today addressing critical vulnerabilities:

- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability sec.cloudapps.cisco.com/securi

- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #Cisco #vulnerability

##

CVE-2026-20362
(7.2 HIGH)

EPSS: 0.47%

updated 2026-10-07T18:32:14

1 posts

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful

sans_isc@infosec.exchange at 2026-10-09T07:55:30.000Z ##

SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)
isc.sans.edu/podcastdetail/101

##

CVE-2026-107181
(8.1 HIGH)

EPSS: 0.34%

updated 2026-10-07T15:32:07

7 posts

Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.

1 repos

https://github.com/SeanDishman/telegram-cve-2026-107181

raul@mastodon.in4matics.cat at 2026-10-10T07:33:37.000Z ##

⚠️ Un clic en un enllaç extern podia acabar amb el segrest de Telegram Desktop: una fallada IPC permetia llegir i exfiltrar fitxers locals. CVE-2026-107181; corregida a 7.2.9. Actualitza. #Telegram #Ciberseguretat beaksec.github.io/posts/telegr

##

thecybersecguru@mastox.eu at 2026-10-10T06:16:05.000Z ##

🚨 TELEGRAM DESKTOP: ONE CLICK. FULL ACCOUNT TAKEOVER.

Full technical breakdown 👉 thecybersecguru.com/exploits/t

A critical flaw, CVE-2026-107181, reportedly chains IPC injection with local session file theft to let attackers hijack Telegram accounts through a malicious link.

⚠️ No traditional malware installer. Just one click.

🔴 IPC command injection
🔴 Local file theft
🔴 Session hijacking
🔴 Account takeover

The article reports that Telegram Desktop 7.2.9 fixes the flaw. Update now, set a local passcode, and review auto-download settings.

#CyberSecurity #Telegram #CVE

CC @durov

##

guru@thecybersecguru.com at 2026-10-10T06:08:29.000Z ##

Critical Telegram Desktop Vulnerability (CVE-2026-107181): A Technical Analysis of One-Click Account Takeover via IPC Injection

Telegram Desktop CVE-2026-107181 enables one-click account takeover through IPC injection and local session file theft. Learn how it works and how to protect your account

thecybersecguru.com/exploits/t

##

raul@mastodon.in4matics.cat at 2026-10-10T07:33:37.000Z ##

⚠️ Un clic en un enllaç extern podia acabar amb el segrest de Telegram Desktop: una fallada IPC permetia llegir i exfiltrar fitxers locals. CVE-2026-107181; corregida a 7.2.9. Actualitza. #Telegram #Ciberseguretat beaksec.github.io/posts/telegr

##

guru@thecybersecguru.com at 2026-10-10T06:08:29.000Z ##

Critical Telegram Desktop Vulnerability (CVE-2026-107181): A Technical Analysis of One-Click Account Takeover via IPC Injection

Telegram Desktop CVE-2026-107181 enables one-click account takeover through IPC injection and local session file theft. Learn how it works and how to protect your account

thecybersecguru.com/exploits/t

##

DarkWebInformer@infosec.exchange at 2026-10-09T21:10:20.000Z ##

🚨 PoC released for Telegram Desktop account takeover vulnerability; CVE-2026-107181

beaksec.github.io/posts/telegr

A vulnerability in Telegram Desktop allows attackers to steal local files, including session keys, by tricking users into opening a specially crafted tg:// link.

Stolen session data could allow attackers to hijack Telegram accounts without knowing the victim's password.

CVSS: 8.1 (High, v3.1) / 8.6 (High, v4.0)
Affected: Telegram Desktop before 7.2.9
Fixed: Version 7.2.9

The published PoC demonstrates how a malicious link can trigger file exfiltration through Telegram's IPC handler.

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T02:09:46.000Z ##

A critical Telegram Desktop account takeover vulnerability (CVE-2026-107181) exposes users to session hijacking. Exploit details and PoC are now public.

#Telegram #Cybersecurity #CVE2026107181 #AccountTakeover #PoC

securityonline.info/telegram-d

##

CVE-2026-21589
(0 None)

EPSS: 1.77%

updated 2026-10-07T13:17:22.273000

4 posts

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledg

Nuclei template

12 repos

https://github.com/gotr00t0day/CVE-2026-21589

https://github.com/BimBoxH4/CVE-2026-21589

https://github.com/murrez/CVE-2026-21589

https://github.com/webserverdude/f5_CVE-2026-21589_mitigation

https://github.com/rxsklife/CVE-2026-21589

https://github.com/renzi25031469/CVE-2026-21589

https://github.com/MarcusProgram/CVE-2026-21589

https://github.com/tc4dy/CVE-2026-21589-PoC-Exploit

https://github.com/aduli198/CVE-2026-21589

https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589

https://github.com/0xBlackash/CVE-2026-21589

https://github.com/ynsmroztas/AtlasSniper

DailyCyberSecurity@infosec.exchange at 2026-10-09T12:56:36.000Z ##

Hackers rapidly exploit the Atlassian vulnerability CVE-2026-21589. Learn how this critical flaw compromises Jira, Confluence, and Bitbucket security.

#Atlassian #CVE202621589 #CyberSecurity #Jira #TechNews

meterpreter.org/atlassian-cve-

##

patrickcmiller@infosec.exchange at 2026-10-09T03:12:00.000Z ##

You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) labs.watchtowr.com/you-wont-he

##

linuxmint_hun@mastodon.social at 2026-10-08T17:13:07.000Z ##

CVE-2026-21589 kritikus arbitrary file access hiba érinti több Atlassian Data Center terméket (Jira, Confluence, Bitbucket) és bejelentkezés nélkül hozzáférhetők lehetnek fájlok. Van internetre kitett példányod, ami veszélyben lehet, aggódsz? A végleges megoldás a frissítés; ideiglenes WAF/Tomcat RewriteValve mitigációk lehetségesek.

linuxmint.hu/hir/2026/10/kriti

#Atlassian #CVE202621589 #Jira #Confluence #Bitbucket #DataCenter #WAF #Tomcat #kiberbiztonság #infosec

##

jschauma@mstdn.social at 2026-10-08T16:58:05.000Z ##

Oh, Atlassian, never change! 😭

"CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products"

CVSS Score 9.3, so, you know, you better "Test that your rule blocks .. immediately adjacent to /".

