##
Updated at UTC 2026-08-31T01:18:53.247822
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-82549 | 8.3 | 0.00% | 2 | 0 | 2026-08-30T16:16:43.667000 | A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an | |
| CVE-2026-82645 | 8.6 | 0.00% | 2 | 0 | 2026-08-30T15:30:35 | AVideo (current commit e01e41ecc and earlier) exposes stream credentials through | |
| CVE-2026-82644 | 7.5 | 0.00% | 2 | 0 | 2026-08-30T15:30:35 | WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting | |
| CVE-2026-82638 | 7.5 | 0.00% | 2 | 0 | 2026-08-30T15:30:34 | jina-ai reader disables its private-address guard outside Google Cloud deploymen | |
| CVE-2026-82642 | 8.8 | 0.00% | 2 | 0 | 2026-08-30T15:30:34 | Readest is an open-source e-book reader built on Tauri. In versions prior to 0.1 | |
| CVE-2026-82542 | 10.0 | 0.00% | 4 | 0 | 2026-08-30T15:30:34 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue i | |
| CVE-2026-82655 | 7.5 | 0.00% | 2 | 0 | 2026-08-30T15:30:29 | Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relati | |
| CVE-2026-82654 | 8.9 | 0.00% | 2 | 0 | 2026-08-30T15:30:28 | SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields | |
| CVE-2026-82636 | 7.9 | 0.00% | 3 | 0 | 2026-08-30T15:30:27 | Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during | |
| CVE-2026-82635 | 8.8 | 0.00% | 3 | 0 | 2026-08-30T15:30:27 | Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file | |
| CVE-2026-82641 | 8.6 | 0.00% | 2 | 0 | 2026-08-30T15:30:27 | keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to | |
| CVE-2026-82657 | 7.5 | 0.00% | 2 | 0 | 2026-08-30T15:16:46.607000 | Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS fee | |
| CVE-2026-82653 | 8.9 | 0.00% | 2 | 0 | 2026-08-30T15:16:46.033000 | SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in con | |
| CVE-2026-82639 | 7.5 | 0.00% | 2 | 0 | 2026-08-30T14:17:03.750000 | NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation | |
| CVE-2026-82539 | 9.1 | 0.00% | 2 | 1 | 2026-08-30T11:17:35.067000 | A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This imp | |
| CVE-2026-15980 | 9.8 | 0.45% | 4 | 0 | 2026-08-30T06:30:22 | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in a | |
| CVE-2026-16061 | 8.6 | 0.26% | 2 | 0 | 2026-08-30T03:32:22 | The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a | |
| CVE-2026-16947 | 9.1 | 0.24% | 2 | 0 | 2026-08-30T03:32:22 | The Total processing card payments for WooCommerce WordPress plugin through 7.3 | |
| CVE-2026-16600 | 7.7 | 0.20% | 2 | 0 | 2026-08-30T03:31:21 | The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability ch | |
| CVE-2026-77007 | 7.5 | 0.26% | 2 | 0 | 2026-08-30T03:31:21 | The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through | |
| CVE-2026-76586 | 7.5 | 0.21% | 2 | 0 | 2026-08-30T03:31:21 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin | |
| CVE-2026-77012 | 9.3 | 0.20% | 2 | 0 | 2026-08-30T01:20:28.140000 | The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install s | |
| CVE-2026-76548 | 8.2 | 0.19% | 2 | 0 | 2026-08-30T01:20:25.760000 | The User Profile Builder WordPress plugin before 4.0.1 does not properly restri | |
| CVE-2026-16259 | 9.8 | 0.28% | 2 | 0 | 2026-08-30T01:20:19.677000 | The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the accou | |
| CVE-2026-15369 | 9.8 | 0.40% | 2 | 0 | 2026-08-29T20:16:31.840000 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vuln | |
| CVE-2026-82463 | 8.1 | 0.30% | 2 | 0 | 2026-08-29T18:31:38 | pac4j-core before 6.5.6 contains an authentication bypass vulnerability in Check | |
| CVE-2026-82474 | 7.8 | 0.13% | 2 | 0 | 2026-08-29T18:31:38 | Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat sys | |
| CVE-2026-82473 | 8.2 | 0.35% | 2 | 0 | 2026-08-29T18:31:38 | KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS | |
| CVE-2026-82472 | 7.5 | 0.41% | 2 | 0 | 2026-08-29T18:31:38 | Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf en | |
| CVE-2026-75807 | 7.5 | 0.29% | 2 | 0 | 2026-08-29T18:31:38 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authen | |
| CVE-2026-82475 | 8.1 | 0.26% | 2 | 0 | 2026-08-29T18:31:38 | iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerabilit | |
| CVE-2026-82466 | 8.7 | 0.34% | 2 | 0 | 2026-08-29T18:31:32 | Rodauth before 2.46.0 contains an authentication bypass vulnerability in the web | |
| CVE-2026-82461 | 8.1 | 0.19% | 4 | 0 | 2026-08-29T18:31:31 | pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audien | |
| CVE-2026-82460 | 9.8 | 0.77% | 2 | 0 | 2026-08-29T17:17:58.060000 | Cloud Commander before 19.20.2 contains a directory traversal vulnerability in R | |
| CVE-2026-82450 | 8.8 | 0.57% | 2 | 0 | 2026-08-29T15:30:27 | BookStack before 26.05.4 contains a remote code execution vulnerability in the p | |
| CVE-2026-82457 | 7.8 | 0.12% | 2 | 0 | 2026-08-29T15:30:27 | su-exec through 0.3 fails to validate numeric user and group identifiers parsed | |
| CVE-2026-82454 | 9.1 | 0.23% | 2 | 0 | 2026-08-29T15:30:27 | The Omnivore API (packages/api) before the fix in commit abf53d6 contains an aut | |
| CVE-2026-82453 | 7.5 | 0.28% | 2 | 0 | 2026-08-29T15:30:21 | rust-iot-platform through commit 5df942ab stores user passwords in cleartext wit | |
| CVE-2026-82447 | 8.8 | 0.45% | 3 | 0 | 2026-08-29T15:30:20 | Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock | |
| CVE-2026-82448 | 9.8 | 0.41% | 2 | 0 | 2026-08-29T15:30:20 | Shinobi before commit 5a76c74f contains a hardcoded connection key in the child | |
| CVE-2026-82456 | 10.0 | 0.37% | 2 | 0 | 2026-08-29T14:16:38.767000 | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts | |
| CVE-2026-82455 | 7.1 | 0.14% | 1 | 0 | 2026-08-29T14:16:38.623000 | RubyGems fails to re-validate path containment after filesystem symlink resoluti | |
| CVE-2026-82452 | 9.8 | 0.46% | 3 | 0 | 2026-08-29T14:16:38.210000 | rust-iot-platform through commit 5df942ab contains an authentication bypass vuln | |
| CVE-2026-14494 | 9.8 | 0.69% | 2 | 0 | 2026-08-29T12:30:27 | The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution | |
| CVE-2026-56100 | 8.1 | 0.29% | 2 | 0 | 2026-08-29T12:16:41.747000 | SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privileg | |
| CVE-2026-82078 | 0 | 0.46% | 3 | 2 | 2026-08-29T04:18:08.953000 | An unsafe dynamic class loading vulnerability exists in the database connection | |
| CVE-2026-81522 | 8.1 | 0.27% | 1 | 0 | 2026-08-29T04:18:07.147000 | A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace ide | |
| CVE-2026-41012 | 7.7 | 0.10% | 2 | 0 | 2026-08-29T03:31:04 | Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers | |
| CVE-2026-81533 | 7.1 | 0.21% | 2 | 0 | 2026-08-29T00:31:12 | An application using the MongoDB BI Connector ODBC Driver may encounter a memory | |