APT /../../../../../../etc/passwd strikes again.

confluence.atlassian.com/secur

##

CVE-2026-105192
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-10-07T12:31:58

1 posts

LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER mes

1 repos

https://github.com/rxsklife/CVE-2026-105192

DailyCyberSecurity@infosec.exchange at 2026-10-09T11:54:44.000Z ##

Explore the critical LMCache vulnerability CVE-2026-105192. Learn how insecure ZeroMQ configurations and Python pickle deserialization lead to RCE attacks.

#LMCache #CVE2026105192 #CyberSecurity #TechNews #ZeroMQ

meterpreter.org/critical-lmcac

##

CVE-2025-64393(CVSS UNKNOWN)

EPSS: 0.36%

updated 2026-10-07T09:32:29

2 posts

This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.

security_crawler_carl@infosec.exchange at 2026-10-09T09:22:31.000Z ##

🏆 New Achievement! The Keys to the Vault Were Under the Mat!

Magnificent. Truly, someone looked at a backup server — the one room that holds the skeleton keys to your entire infrastructure — and said, let's let low-privileged users knock it over. CVE-2025-64393 is a critical remote code execution flaw in Veeam Backup & Replication version 12, and it hands full control of the backup server to anyone with the Backup Viewer role. (1/3)

##

beyondmachines1@infosec.exchange at 2026-10-09T09:01:49.000Z ##

Veeam Patches Critical Remote Code Execution Flaw in Backup & Replication Software

Veeam patched four vulnerabilities in Backup & Replication version 12, including a critical RCE flaw (CVE-2025-64393) that allows low-privileged users to take control of the backup server.

**If you use Veeam Backup & Replication version 12, update ASAP to 12.3.2 P4 (build 12.3.2.4934). Review and remove the Backup Viewer role from anyone who doesn't really need it, and keep your backup servers isolated from the rest of the network.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-59346
(9.3 CRITICAL)

EPSS: 0.26%

updated 2026-10-07T06:33:08

2 posts

VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)

1 repos

https://github.com/0xCyberstan/CVE-2026-59346-POC

threatcodex@infosec.exchange at 2026-10-09T17:21:50.000Z ##

CVE-2026-59346: Critical VMware Workstation and Fusion Flaw Enables Guest-to-Host Code Execution
#CVE_2026_59346
socprime.com/blog/cve-2026-593

##

guru@thecybersecguru.com at 2026-10-08T18:05:42.000Z ##

PoC Released for Critical VMware VMXNET3 Integer Overflow Flaw Enabling Guest-to-Host Code Execution (CVE-2026-59346)

CVE-2026-59346 affects VMware VMXNET3 and enables guest-to-host memory corruption. A public PoC crashes vmware-vmx. Patch Workstation and Fusion now

thecybersecguru.com/exploits/c

##

CVE-2026-79820
(9.0 CRITICAL)

EPSS: 0.27%

updated 2026-10-06T15:15:48.310000

1 posts

A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.

CVE-2026-105134
(10.0 CRITICAL)

EPSS: 1.84%

updated 2026-10-06T15:04:52.637000

5 posts

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve

1 repos

https://github.com/RayanAlmulhim/CVE-2026-105134-lab

threatnoir at 2026-10-10T09:06:30.426Z ##

⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-10-10T09:06:30.000Z ##

⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

cyberworldops@infosec.exchange at 2026-10-09T18:40:07.000Z ##

Huntress reports active exploitation of AhsayCBS CVE-2026-105133 and CVE-2026-105134 chained for auth bypass and OS command execution. Attackers deploy web shells and XMRig miners, gaining persistence on backup servers. Patch and hunt for indicators. #AhsayCBS #ThreatIntel #InfoSec

cyberworldops.eu/en/huntress-a

##

ssvc@infosec.exchange at 2026-10-09T14:55:27.000Z ##

Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:

Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.

huntress.com/blog/ahsaycbs-fla

#threatintel #ahsayCBS #CVE #eitw #IOC

##

beyondmachines1@infosec.exchange at 2026-10-09T11:01:49.000Z ##

Threat Actors Chain AhsayCBS Vulnerabilities to Deploy Webshells and Cryptominers

Threat actors are chaining two vulnerabilities in AhsayCBS (CVE-2026-105133 and CVE-2026-105134) to bypass authentication and gain remote code execution on backup servers.

**If you run AhsayCBS (any version up to and including 10.3.4), be aware it's actively exploited with no patch available. Immediately make sure that the management console is off the internet and allow access only from trusted IPs or over VPN. Then check for signs of compromise, such as unusual processes started by cbssvcX64.exe. If you find any, fully re-image the server from a clean backup.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-105133
(7.3 HIGH)

EPSS: 0.38%

updated 2026-10-04T09:30:21

5 posts

A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate thi

threatnoir at 2026-10-10T09:06:30.426Z ##

⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-10-10T09:06:30.000Z ##

⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

cyberworldops@infosec.exchange at 2026-10-09T18:40:07.000Z ##

Huntress reports active exploitation of AhsayCBS CVE-2026-105133 and CVE-2026-105134 chained for auth bypass and OS command execution. Attackers deploy web shells and XMRig miners, gaining persistence on backup servers. Patch and hunt for indicators. #AhsayCBS #ThreatIntel #InfoSec

cyberworldops.eu/en/huntress-a

##

ssvc@infosec.exchange at 2026-10-09T14:55:27.000Z ##

Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:

Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.

huntress.com/blog/ahsaycbs-fla

#threatintel #ahsayCBS #CVE #eitw #IOC

##

beyondmachines1@infosec.exchange at 2026-10-09T11:01:49.000Z ##

Threat Actors Chain AhsayCBS Vulnerabilities to Deploy Webshells and Cryptominers

Threat actors are chaining two vulnerabilities in AhsayCBS (CVE-2026-105133 and CVE-2026-105134) to bypass authentication and gain remote code execution on backup servers.

**If you run AhsayCBS (any version up to and including 10.3.4), be aware it's actively exploited with no patch available. Immediately make sure that the management console is off the internet and allow access only from trusted IPs or over VPN. Then check for signs of compromise, such as unusual processes started by cbssvcX64.exe. If you find any, fully re-image the server from a clean backup.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-88467
(6.2 MEDIUM)

EPSS: 0.12%

updated 2026-10-01T18:33:43

1 posts

CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information.

hugovalters@mastodon.social at 2026-10-10T12:30:03.000Z ##

CVE-2026-88467: CRMEB Knowledge-Paid System 1.4.4 leaks sensitive info via a backend verification flaw. CVSS 6.2, no patch yet. Restrict access and monitor. Details: valtersit.com/cve/CVE-2026-884 #CVE #infosec #CRMEB

##

CVE-2026-48710
(6.5 MEDIUM)

EPSS: 7.06%

updated 2026-10-01T18:17:18.153000

1 posts

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and e

Nuclei template

5 repos

https://github.com/eris-ths/supply-chain-guard

https://github.com/xtremebeing/starlette-host-header-lab

https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace

https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit

https://github.com/CuteeCat/CVE-2026-48710

x41sec@infosec.exchange at 2026-10-09T14:05:54.000Z ##

We have published our writeup about the discovery and details of the #BadHost vulnerability (CVE-2026-48710) at x41-dsec.de/lab/research/2026/

##

CVE-2026-46649
(0 None)

EPSS: 0.50%

updated 2026-09-28T21:17:17.733000

1 posts

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker who targets a user during an active SSO login can make unlimited guesses, and a cor

hugovalters@mastodon.social at 2026-10-10T17:10:02.000Z ##

CVE-2026-46649: Joplin Server pre-3.7.2 SSO code endpoint skips brute-force limits, letting unauthenticated attackers guess 9-digit codes and steal session tokens for full note access. CVSS 9.1. Patch under review - restrict valtersit.com/cve/CVE-2026-466 #CVE #infosec #Joplin

##

linuxmint_hun@mastodon.social at 2026-10-10T17:32:06.000Z ##

Riasztás: kritikus, aktívan kihasznált CVE-2026-88771 és CVE-2026-88772 sebezhetőségek érintik a NetScaler ADC/Gateway eszközöket. Telepítetted már az ajánlott javításokat, és gondoltál rá, hogy korábbi kompromittálódás miatt vizsgálatot indíts? A cikkben megtalálod a frissített kiadásokat és a javasolt teendőket.

linuxmint.hu/hir/2026/10/riasz

#NetScaler #NetScalerADC #NetScalerGateway #CVE2026-88771 #CVE2026-88772 #Citrix #kiberbiztonság #patch #frissítés #CISA #VPN

##

bontchev@infosec.exchange at 2026-10-09T05:37:07.000Z ##

@GossiTheDog Meanwhile I've updated my Citrix honeypot to handle CVE-2026-88771 - but so far have seen absolutely no attacks. I'll run some tests later today to check if it doesn't miss them due to some kind of bug.

Visualization (empty so far):

pandora.nlcv.bas.bg/grafana/d/

##

GossiTheDog@cyberplace.social at 2026-10-08T16:55:50.000Z ##

Watchtowr have a good look at pray and spray #PitScaler exploitation. This isn’t the initial exploitation - their timeline should expand back to September 4th for that.

Also they make a good point re the latest SAML bug - by using it to DoS, it causes attacker commands in the logs to process immediately post reboot with PitScaler vuln. Not covered in blog: Attackers are actually doing this, they’re preloading the logs using the username field for failed logins.

watchtowr.com/intelligence/pos

##

CVE-2026-88772
(8.1 HIGH)

EPSS: 1.30%

updated 2026-09-28T12:26:47.670000

1 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

8 repos

https://github.com/murrez/CVE-2026-88772

https://github.com/FollowerSeize/CVE-2026-88772-POC

https://github.com/technion/netscaler_scanner

https://github.com/orjanj/netscaler_threat_hunt_helper

https://github.com/emilstahl/pitscaler

https://github.com/securekomodo/citrixInspector

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

linuxmint_hun@mastodon.social at 2026-10-10T17:32:06.000Z ##

Riasztás: kritikus, aktívan kihasznált CVE-2026-88771 és CVE-2026-88772 sebezhetőségek érintik a NetScaler ADC/Gateway eszközöket. Telepítetted már az ajánlott javításokat, és gondoltál rá, hogy korábbi kompromittálódás miatt vizsgálatot indíts? A cikkben megtalálod a frissített kiadásokat és a javasolt teendőket.

linuxmint.hu/hir/2026/10/riasz

#NetScaler #NetScalerADC #NetScalerGateway #CVE2026-88771 #CVE2026-88772 #Citrix #kiberbiztonság #patch #frissítés #CISA #VPN

##

CVE-2026-82077(CVSS UNKNOWN)

EPSS: 0.74%

updated 2026-09-24T09:32:00

3 posts

An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.