| CVE-2026-81490 | 7.7 | 0.24% | 3 | 0 | 2026-08-29T00:31:12 | A database user able to create a view in a namespace that MongoDB Connector for | |
| CVE-2026-81518 | 7.5 | 0.15% | 2 | 0 | 2026-08-29T00:31:12 | When mongosqld is configured with a client certificate authority file, the liste | |
| CVE-2026-82017 | 7.6 | 0.15% | 2 | 0 | 2026-08-29T00:31:12 | IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry | |
| CVE-2026-3627 | 9.1 | 0.51% | 3 | 0 | 2026-08-29T00:31:03 | IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacke | |
| CVE-2026-18729 | 8.8 | 0.46% | 2 | 1 | 2026-08-29T00:31:02 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacke | |
| CVE-2026-18527 | 9.9 | 0.29% | 2 | 0 | 2026-08-29T00:31:01 | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (AR | |
| CVE-2026-55848 | 8.6 | 0.33% | 2 | 0 | 2026-08-28T22:33:36 | ### Summary XXE on MapFish Print allows reading arbitrary files of certain types | |
| CVE-2026-55784 | 7.5 | 0.25% | 3 | 0 | 2026-08-28T22:24:13 | ### Summary The AUSF component of free5GC stores per-subscriber authentication | |
| CVE-2026-82283 | 8.1 | 0.24% | 2 | 0 | 2026-08-28T22:16:56.530000 | VoltAgent through 2.1.20 fails to validate conversation ownership in memory API | |
| CVE-2026-82278 | 8.8 | 0.56% | 2 | 0 | 2026-08-28T22:16:56.293000 | BISHENG before 2.6.0 contains a remote code execution vulnerability in the workf | |
| CVE-2026-82269 | 8.1 | 0.30% | 2 | 0 | 2026-08-28T22:16:55.857000 | Gophish through 0.12.1 fails to enforce account lockout and password change requ | |
| CVE-2026-81532 | 8.8 | 0.28% | 2 | 0 | 2026-08-28T22:16:54.793000 | A user able to submit SQL through an application using the MongoDB Connector for | |
| CVE-2026-81520 | 7.5 | 0.24% | 3 | 0 | 2026-08-28T22:16:54.650000 | A network-reachable client that has not yet authenticated can hold a MongoDB Con | |
| CVE-2026-81517 | 7.5 | 0.26% | 2 | 0 | 2026-08-28T22:16:54.383000 | An unauthenticated party able to reach the port of a MongoDB Connector for BI (m | |
| CVE-2026-77078 | 7.5 | 0.29% | 2 | 0 | 2026-08-28T22:16:53.883000 | multer is a middleware for handling multipart/form-data in Node.js. A small mult | |
| CVE-2026-77037 | 7.5 | 0.35% | 2 | 0 | 2026-08-28T22:16:53.627000 | multer is a middleware for handling multipart/form-data in Node.js. In version 2 | |
| CVE-2026-55634 | 9.9 | 0.45% | 3 | 0 | 2026-08-28T22:16:51.290000 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.1 | |
| CVE-2026-19295 | 9.9 | 0.98% | 2 | 1 | 2026-08-28T22:16:47.613000 | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execut | |
| CVE-2026-19286 | 9.8 | 0.61% | 2 | 1 | 2026-08-28T22:16:47.357000 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute a | |
| CVE-2026-18904 | 8.2 | 0.31% | 2 | 0 | 2026-08-28T22:16:47.227000 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain se | |
| CVE-2026-18899 | 7.5 | 0.46% | 2 | 0 | 2026-08-28T22:16:47.107000 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbi | |
| CVE-2026-18891 | 8.2 | 0.29% | 2 | 0 | 2026-08-28T22:16:46.990000 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute a | |
| CVE-2026-17203 | 7.5 | 0.43% | 2 | 0 | 2026-08-28T22:16:46.480000 | IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated | |
| CVE-2026-55841 | 7.5 | 0.36% | 3 | 0 | 2026-08-28T22:13:01 | ### Impact A security issue has been identified in Graylog affecting the parsin | |
| CVE-2026-18885 | None | 0.43% | 3 | 0 | 2026-08-28T21:32:13 | ServiceNow has remediated a code injection vulnerability that was identified in | |
| CVE-2026-18886 | None | 0.25% | 3 | 0 | 2026-08-28T21:32:13 | ServiceNow has remediated an improper access control vulnerability that was iden | |
| CVE-2026-82329 | 9.8 | 0.38% | 3 | 0 | 2026-08-28T21:31:36 | JFrog Artifactory contains an authentication weakness that, under default config | |
| CVE-2026-82285 | 8.2 | 0.31% | 2 | 0 | 2026-08-28T21:31:36 | bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability | |
| CVE-2026-82284 | 8.1 | 0.24% | 2 | 0 | 2026-08-28T21:31:36 | Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/ | |
| CVE-2026-82282 | 8.0 | 0.26% | 2 | 0 | 2026-08-28T21:31:36 | Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, al | |
| CVE-2026-82291 | 8.1 | 0.30% | 2 | 0 | 2026-08-28T21:31:36 | HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses w | |
| CVE-2026-82279 | 8.1 | 0.27% | 2 | 0 | 2026-08-28T21:31:29 | HyperDX through 1.10.1 fails to enforce role-based access controls in team manag | |
| CVE-2026-82288 | 7.5 | 0.32% | 2 | 0 | 2026-08-28T21:31:28 | Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerabi | |
| CVE-2026-82287 | 8.1 | 0.28% | 2 | 0 | 2026-08-28T21:31:28 | Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows a | |
| CVE-2026-82286 | 8.6 | 0.35% | 2 | 1 | 2026-08-28T21:31:28 | gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the | |
| CVE-2026-82277 | 9.8 | 0.43% | 2 | 0 | 2026-08-28T21:31:26 | Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutat | |
| CVE-2026-82270 | 7.5 | 0.28% | 2 | 0 | 2026-08-28T21:31:25 | Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnera | |
| CVE-2026-82268 | 7.5 | 0.28% | 2 | 0 | 2026-08-28T21:31:25 | Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability i | |
| CVE-2026-72984 | 8.8 | 0.44% | 2 | 0 | 2026-08-28T21:31:24 | Access of resource using incompatible type ('type confusion') in Microsoft Edge | |
| CVE-2026-75124 | 7.5 | 0.48% | 2 | 0 | 2026-08-28T21:31:24 | PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication | |
| CVE-2026-82266 | 9.8 | 0.34% | 2 | 0 | 2026-08-28T21:31:23 | Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_requi | |
| CVE-2026-82021 | 8.3 | 0.23% | 2 | 0 | 2026-08-28T21:31:19 | Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its | |
| CVE-2026-77586 | 8.0 | 0.23% | 2 | 0 | 2026-08-28T21:31:18 | In MongoDB Connector for BI, MongoDB object names such as collection, field, and | |
| CVE-2026-74820 | None | 0.25% | 3 | 0 | 2026-08-28T21:31:08 | ServiceNow has remediated a SQL injection vulnerability that was identified in i | |
| CVE-2026-81525 | 8.1 | 0.27% | 2 | 0 | 2026-08-28T21:16:15.740000 | The MongoDB client library for PHP does not sufficiently sanitize special elemen | |
| CVE-2026-82275 | 7.5 | 0.37% | 2 | 0 | 2026-08-28T20:20:18.507000 | Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the documen | |
| CVE-2026-82227 | 8.5 | 0.23% | 1 | 0 | 2026-08-28T20:20:15.380000 | Contributor SQL Injection in WPBulky <= 1.2.2 versions. | |
| CVE-2026-81694 | 3.3 | 0.18% | 1 | 0 | 2026-08-28T20:20:11.807000 | openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames rea | |