CVE-2026-88404
(9.8 CRITICAL)

EPSS: 0.75%

updated 2026-09-22T15:33:37

1 posts

A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

hugovalters@mastodon.social at 2026-10-10T11:00:15.000Z ##

CVE-2026-88404: RCE in Univer v1.0.0-alpha.2 via UniscriptExecutionService.execute(). CVSS 9.8, unpatched. Patch now.
valtersit.com/cve/CVE-2026-884
#CVE #infosec #cybersecurity

##

CVE-2026-88402
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-09-22T15:33:36

1 posts

A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.

hugovalters@mastodon.social at 2026-10-10T14:10:23.000Z ##

CVE-2026-88402 NocoBase v2.1.21 SQL injection in checkSQL, CVSS 9.8, unpatched. Crafted SQL exposes sensitive database data. Patch status unknown, so restrict exposure now. valtersit.com/cve/CVE-2026-884 #CVE #infosec

##

CVE-2026-61647(CVSS UNKNOWN)

EPSS: 0.32%

updated 2026-09-22T14:43:27

1 posts

## Summary The `vault_batch` MCP tool (and the equivalent `POST /batch-to-vault` HTTP endpoint) accepted a caller-supplied `vault_dir` path that was passed directly to `path.resolve()` + `fs.mkdir()` with no containment check. A caller — or a prompt-injected LLM driving the MCP — could therefore create directories and write `.md` / `.json` answer files anywhere the server process can write. The

hugovalters@mastodon.social at 2026-10-10T15:40:32.000Z ##

CVE-2026-61647: Path traversal in NotebookLM MCP 1.6.0-2.0.2 lets attacker-controlled vault_dir write files anywhere on disk via POST /batch-to-vault. CVSS 9.1. Patch under review, so restrict endpoint access now. valtersit.com/cve/CVE-2026-616 #CVE #infosec #cybersecurity

##

CVE-2026-94571(CVSS UNKNOWN)

EPSS: 0.53%

updated 2026-09-21T21:32:01

1 posts

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, and thus newlines passed structural checks, but Octavia stored and wrote the raw unencoded value directly into the HAProxy configuration generated on the amphora.

hugovalters@mastodon.social at 2026-10-10T09:20:19.000Z ##

CVE-2026-94571: OpenStack Octavia before 18.0.1 lets an authenticated load balancer owner inject newlines via redirect_url, writing arbitrary HAProxy directives on the amphora. CVSS 8.8. Patch under review. Track it: valtersit.com/cve/CVE-2026-945 #CVE #infosec #OpenStack

##

CVE-2026-92382
(4.1 MEDIUM)

EPSS: 0.14%

updated 2026-09-21T18:32:14

1 posts

An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() and allowing a usbredir peer to write past the end of the packet descriptor array on every subsequent isochronous packet.

hugovalters@mastodon.social at 2026-10-10T07:50:02.000Z ##

CVE-2026-92382: OOB write in usbredir. A peer can write past the packet descriptor array. CVSS 4.1, no patch yet. Audit your usbredir exposure now.
valtersit.com/cve/CVE-2026-923
#CVE #infosec #cybersecurity

##

CVE-2026-87491
(8.8 HIGH)

EPSS: 3.14%

updated 2026-09-21T13:17:11.283000

1 posts

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

2 repos

https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter

https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.

CVE-2026-93485
(7.1 HIGH)

EPSS: 0.38%

updated 2026-09-18T06:32:17

1 posts

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.1

4 repos

https://github.com/686f6c61/POC-WP-CORE-CVE-2026-93485

https://github.com/DeathShotXD/Comment2Shell

https://github.com/HORKimhab/CVE-2026-93485

https://github.com/0xBlackash/CVE-2026-93485

sekurakbot@mastodon.com.pl at 2026-10-09T07:35:00.000Z ##

Ataki na strony WordPress chwilę po wydaniu poprawki

17 września 2026 r. WordPress wydał wersję 7.1.1, w której załatano dwie podatności – kojarzone jako Click2Shell i Comment2Shell (CVE-2026-93485). To jednak dopiero początek historii. Kilka dni później – 22 września – wydano wersję 7.1.2 łatającą kolejną podatność. Atakujący nie czekali jednak na publikację jej szczegółów – wszystko wskazuje na...

#WBiegu #Podatność #Rce #Wordpress

sekurak.pl/ataki-na-strony-wor

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 63.53%

updated 2026-09-14T00:16:56.777000

3 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

CVE-2026-0310(CVSS UNKNOWN)

EPSS: 0.37%

updated 2026-09-10T06:31:55

1 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

AAKL@infosec.exchange at 2026-10-09T16:15:10.000Z ##

Palo Alto has a a long list of advisories, addressing at least two critical vulnerabilities, among others: security.paloaltonetworks.com/

CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing security.paloaltonetworks.com/

CRITICAL: PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) security.paloaltonetworks.com/

- Tenable Research Advisories:

HIGH: Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion tenable.com/security/research/

There are also two WordPress vulnerabilities and a few others here tenable.com/security/research #WorPress

- Microsoft:

In case you missed this, Microsoft posted quite a few patches yesterday msrc.microsoft.com/update-guide #infosec #vulnerability #Microsofot #Azure #Linux

##

CVE-2026-80093
(7.0 None)

EPSS: 0.32%

updated 2026-09-09T00:31:34

1 posts

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

DailyCyberSecurity@infosec.exchange at 2026-10-09T13:15:49.000Z ##

Discover the details of the Windows Cloud Files Driver vulnerability, CVE-2026-80093. Learn how this flaw in cldflt.sys affects kernel privileges.

#WindowsSecurity #CVE202680093 #CyberSecurity #Microsoft #TechNews

meterpreter.org/windows-cloud-

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 3.44%

updated 2026-09-08T09:36:36

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

Nuclei template

100 repos

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/abdullaabdullazade/CVE-2026-31431

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/st4rburn/public-passwd

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/st4rburn/RootRemover

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/pedromizz/copy-fail

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/pyroceper/copy-fail-CVE-2026-31431

https://github.com/Smarttfoxx/copyfail

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/sudoytang/copyfail-arm64

https://github.com/tgies/copy-fail-c

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/badsectorlabs/copyfail-go

https://github.com/malwarekid/CVE-2026-31431

https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape

https://github.com/cyber-joker/copy-fail-python

https://github.com/wesmar/CVE-2026-31431

https://github.com/0xShe/CVE-2026-31431

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/cozystack/copy-fail-blocker

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/b5null/CVE-2026-31431-C

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/sgkdev/page_inject

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/xeloxa/copyfail-exploit

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/desultory/CVE-2026-31431

https://github.com/povzayd/CVE-2026-31431

https://github.com/samanzamani/copy-fail-checker

https://github.com/atgreen/block-copyfail

https://github.com/rootsecdev/cve_2026_31431

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/mrunalp/block-copyfail

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/TrevoCastles/CVE-2026-31431-copy-fail

https://github.com/cs8425/copy-fail-go

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/Qengineering/RK35xx-CopyFail-Hotfix

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/ZeroDayEvil/CVE-2026-31431

https://github.com/sammwyy/copyfail-rs

https://github.com/rvzsec/CVE-2026-31431

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/Boos4721/copyfail-rs

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/nisec-eric/cve-2026-31431

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/sgkdev/ptrace_may_dream

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/diemoeve/copyfail-rs

https://github.com/wgnet/wg.copyfail.patch

https://github.com/Huchangzhi/autorootlinux

https://github.com/luotian2/CVE-2026-31431

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/Juguitos/copy-fail

https://github.com/gagaltotal/cve-2026-31431-copy-fail

https://github.com/bootsareme/copyfail-deconstructed

kubesploit@learnk8s.news at 2026-10-09T18:46:02.000Z ##

This article examines why Copy Fail (CVE-2026-31431) breaks container assumptions and provides a small, safe Python check to determine whether your nodes can reach the vulnerable kernel path

➤ ku.bz/CTv-Yf60c

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 85.58%

updated 2026-08-31T21:31:56

3 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Nuclei template

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

CVE-2026-73570
(8.9 HIGH)

EPSS: 71.66%

updated 2026-08-21T18:34:48

1 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

Nuclei template

10 repos

https://github.com/dahnutz/zimbra-cve-2026-73570-ir

https://github.com/HORKimhab/CVE-2026-73570

https://github.com/alsyundawy/eradicate-zimbra-malware

https://github.com/gabrielunknown/CVE-2026-73570

https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules

https://github.com/BiuTrap/CVE-2026-73570

https://github.com/0xBlackash/CVE-2026-73570

https://github.com/jishino567/CVE-2026-73570

https://github.com/juanpoch/CVE-2026-73570

https://github.com/hainhc/CVE-2026-73570

hasamba@infosec.exchange at 2026-10-09T17:49:51.000Z ##

----------------

🎯 Threat Intelligence
===================

Microsoft Threat Intelligence tracks CVE-2026-73570: unauthenticated command injection on internet-facing Zimbra mail servers

Microsoft Threat Intelligence published an analysis of CVE-2026-73570, described as an unauthenticated command injection vulnerability exploited in Zimbra on internet-facing mail servers. The post documents observed attack paths, detection opportunities, and mitigation guidance. The digest available here is thin, so this write-up keeps what the source states separate from general class context and flags everything the digest does not state.

🔹 Executive Summary
• CVE-2026-73570 is an unauthenticated command injection vulnerability in Zimbra.
• Exploitation observed in the wild, per Microsoft Threat Intelligence.
• Exposure model: internet-facing mail servers, no authentication required.
• The same post carries detection opportunities and mitigation guidance.

🔹 Technical Details

What the source states:
• Vulnerability class: command injection
• Authentication: none (pre-auth)
• Exposure: internet-facing mail servers
• Affected product: Zimbra
• Publisher and date: Microsoft Threat Intelligence, September 30, roughly a 20-minute read

Not stated in the digest: affected versions, CVSS score, CWE mapping, specific IOCs, named actor, ATT&CK mappings. Treat all of that as unconfirmed until the full post is read.

🔹 Analysis

Class context, not a source claim: pre-auth command injection on an internet-facing mail server is close to the worst property combination a CVE can carry. No credential barrier, no user interaction, and the target sits on the public edge. Mail hosts also concentrate mailbox contents, credentials in authentication flows, and internal trust relationships, which makes a pre-auth path on the edge a practical pivot for follow-on activity. Zimbra has a history as a target of mass exploitation campaigns on earlier CVEs; that is general background relevant to prioritization, not a claim from the current post.

🔹 Attack Chain Analysis

Only the entry step is confirmed by the digest:

1. Initial Access: unauthenticated exploitation of CVE-2026-73570 against an internet-facing Zimbra instance.
2. Post-exploitation: the original post describes observed attack paths, but the digest does not enumerate stages beyond initial access. Do not assume a specific chain from this summary.

🔹 Detection

The source says the post includes detection opportunities, but the digest does not contain the actual queries. Reasonable starting hypotheses for a command injection scenario on a mail host: unexpected process spawns from mail service modules, unusual outbound connections originating from the mail server itself, and anomalous request patterns in web access logs aimed at service and admin endpoints. Treat these as hypotheses to validate against the full post, not verified signatures.

🔹 Mitigation
• The post publishes specific mitigation guidance, so apply it from the source directly.
• Interim hygiene: confirm patch status on every internet-facing Zimbra instance, trim unnecessary internet exposure, and test the detection hypotheses above against existing logs.

🔹 Source Note

The feed item also carried the headline "3 lessons from frontier AI vulnerability research" with no body content, so it is not covered here.