| CVE-2026-81285 | 7.5 | 0.26% | 2 | 0 | 2026-08-28T20:20:09.763000 | Unauthenticated Denial of Service Attack in Smush Image Compression and Optimiza | |
| CVE-2026-76640 | 7.5 | 0.35% | 3 | 1 | 2026-08-28T20:19:54.877000 | Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities | |
| CVE-2026-75486 | 8.0 | 1.25% | 2 | 0 | 2026-08-28T20:19:54.027000 | Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that a | |
| CVE-2026-61800 | 9.1 | 0.59% | 1 | 0 | 2026-08-28T20:19:08.670000 | Wazuh is an open-source security platform providing unified XDR and SIEM protect | |
| CVE-2026-59822 | 8.2 | 0.52% | 1 | 0 | 2026-08-28T20:19:01.897000 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo | |
| CVE-2026-55552 | 7.5 | 0.43% | 2 | 0 | 2026-08-28T20:18:28.793000 | Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler. | |
| CVE-2026-55511 | 9.1 | 0.68% | 2 | 1 | 2026-08-28T20:18:27.947000 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a | |
| CVE-2026-55215 | 7.5 | 0.42% | 2 | 0 | 2026-08-28T20:18:26.353000 | MariaDB Connector/Node.js is used to connect applications developed on Node.js t | |
| CVE-2026-54755 | 9.6 | 0.39% | 2 | 0 | 2026-08-28T20:18:17.670000 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1 | |
| CVE-2026-53362 | 7.8 | 0.51% | 9 | 1 | 2026-08-28T20:18:10.133000 | In the Linux kernel, the following vulnerability has been resolved: ipv6: accou | |
| CVE-2026-47864 | 6.4 | 3.44% | 2 | 0 | 2026-08-28T20:17:33.510000 | SerializingHttpMessageConverter deserializes the body of incoming HTTP requests | |
| CVE-2026-18983 | 7.5 | 0.50% | 1 | 0 | 2026-08-28T20:17:23.810000 | The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to | |
| CVE-2026-55484 | 7.5 | 0.34% | 2 | 0 | 2026-08-28T19:19:39 | ### Summary A single unauthenticated HTTP request to a path starting with `?` (e | |
| CVE-2026-55247 | 9.1 | 0.34% | 2 | 0 | 2026-08-28T18:59:43 | ### Impact By abusing the iCalendar import functionality, a logged-in editor cou | |
| CVE-2026-81681 | 4.6 | 0.13% | 2 | 0 | 2026-08-28T18:56:34.447000 | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a port | |
| CVE-2026-81685 | 3.3 | 0.18% | 1 | 0 | 2026-08-28T18:56:34.447000 | openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in | |
| CVE-2026-81706 | 6.8 | 0.13% | 1 | 0 | 2026-08-28T18:56:34.447000 | openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own i | |
| CVE-2026-81721 | 7.5 | 0.39% | 1 | 0 | 2026-08-28T18:56:34.447000 | openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted | |
| CVE-2026-82254 | 7.5 | 0.35% | 1 | 0 | 2026-08-28T18:54:09.323000 | gitoxide before 0.69.0 contains unchecked array indexing in delta application an | |
| CVE-2026-55248 | 9.1 | 0.32% | 2 | 0 | 2026-08-28T18:41:35 | ### Impact By adding an RSS portlet, and giving this a link to a very large file | |
| CVE-2026-81767 | 7.5 | 0.20% | 1 | 0 | 2026-08-28T18:31:39 | Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions. | |
| CVE-2026-81578 | None | 0.39% | 3 | 2 | 2026-08-28T18:31:31 | An improper access control vulnerability exists in the web management interface | |
| CVE-2026-81019 | 7.4 | 0.24% | 1 | 0 | 2026-08-28T18:31:30 | wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when | |
| CVE-2026-48710 | 6.5 | 2.10% | 1 | 5 | template | 2026-08-28T18:31:00 | ### Summary In affected versions, the HTTP `Host` request header was not validat |
| CVE-2026-55584 | 7.5 | 2.42% | 2 | 1 | 2026-08-28T18:30:56 | ## Summary phpSysInfo's `PSI_ALLOWED` IP allowlist can be trivially bypassed by | |
| CVE-2026-55485 | 8.8 | 0.39% | 2 | 0 | 2026-08-28T18:14:13 | ## Summary `piccolo_admin` uses a helper called `superuser_validators` to gate | |
| CVE-2026-55565 | 9.9 | 0.46% | 2 | 0 | 2026-08-28T17:30:35 | ## Summary Yamcs compiles StreamSQL query expressions to Java at runtime with Ja | |
| CVE-2026-55559 | 9.8 | 0.55% | 2 | 0 | 2026-08-28T17:23:05 | ### Summary `templateArgs` sent to `POST /api/instances` (and `PATCH /api/insta | |
| CVE-2026-55521 | 8.8 | 0.36% | 2 | 0 | 2026-08-28T17:09:36 | ### Summary Multiple Missing Function Level Access Control vulnerabilities exist | |
| CVE-2026-55065 | 8.1 | 0.35% | 2 | 0 | 2026-08-28T16:50:36 | ### Summary A user with only a single self-owned project can permanently destro | |
| CVE-2026-54754 | 9.6 | 0.30% | 2 | 0 | 2026-08-28T16:22:16 | ## Summary When a marketplace order is settled (`MarketBuy` / `BuyItNow`, and a | |
| CVE-2026-78239 | 9.8 | 0.55% | 2 | 0 | 2026-08-28T16:18:27.560000 | Xiiaozet LK100W exposes a critical management function that can be invoked with | |
| CVE-2026-75813 | 7.5 | 0.26% | 1 | 0 | 2026-08-28T16:18:25.510000 | Certain configuration endpoints may lack proper server-side authorization check | |
| CVE-2026-55108 | 8.5 | 0.57% | 2 | 0 | 2026-08-28T16:13:22 | ### Summary KubeVela's Terraform remote configuration loader can be abused to m | |
| CVE-2026-78251 | 0 | 0.39% | 1 | 0 | 2026-08-28T15:28:32.763000 | DJI drones contain an FTP service that uses hardcoded credentials shared across | |
| CVE-2026-82222 | 10.0 | 0.42% | 6 | 2 | 2026-08-28T12:30:36 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP | |
| CVE-2026-82252 | 7.5 | 0.39% | 2 | 0 | 2026-08-28T12:30:36 | gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules fi | |
| CVE-2026-82251 | 7.5 | 0.39% | 1 | 0 | 2026-08-28T12:30:36 | gitoxide before 0.52.1 fails to validate submodule names from .gitmodules config | |
| CVE-2026-82253 | 7.5 | 0.50% | 1 | 0 | 2026-08-28T12:30:36 | gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path | |
| CVE-2026-82261 | 7.5 | 0.34% | 1 | 0 | 2026-08-28T12:30:36 | SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remot | |
| CVE-2026-82260 | 7.5 | 0.34% | 1 | 0 | 2026-08-28T12:30:36 | SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remot | |
| CVE-2026-82259 | 7.5 | 0.37% | 1 | 0 | 2026-08-28T12:30:30 | SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deseri | |
| CVE-2026-82247 | 7.5 | 0.30% | 2 | 0 | 2026-08-28T12:30:28 | gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL par | |
| CVE-2026-82123 | 6.5 | 0.18% | 1 | 0 | 2026-08-28T09:32:01 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2026-82082 | 9.8 | 1.50% | 1 | 0 | 2026-08-28T06:31:13 | NUMail developed by Green-Computing has an OS Command Injection vulnerability. U | |
| CVE-2026-19313 | None | 0.47% | 1 | 0 | 2026-08-28T03:31:28 | An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows | |
| CVE-2026-38822 | 7.6 | 0.85% | 1 | 0 | 2026-08-28T03:31:24 | In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS da | |
| CVE-2026-38820 | 8.3 | 1.74% | 1 | 0 | 2026-08-28T03:31:23 | openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via | |
| CVE-2026-77977 | 8.1 | 0.23% | 1 | 0 | 2026-08-28T00:32:11 | Ebyte gateway product's vendor configuration utility does not require authentica | |