🔹 References
• Microsoft Threat Intelligence post: "Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570", September 30
• CVE-2026-73570

🔹 CVE202673570 #Zimbra #ThreatIntelligence #CommandInjection #MailServers

🔗 Source: microsoft.com/en-us/security/b

##

CVE-2026-47483
(8.2 HIGH)

EPSS: 0.34%

updated 2026-07-28T18:33:11

1 posts

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

_r_netsec@infosec.exchange at 2026-10-08T22:03:21.000Z ##

How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483) lava.security/research/cve-202

##

CVE-2025-31200
(9.8 CRITICAL)

EPSS: 20.90%

updated 2026-06-17T09:10:00.550000

1 posts

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specif

4 repos

https://github.com/serundengsapi/CVE-2025-31200-iOS-AudioConverter-RCE

https://github.com/hunters-sec/CVE-2025-31200

https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201

https://github.com/zhuowei/apple-positional-audio-codec-invalid-header

cyberworldops@infosec.exchange at 2026-10-09T17:20:57.000Z ##

iVerify reports a P7 DarkSword iOS variant combining crypto-wallet theft with remote command execution. It chains CVE-2025-24201 and CVE-2025-31200, both CISA KEV-listed, enabling persistent device control. Patching and wallet-device isolation are critical. #IosSecurity #CryptoTheft #DarkSword

cyberworldops.eu/en/p7-darkswo

##

CVE-2025-24201
(7.1 HIGH)

EPSS: 3.85%

updated 2025-11-13T21:31:15

1 posts

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionOS 2.3.2, iOS 18.3.2 and iPadOS 18.3.2, macOS Sequoia 15.3.2. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been e

3 repos

https://github.com/JGoyd/Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201

https://github.com/The-Maxu/CVE-2025-24201-WebKit-Vulnerability-Detector-PoC-

https://github.com/5ky9uy/glass-cage-i18-2025-24085-and-cve-2025-24201

cyberworldops@infosec.exchange at 2026-10-09T17:20:57.000Z ##

iVerify reports a P7 DarkSword iOS variant combining crypto-wallet theft with remote command execution. It chains CVE-2025-24201 and CVE-2025-31200, both CISA KEV-listed, enabling persistent device control. Patching and wallet-device isolation are critical. #IosSecurity #CryptoTheft #DarkSword

cyberworldops.eu/en/p7-darkswo

##

CVE-2025-47818
(2.2 LOW)

EPSS: 0.24%

updated 2025-10-24T18:32:04

1 posts

Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.

olearysec@infosec.exchange at 2026-10-09T14:11:02.000Z ##

@briankrebs Every Flock CVE in existence (CVE-2025-47818 through -47824) came through MITRE off Jon Gaines' 2025 research, before Flock had any say in the numbering. The "outside parties requesting CVE IDs before a fix is ready" line reads like a reference to that.

As for who decides what's a bug, they've answered in writing. The new VDP gives Flock 120 days to publish, with an exception for anything it deems a "material safety risk to law enforcement or the public." Their advisories page lists nothing, two weeks after a pentest write-up with 2 criticals and 7 highs that Flock says needed no customer action, which is exactly the kind of finding a vendor CNA can decline to number. So yes, Flock decides now. The criteria just live on a legal page instead of a press release.

##

CVE-2024-3094
(10.0 CRITICAL)

EPSS: 85.97%

updated 2024-03-29T18:30:50

1 posts

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The tarballs included extra .m4 files, which contained instructions for building with automake that did not exist in the repository. These instructions, through a series of complex obfuscations, extract a prebuilt object file from one of the test archives, which is then used to modify specific functions in t

Nuclei template

90 repos

https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094

https://github.com/hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-

https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094

https://github.com/x-cmd-build/xz

https://github.com/Horizon-Software-Development/CVE-2024-3094

https://github.com/robertdebock/ansible-role-cve_2024_3094

https://github.com/devjanger/CVE-2024-3094-XZ-Backdoor-Detector

https://github.com/lockness-Ko/xz-vulnerable-honeypot

https://github.com/badsectorlabs/ludus_xz_backdoor

https://github.com/jfrog/cve-2024-3094-tools

https://github.com/gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer

https://github.com/nnatsopoulos/xz-backdoor-research

https://github.com/zpxlz/CVE-2024-3094

https://github.com/mightysai1997/CVE-2024-3094-info

https://github.com/bsekercioglu/cve2024-3094-Checker

https://github.com/neuralinhibitor/xzwhy

https://github.com/dah4k/CVE-2024-3094

https://github.com/wgetnz/CVE-2024-3094-check

https://github.com/Michel-DV/xz-utils-backdoor-case-study

https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project

https://github.com/0xlane/xz-cve-2024-3094

https://github.com/galacticquest/cve-2024-3094-detect

https://github.com/bioless/xz_cve-2024-3094_detection

https://github.com/ElinaNotElina/cve-2024-3094-analysis

https://github.com/gustavorobertux/CVE-2024-3094

https://github.com/extracoding-dozen/CVE-2024-3094

https://github.com/stevehenderson/lab_xz_backdoor

https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check

https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public

https://github.com/Yuma-Tsushima07/CVE-2024-3094

https://github.com/spidygal/CVE-2024-3094-Nmap-NSE-script

https://github.com/hazemkya/CVE-2024-3094-checker

https://github.com/fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-

https://github.com/Ava-Vispilio/CVE-2024-3094

https://github.com/TheTorjanCaptain/CVE-2024-3094-Checker

https://github.com/mightysai1997/CVE-2024-3094

https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094

https://github.com/emirkmo/xz-backdoor-github

https://github.com/hackingetico21/revisaxzutils

https://github.com/jbnetwork-git/CVE-2024-3094-XZ-Utils-Check

https://github.com/M1lo25/CS50FinalProject

https://github.com/isuruwa/CVE-2024-3094

https://github.com/mrk336/CVE-2024-3094

https://github.com/24Owais/threat-intel-cve-2024-3094

https://github.com/pentestfunctions/CVE-2024-3094

https://github.com/HackerHermanos/CVE-2024-3094_xz_check

https://github.com/shefirot/CVE-2024-3094

https://github.com/KaminaDuck/ansible-CVE-2024-3094

https://github.com/ScrimForever/CVE-2024-3094

https://github.com/AndreaCicca/Sicurezza-Informatica-Presentazione

https://github.com/harekrishnarai/xz-utils-vuln-checker

https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker

https://github.com/mesutgungor/xz-backdoor-vulnerability

https://github.com/ThomRgn/xzutils_backdoor_obfuscation

https://github.com/teyhouse/CVE-2024-3094

https://github.com/amlweems/xzbot

https://github.com/Mustafa1986/CVE-2024-3094

https://github.com/buluma/ansible-role-cve_2024_3094

https://github.com/robertdebock/ansible-playbook-cve-2024-3094

https://github.com/0xBlackash/CVE-2024-3094

https://github.com/Simplifi-ED/CVE-2024-3094-patcher

https://github.com/brinhosa/CVE-2024-3094-One-Liner

https://github.com/weltregie/liblzma-scan

https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094

https://github.com/encikayelwhitehat-glitch/CVE-2024-3094

https://github.com/MagpieRYL/CVE-2024-3094-backdoor-env-container

https://github.com/ykhurshudyan-blip/CVE-2024-3094

https://github.com/mhicairo-hue/cs50-cybersecurity-final-project

https://github.com/Ikram124/CVE-2024-3094-analysis

https://github.com/Fractal-Tess/CVE-2024-3094

https://github.com/byinarie/CVE-2024-3094-info

https://github.com/Dermot-lab/TryHack

https://github.com/vnchk1/sec_review_cve-2024-3094

https://github.com/iheb2b/CVE-2024-3094-Checker

https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094

https://github.com/przemoc/xz-backdoor-links

https://github.com/BOSE122/CVE-2024-3094

https://github.com/Security-Phoenix-demo/CVE-2024-3094-fix-exploits

https://github.com/FabioBaroni/CVE-2024-3094-checker

https://github.com/felipecosta09/cve-2024-3094

https://github.com/ashwani95/CVE-2024-3094

https://github.com/r0binak/xzk8s

https://github.com/robertdfrench/ifuncd-up

https://github.com/ackemed/detectar_cve-2024-3094

https://github.com/h3raklez/CVE-2024-3094

https://github.com/Juul/xz-backdoor-scan

https://github.com/valeriot30/cve-2024-3094

https://github.com/been22426/CVE-2024-3094

https://github.com/michalAshurov/writeup-CVE-2024-3094

https://github.com/hackura/xz-cve-2024-3094

technotenshi@infosec.exchange at 2026-10-10T01:41:36.000Z ##

An analysis by a Redditor, published on sheets.works, counted regular contributors on 23 core open source projects and found 11 had only one or two in the past year. xz, which shipped a backdoor in 2024 (CVE-2024-3094), again has one: Lasse Collin wrote 97 percent of its 2025 changes, and the analysis found no new funding. Eight projects, including SQLite, zlib and bash, show no grant from four named funders.

linuxstans.com/11-of-23-core-o

#OpenSource #InfoSec #SupplyChain #Linux

##

CVE-2023-22894
(7.5 HIGH)

EPSS: 3.61%

updated 2023-11-07T05:05:45

2 posts

### Summary Strapi through 4.7.1 allows unauthenticated attackers to discover sensitive user details for Strapi administrators and API users. ### Details Strapi through 4.7.1 allows unauthenticated attackers to discover sensitive user details for Strapi administrators and API users. The unauthenticated attacker can filter users by columns that contain sensitive information and infer the values

2 repos

https://github.com/maxntv/CVE-2023-22894-PoC

https://github.com/Saboor-Hakimi/CVE-2023-22894

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:01:28.000Z ##

CVE ID: CVE-2023-22894
Vendor: Strapi
Product: Strapi
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2016-3081
(8.1 HIGH)

EPSS: 96.05%

updated 2023-11-01T19:47:30

6 posts

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

Nuclei template

thecybermind at 2026-10-10T12:49:06.654Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2016-3081 – Apache Struts Command Injection Vulnerability

A strategic C-Suite threat brief covering CVE-2016-3081 Apache Struts command injection vulnerability, featuring active mitigation, asset inventory management, and endpoint hardening....

thecybermind.co/2p4b

##

thecybermind at 2026-10-10T12:47:26.592Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2016-3081 – Apache Struts Command Injection Vulnerability

Unpack CVE-2016-3081 with our technical TSUITE brief. Get advanced detection rules, Splunk SPL, KQL, and forensic triage priorities for active CISA KEV threats....

thecybermind.co/bw95

##

thecybermind@infosec.exchange at 2026-10-10T12:49:06.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2016-3081 – Apache Struts Command Injection Vulnerability

A strategic C-Suite threat brief covering CVE-2016-3081 Apache Struts command injection vulnerability, featuring active mitigation, asset inventory management, and endpoint hardening....

thecybermind.co/2p4b

##

thecybermind@infosec.exchange at 2026-10-10T12:47:26.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2016-3081 – Apache Struts Command Injection Vulnerability

Unpack CVE-2016-3081 with our technical TSUITE brief. Get advanced detection rules, Splunk SPL, KQL, and forensic triage priorities for active CISA KEV threats....