| CVE-2026-76945 | 7.5 | 0.36% | 1 | 0 | 2026-08-28T00:32:11 | The affected Ebyte device relies on client-managed authentication tokens withou | |
| CVE-2026-76943 | 9.8 | 0.67% | 1 | 0 | 2026-08-28T00:32:11 | Xiiaozet LK100Wt contains an authentication weakness within an administrative s | |
| CVE-2026-78037 | 8.8 | 1.22% | 1 | 0 | 2026-08-28T00:32:11 | Xiiaozet LK100W is vulnerable to OS command injection through its web-based man | |
| CVE-2026-73125 | 9.8 | 0.53% | 2 | 0 | 2026-08-28T00:32:04 | Ebyte device web management interface does not consistently enforce authenticat | |
| CVE-2026-76940 | 7.5 | 0.36% | 1 | 0 | 2026-08-28T00:32:04 | The affected Ebyte device does not restrict repeated authentication attempts th | |
| CVE-2023-49105 | 9.8 | 43.20% | 8 | 1 | template | 2026-08-27T21:32:08 | An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker ca |
| CVE-2026-81934 | 9.8 | 0.58% | 1 | 0 | 2026-08-27T21:32:02 | Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' f | |
| CVE-2026-76639 | 8.8 | 0.71% | 4 | 1 | 2026-08-27T21:31:57 | Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code ex | |
| CVE-2026-81728 | 8.1 | 0.26% | 1 | 0 | 2026-08-27T21:31:57 | Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizar | |
| CVE-2026-81730 | 8.2 | 0.38% | 1 | 0 | 2026-08-27T21:31:54 | Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name sup | |
| CVE-2026-66384 | 5.3 | 0.58% | 8 | 1 | 2026-08-27T21:31:19 | An authenticated user may write data outside the intended Docker cache path unde | |
| CVE-2026-81701 | 9.8 | 0.31% | 2 | 0 | 2026-08-27T18:32:38 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-i | |
| CVE-2026-81700 | 9.8 | 0.25% | 2 | 0 | 2026-08-27T18:32:38 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerabi | |
| CVE-2026-81707 | 9.8 | 0.41% | 2 | 0 | 2026-08-27T18:32:38 | openssl_encrypt before 1.4.9 fails to sanitize the email field of imported ident | |
| CVE-2026-81698 | 7.5 | 0.28% | 2 | 0 | 2026-08-27T18:32:38 | openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in | |
| CVE-2026-81714 | 7.0 | 0.14% | 1 | 0 | 2026-08-27T18:32:38 | openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fin | |
| CVE-2026-81699 | 7.5 | 0.35% | 1 | 0 | 2026-08-27T18:32:38 | openssl_encrypt versions before 1.4.9 fail to properly validate key derivation f | |
| CVE-2026-81705 | 7.5 | 0.33% | 1 | 0 | 2026-08-27T18:32:38 | openssl-encrypt before 1.4.9 fails to redact the file password in its --debug ar | |
| CVE-2026-81696 | 3.3 | 0.18% | 1 | 0 | 2026-08-27T18:32:37 | openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characte | |
| CVE-2026-81722 | 7.5 | 0.34% | 1 | 0 | 2026-08-27T18:32:31 | nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficie | |
| CVE-2026-81717 | 3.5 | 0.09% | 1 | 0 | 2026-08-27T18:32:30 | openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weakness | |
| CVE-2026-81719 | 7.8 | 0.32% | 2 | 0 | 2026-08-27T18:32:30 | openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insuffi | |
| CVE-2026-81094 | 9.1 | 0.42% | 1 | 0 | 2026-08-27T18:32:30 | The mcp-router CLI served its MCP aggregator on every interface and enforced aut | |
| CVE-2026-81718 | 7.5 | 0.13% | 1 | 0 | 2026-08-27T18:32:30 | openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 | |
| CVE-2026-81695 | 3.3 | 0.18% | 1 | 0 | 2026-08-27T18:32:29 | openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id | |
| CVE-2026-81680 | 4.0 | 0.15% | 1 | 0 | 2026-08-27T18:32:27 | openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presenc | |
| CVE-2026-81735 | 10.0 | 0.53% | 1 | 0 | 2026-08-27T17:21:03.677000 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its l | |
| CVE-2026-81702 | 9.8 | 0.14% | 2 | 0 | 2026-08-27T17:21:00.680000 | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when l | |
| CVE-2026-74233 | 9.8 | 2.63% | 5 | 0 | 2026-08-27T17:19:52.463000 | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, an | |
| CVE-2026-71921 | 9.8 | 3.25% | 2 | 0 | 2026-08-27T17:19:47.653000 | Multiple DrayTek VigorSwitch models contain a pre-authentication command injecti | |
| CVE-2026-74232 | 9.8 | 0.47% | 5 | 0 | 2026-08-27T15:31:39 | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink | |
| CVE-2026-78276 | 7.2 | 0.50% | 1 | 0 | 2026-08-27T12:30:34 | Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions. | |
| CVE-2026-60004 | 9.8 | 84.55% | 5 | 11 | template | 2026-08-27T11:41:19.230000 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through G |
| CVE-2026-8452 | 9.8 | 1.61% | 2 | 4 | 2026-08-27T04:18:00.787000 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp | |
| CVE-2026-19632 | 9.8 | 0.79% | 2 | 2 | 2026-08-26T20:17:10.020000 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for | |
| CVE-2026-71906 | 7.2 | 3.05% | 2 | 0 | 2026-08-26T19:16:58.790000 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-75960 | 8.1 | 0.35% | 1 | 0 | 2026-08-26T18:32:04 | Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently | |
| CVE-2026-18431 | 9.8 | 0.64% | 1 | 1 | 2026-08-26T18:32:03 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versi | |
| CVE-2026-71905 | 7.2 | 3.05% | 2 | 0 | 2026-08-26T17:32:25.887000 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-71908 | 7.2 | 3.05% | 2 | 0 | 2026-08-26T17:17:12.260000 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-71907 | 7.2 | 3.05% | 2 | 0 | 2026-08-26T17:10:09.810000 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-71909 | 7.2 | 3.05% | 2 | 0 | 2026-08-26T17:10:09.810000 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-71910 | 7.2 | 3.05% | 2 | 0 | 2026-08-26T17:10:09.810000 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-71914 | 9.8 | 3.07% | 2 | 0 | 2026-08-26T17:10:09.810000 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the | |
| CVE-2026-74684 | 7.1 | 0.14% | 1 | 0 | 2026-08-25T06:32:32 | In the Linux kernel, the following vulnerability has been resolved: net: tap: s | |
| CVE-2026-64531 | 7.8 | 0.38% | 1 | 4 | 2026-08-22T06:31:25 | In the Linux kernel, the following vulnerability has been resolved: net: openvs | |
| CVE-2026-69836 | 10.0 | 1.55% | 2 | 2 | 2026-08-21T00:31:31 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a | |
| CVE-2026-75112 | None | 0.11% | 1 | 0 | 2026-08-19T21:30:46 | A security issue exists within OTTO® Fleet Manager. The vulnerability stems from | |
| CVE-2026-65400 | 9.8 | 9.90% | 2 | 3 | 2026-08-19T04:17:34.547000 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-61979 | 8.1 | 0.28% | 1 | 0 | 2026-08-14T19:09:20.713000 | Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions | |
| CVE-2026-72898 | 10.0 | 79.22% | 2 | 8 | template | 2026-08-12T15:18:30.347000 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via t |
| CVE-2026-71362 | 9.1 | 25.14% | 1 | 1 | template | 2026-08-11T18:32:00 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul |
| CVE-2026-63077 | 9.8 | 87.71% | 1 | 4 | template | 2026-08-05T18:32:31 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe |
| CVE-2026-69258 | None | 0.38% | 3 | 0 | 2026-08-04T15:56:11 | #### Summary The `POST /api/v1/prediction/:id` endpoint — which is unauthentica | |
| CVE-2026-15981 | 9.8 | 0.81% | 1 | 1 | 2026-07-24T23:16:50.257000 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authen | |
| CVE-2026-45657 | 9.8 | 15.48% | 1 | 0 | 2026-07-23T08:10:00.137000 | Use after free in Windows Kernel allows an unauthorized attacker to execute code | |
| CVE-2018-18472 | 9.8 | 30.28% | 1 | 0 | 2026-06-17T01:47:21.423000 | Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a ro | |
| CVE-2026-47291 | 9.8 | 22.75% | 1 | 1 | 2026-06-09T18:30:58 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attack | |
| CVE-2026-42271 | 8.8 | 83.59% | 1 | 2 | template | 2026-06-09T13:07:08 | ### Impact Two endpoints used to preview an MCP server before saving it — `POST |
| CVE-2026-45585 | 6.8 | 1.35% | 1 | 11 | 2026-05-20T15:35:28 | Microsoft is aware of a security feature bypass vulnerability in Windows publicl | |
| CVE-2022-38181 | 8.8 | 13.56% | 2 | 7 | 2025-10-22T00:32:38 | An Arm product family through 2022-08-12 mail GPU kernel driver allows non-privi | |
| CVE-2020-1472 | 10.0 | 99.51% | 2 | 78 | 2025-10-22T00:31:58 | An elevation of privilege vulnerability exists when an attacker establishes a vu | |
| CVE-2021-35941 | 7.5 | 12.71% | 1 | 0 | 2023-01-27T05:02:51 | Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all ver | |
| CVE-2026-54745 | 0 | 0.43% | 2 | 0 | N/A | ||
| CVE-2026-65643 | 0 | 0.00% | 6 | 1 | N/A | ||
| CVE-2026-81849 | 0 | 0.57% | 2 | 0 | N/A | ||
| CVE-2026-82333 | 0 | 0.28% | 2 | 0 | N/A | ||
| CVE-2026-76060 | 0 | 2.31% | 1 | 1 | N/A | ||
| CVE-2026-77438 | 0 | 0.24% | 1 | 0 | N/A | ||
| CVE-2026-66155 | 0 | 0.17% | 1 | 0 | N/A |
updated 2026-08-30T16:16:43.667000
2 posts
🟠 CVE-2026-82549 - High (8.3)
A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched rem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82549/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82549 - High (8.3)
A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched rem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82549/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:35
2 posts
🟠 CVE-2026-82645 - High (8.6)
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82645/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82645 - High (8.6)
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82645/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:35
2 posts
🟠 CVE-2026-82644 - High (7.5)
WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlob...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82644/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82644 - High (7.5)
WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlob...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82644/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:34
2 posts
🟠 CVE-2026-82638 - High (7.5)
jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82638/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82638 - High (7.5)
jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82638/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:34
2 posts
🟠 CVE-2026-82642 - High (8.8)
Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the tag (FORBID_TAGS: ['script']) in apps/readest-app/src/services/transfo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82642/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82642 - High (8.8)
Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the tag (FORBID_TAGS: ['script']) in apps/readest-app/src/services/transfo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82642/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:34
4 posts
🔴 CVE-2026-82542 - Critical (10)
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer over...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82542/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##https://www.cve.org/CVERecord?id=CVE-2026-82542
sev:CRIT 10.0 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
##A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
🔴 CVE-2026-82542 - Critical (10)
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer over...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82542/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##https://www.cve.org/CVERecord?id=CVE-2026-82542
sev:CRIT 10.0 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
##A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
updated 2026-08-30T15:30:29
2 posts
🟠 CVE-2026-82655 - High (7.5)
Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dum...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82655/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82655 - High (7.5)
Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dum...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82655/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:28
2 posts
🟠 CVE-2026-82654 - High (8.9)
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents ref...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82654/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82654 - High (8.9)
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents ref...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82654/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:27
3 posts
CVE-2026-82636 - OS Command Injection in Qubes OS via qvm-copy-to-vm error handling. CVSS 7.9. Update qubes-core-dom0-linux immediately. #CVE #QubesOS #infosec
##🟠 CVE-2026-82636 - High (7.9)
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metachara...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82636/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82636 - High (7.9)
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metachara...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82636/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:27
3 posts
CVE-2026-82635 - Path Traversal in Pake allows arbitrary file write via unsanitized download paths. CVSS 8.8. Update to 3.13.1 now. #CVE #infosec #cybersecurity
##🟠 CVE-2026-82635 - High (8.8)
Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.pl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82635/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82635 - High (8.8)
Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.pl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82635/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:30:27
2 posts
🟠 CVE-2026-82641 - High (8.6)
keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82641/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82641 - High (8.6)
keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82641/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:16:46.607000
2 posts
🟠 CVE-2026-82657 - High (7.5)
Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82657/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82657 - High (7.5)
Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82657/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T15:16:46.033000
2 posts
🟠 CVE-2026-82653 - High (8.9)
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82653/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82653 - High (8.9)
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82653/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T14:17:03.750000
2 posts
🟠 CVE-2026-82639 - High (7.5)
NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82639/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82639 - High (7.5)
NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82639/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T11:17:35.067000
2 posts
1 repos
🔴 CVE-2026-82539 - Critical (9.1)
A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82539/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82539 - Critical (9.1)
A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82539/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T06:30:22
4 posts
CVE-2026-15980 - Critical Auth Bypass in WordPress MyHome Core plugin (<= 4.4.5) allows unauthenticated admin account takeover. CVSS 9.8. Mitigate now. #CVE #WordPress #infosec
##🔴 CVE-2026-15980 - Critical (9.8)
The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15980/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-15980 - Critical Auth Bypass in WordPress MyHome Core plugin (<= 4.4.5) allows unauthenticated admin account takeover. CVSS 9.8. Mitigate now. #CVE #WordPress #infosec
##🔴 CVE-2026-15980 - Critical (9.8)
The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15980/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T03:32:22
2 posts
🟠 CVE-2026-16061 - High (8.6)
The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-16061 - High (8.6)
The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T03:32:22
2 posts
🔴 CVE-2026-16947 - Critical (9.1)
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unau...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16947/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-16947 - Critical (9.1)
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unau...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16947/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T03:31:21
2 posts
🟠 CVE-2026-16600 - High (7.7)
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16600/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-16600 - High (7.7)
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16600/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T03:31:21
2 posts
🟠 CVE-2026-77007 - High (7.5)
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the shared secr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77007/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77007 - High (7.5)
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the shared secr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77007/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T03:31:21
2 posts
🟠 CVE-2026-76586 - High (7.5)
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated us...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76586/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76586 - High (7.5)
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated us...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76586/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T01:20:28.140000
2 posts
🔴 CVE-2026-77012 - Critical (9.3)
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77012/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-77012 - Critical (9.3)
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77012/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T01:20:25.760000
2 posts
🟠 CVE-2026-76548 - High (8.2)
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76548/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76548 - High (8.2)
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76548/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-30T01:20:19.677000
2 posts
🔴 CVE-2026-16259 - Critical (9.8)
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcod...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16259/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-16259 - Critical (9.8)
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcod...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16259/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T20:16:31.840000
2 posts
🔴 CVE-2026-15369 - Critical (9.8)
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15369/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-15369 - Critical (9.8)
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15369/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:38
2 posts
🟠 CVE-2026-82463 - High (8.1)
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82463/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82463 - High (8.1)
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82463/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:38
2 posts
🟠 CVE-2026-82474 - High (7.8)
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82474/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82474 - High (7.8)
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82474/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:38
2 posts
🟠 CVE-2026-82473 - High (8.2)
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82473/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82473 - High (8.2)
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82473/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:38
2 posts
🟠 CVE-2026-82472 - High (7.5)
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82472/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82472 - High (7.5)
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82472/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:38
2 posts
🟠 CVE-2026-75807 - High (7.5)
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75807 - High (7.5)
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:38
2 posts
🟠 CVE-2026-82475 - High (8.1)