thecybermind.co/bw95

##

secdb@infosec.exchange at 2026-10-08T19:00:11.000Z ##

🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2015-3306 (secdb.nttzen.cloud/cve/detail/)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: proftpd.org/ ; lists.debian.org/debian-securi ; lists.opensuse.org/archives/li ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2015-5477 (secdb.nttzen.cloud/cve/detail/)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: web.archive.org/web/2015072901 ; access.redhat.com/errata/RHSA-; supportportal.juniper.net/s/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2016-3081 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: cwiki.apache.org/confluence/di ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2021-3199 (secdb.nttzen.cloud/cve/detail/)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; github.com/ONLYOFFICE/Document ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2023-22894 (secdb.nttzen.cloud/cve/detail/)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: strapi.io/blog/security-disclo ; github.com/strapi/strapi/relea ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894

##

cisakevtracker@mastodon.social at 2026-10-08T18:01:13.000Z ##

CVE ID: CVE-2016-3081
Vendor: Apache
Product: Struts
Date Added: 2026-10-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-85219
(0 None)

EPSS: 0.41%

2 posts

N/A

hugovalters@mastodon.social at 2026-10-10T06:20:19.000Z ##

CVE-2026-85219: DoS in Thinkst Canary OpenCanary 0.9.9 Redis module. Unauthenticated remote attacker can exhaust memory. CVSS 3.7. Patch under review, watch for updates. valtersit.com/cve/CVE-2026-852 #CVE #infosec #cybersecurity

##

hugovalters@mastodon.social at 2026-10-10T06:20:19.000Z ##

CVE-2026-85219: DoS in Thinkst Canary OpenCanary 0.9.9 Redis module. Unauthenticated remote attacker can exhaust memory. CVSS 3.7. Patch under review, watch for updates. valtersit.com/cve/CVE-2026-852 #CVE #infosec #cybersecurity

##

linuxmint_hun@mastodon.social at 2026-10-10T06:08:29.000Z ##

Figyelem: egy magas súlyosságú WordPress Core hiba (CVE-2026-87902) LFI-ből RCE-vé alakulhat — érint sok ágat és régi témát. Van aktív page- előtagú témád és régi PHP-d? Ellenőrizd a naplókat, és frissíts minél előbb.

linuxmint.hu/hir/2026/10/riasz

#WordPress #CVE2026-87902 #RCE #LFI #NKI #CISA #websecurity #PHP #themes #kiberbiztonság

##

linuxmint_hun@mastodon.social at 2026-10-10T06:08:29.000Z ##

Figyelem: egy magas súlyosságú WordPress Core hiba (CVE-2026-87902) LFI-ből RCE-vé alakulhat — érint sok ágat és régi témát. Van aktív page- előtagú témád és régi PHP-d? Ellenőrizd a naplókat, és frissíts minél előbb.

linuxmint.hu/hir/2026/10/riasz

#WordPress #CVE2026-87902 #RCE #LFI #NKI #CISA #websecurity #PHP #themes #kiberbiztonság

##

CVE-2026-108269
(0 None)

EPSS: 0.13%

1 posts

N/A

offseq@infosec.exchange at 2026-10-10T01:30:27.000Z ##

CVE-2026-108269 (CRITICAL, CVSS 9.1): Privasys ra-tls-clients <0.5.0 origin validation error lets attackers relay attestation quotes, compromising TLS trust. Upgrade to 0.5.0+ now. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026108269 #Rust #Go #TLS

##

CVE-2026-108263
(0 None)

EPSS: 0.43%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-09T21:46:48.000Z ##

🔴 CVE-2026-108263 - Critical (9.9)

Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107821
(0 None)

EPSS: 0.48%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-09T18:46:36.000Z ##

🟠 CVE-2026-107821 - High (8)

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB insufficiently validated counts, offsets, lengths, and field boundaries in FRM metadata while opening b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107838
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-09T18:31:09.000Z ##

🟠 CVE-2026-107838 - High (7.5)

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107837
(0 None)

EPSS: 0.38%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-09T18:31:00.000Z ##

🟠 CVE-2026-107837 - High (8.2)

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, _receive() in sys/net/gnrc/network_layer/sixlowpan/gnrc_sixlowpan.c can route an undersized packet ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61746
(0 None)

EPSS: 0.40%

1 posts

N/A

hugovalters@mastodon.social at 2026-10-09T17:40:03.000Z ##

CVE-2026-61746 InvenTree: unauthenticated info disclosure via plugin settings API before 1.4.0. CVSS 5.3. Patch under review - restrict API access now. valtersit.com/cve/CVE-2026-617 #CVE #infosec

##

kaito834@infosec.exchange at 2026-10-08T23:15:40.000Z ##

直近で相次いでいる国内組織における不正アクセスに関する注意喚起 jpcert.or.jp/m/at/2026/at26003 2026-10-08
JPCERT/CCに寄せられた情報などでは:
ケースA:...既知の脆弱性を探索し攻撃試行するもの
ケースB:API経由での不正な操作
ケースC:MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)

ケースBの場合:
(a)一般公開しているスマートフォンアプリを解析しAPIのエンドポイントやキーを特定する
(b)本来画面操作では実行できない内部APIに対する攻撃
(c)他のシステムの侵害で窃取したAPIキーを使用する

##

CVE-2026-106433
(0 None)

EPSS: 0.27%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-08T19:46:04.000Z ##

🟠 CVE-2026-106433 - High (8.8)

Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault docume...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107376
(0 None)

EPSS: 0.45%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-08T18:30:24.000Z ##

🟠 CVE-2026-107376 - High (8.2)

webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107332
(0 None)

EPSS: 0.11%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-10-08T17:45:00.000Z ##

CVE-2026-107332 - Insecure default file permissions on cached credentials in AWS Toolkit for Visual Studio Code

Bulletin ID: 2026-129-AWS

Scope: AWS

Content Type: Important (requires attention)

Publication Date: 10/08/2026 10:30 PM PDT
Description:
AWS Toolkit for Visual Studio Code is an open source extension that lets developers ...

aws.amazon.com/security/securi

#aws #security

##

Visit counter For Websites