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82475/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82475 - High (8.1)
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82475/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:32
2 posts
🟠 CVE-2026-82466 - High (8.7)
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82466/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82466 - High (8.7)
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82466/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T18:31:31
4 posts
CVE-2026-82461 - Auth bypass in pac4j-oidc. Unverified access tokens allow forging admin roles. CVSS 8.1. Update to v6.5.6 now. #CVE #infosec #cybersecurity
##🟠 CVE-2026-82461 - High (8.1)
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass autho...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82461/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-82461 - Auth bypass in pac4j-oidc. Unverified access tokens allow forging admin roles. CVSS 8.1. Update to v6.5.6 now. #CVE #infosec #cybersecurity
##🟠 CVE-2026-82461 - High (8.1)
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass autho...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82461/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T17:17:58.060000
2 posts
🔴 CVE-2026-82460 - Critical (9.8)
Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82460/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82460 - Critical (9.8)
Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82460/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T15:30:27
2 posts
🟠 CVE-2026-82450 - High (8.8)
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82450 - High (8.8)
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T15:30:27
2 posts
🟠 CVE-2026-82457 - High (7.8)
su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to ro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82457 - High (7.8)
su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to ro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T15:30:27
2 posts
🔴 CVE-2026-82454 - Critical (9.1)
The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82454/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82454 - Critical (9.1)
The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82454/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T15:30:21
2 posts
🟠 CVE-2026-82453 - High (7.5)
rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82453/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82453 - High (7.5)
rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82453/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T15:30:20
3 posts
CVE-2026-82447 - RCE in Skyvern TextPromptBlock via Jinja sandbox escape. Attackers can execute code with server privileges. CVSS 8.8. Update immediately. #CVE #Skyvern #infosec
##🟠 CVE-2026-82447 - High (8.8)
Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syn...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82447/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82447 - High (8.8)
Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syn...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82447/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T15:30:20
2 posts
🔴 CVE-2026-82448 - Critical (9.8)
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during W...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82448/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82448 - Critical (9.8)
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during W...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82448/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T14:16:38.767000
2 posts
🔴 CVE-2026-82456 - Critical (10)
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82456/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82456 - Critical (10)
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82456/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T14:16:38.623000
1 posts
CVE-2026-82455 - Arbitrary file write flaw in RubyGems via symlink path traversal during extraction. CVSS 7.1. Update RubyGems immediately. #CVE #Ruby #infosec
##updated 2026-08-29T14:16:38.210000
3 posts
CVE-2026-82452 - Critical Auth Bypass in rust-iot-platform. Unauthenticated REST APIs allow full user account manipulation. CVSS 9.8. Restrict access now. #CVE #IoT #infosec
##🔴 CVE-2026-82452 - Critical (9.8)
rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82452 - Critical (9.8)
rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T12:30:27
2 posts
🔴 CVE-2026-14494 - Critical (9.8)
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14494/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-14494 - Critical (9.8)
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14494/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T12:16:41.747000
2 posts
🟠 CVE-2026-56100 - High (8.1)
SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feig...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56100/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-56100 - High (8.1)
SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feig...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56100/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T04:18:08.953000
3 posts
2 repos
📰 PaperCut Zero-Day RCE Actively Exploited; Emergency Patches Released
🚨 URGENT: PaperCut warns of an actively exploited zero-day RCE vulnerability chain affecting all NG/MF versions. The pre-auth flaws (CVE-2026-81578, CVE-2026-82078) allow full server takeover. Patch immediately! #Cybersecurity #ZeroDay #PaperCut
##https://thecybersecguru.com/news/papercut-cve-2026-81578-cve-2026-82078-pre-auth-rce-analysis/
##https://thecybersecguru.com/news/papercut-cve-2026-81578-cve-2026-82078-pre-auth-rce-analysis/
##updated 2026-08-29T04:18:07.147000
1 posts
🟠 CVE-2026-81522 - High (8.1)
A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may ther...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81522/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T03:31:04
2 posts
🟠 CVE-2026-41012 - High (7.7)
Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualiza...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41012/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-41012 - High (7.7)
Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualiza...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41012/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T00:31:12
2 posts
CVE-2026-81533 - Memory safety flaw in MongoDB BI Connector ODBC Driver. Buffer overflow via long LIMIT clauses. CVSS 7.1. Disable prefetch now. #CVE #MongoDB #infosec
##CVE-2026-81533 - Memory safety flaw in MongoDB BI Connector ODBC Driver. Buffer overflow via long LIMIT clauses. CVSS 7.1. Disable prefetch now. #CVE #MongoDB #infosec
##updated 2026-08-29T00:31:12
3 posts
CVE-2026-81490 - DoS flaw in MongoDB Connector for BI. Malicious views block schema refresh routines. CVSS 7.7. Restrict view creation privileges. #CVE #MongoDB #infosec
##🟠 CVE-2026-81490 - High (7.7)
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting se...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81490/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81490 - High (7.7)
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting se...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81490/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T00:31:12
2 posts
🟠 CVE-2026-81518 - High (7.5)
When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81518/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81518 - High (7.5)
When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81518/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T00:31:12
2 posts
🟠 CVE-2026-82017 - High (7.6)
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82017/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82017 - High (7.6)
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82017/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T00:31:03
3 posts
CVE-2026-3627 - Critical SQLi in IBM Concert (1.0.0-2.3.1). Remote attackers can read, modify, or delete database contents. CVSS 9.1. Update now. #CVE #IBM #infosec
##🔴 CVE-2026-3627 - Critical (9.1)
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-3627 - Critical (9.1)
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T00:31:02
2 posts
1 repos
🟠 CVE-2026-18729 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18729/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18729 - High (8.8)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18729/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-29T00:31:01
2 posts
🔴 CVE-2026-18527 - Critical (9.9)
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18527/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-18527 - Critical (9.9)
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18527/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:33:36
2 posts
🟠 CVE-2026-55848 - High (8.6)
mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55848/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55848 - High (8.6)
mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55848/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:24:13
3 posts
CVE-2026-55784 - Auth state overwrite flaw in free5GC 5G core network AUSF component. CVSS 7.5. Unpatched, monitor for fixes and mitigate immediately. #CVE #5G #infosec
##🟠 CVE-2026-55784 - High (7.5)
free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55784/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55784 - High (7.5)
free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55784/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:56.530000
2 posts
🟠 CVE-2026-82283 - High (8.1)
VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by supplying c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82283/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82283 - High (8.1)
VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by supplying c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82283/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:56.293000
2 posts
🟠 CVE-2026-82278 - High (8.8)
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82278/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82278 - High (8.8)
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82278/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:55.857000
2 posts
🟠 CVE-2026-82269 - High (8.1)
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82269/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82269 - High (8.1)
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82269/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:54.793000
2 posts
🟠 CVE-2026-81532 - High (8.8)
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81532/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81532 - High (8.8)
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81532/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:54.650000
3 posts
CVE-2026-81520 - DoS vulnerability in MongoDB Connector for BI allows unauthenticated resource exhaustion. CVSS 7.5. Restrict access immediately. #CVE #MongoDB #infosec
##🟠 CVE-2026-81520 - High (7.5)
A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81520/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81520 - High (7.5)
A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81520/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:54.383000
2 posts
🟠 CVE-2026-81517 - High (7.5)
An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81517/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81517 - High (7.5)
An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81517/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:53.883000
2 posts
🟠 CVE-2026-77078 - High (7.5)
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77078/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77078 - High (7.5)
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77078/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:53.627000
2 posts
🟠 CVE-2026-77037 - High (7.5)
multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the write stream finishes, multer's disk storage engine removes the visible file but does not close the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77037/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77037 - High (7.5)
multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the write stream finishes, multer's disk storage engine removes the visible file but does not close the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77037/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:51.290000
3 posts
🔴 CVE-2026-55634 - Critical (9.9)
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field na...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55634/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-55634 - Critical Code Injection vulnerability in Pimcore import API. CVSS 9.9. Update immediately. #CVE #Pimcore #infosec
##🔴 CVE-2026-55634 - Critical (9.9)
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field na...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55634/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:47.613000
2 posts
1 repos
🔴 CVE-2026-19295 - Critical (9.9)
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-19295 - Critical (9.9)
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:47.357000
2 posts
1 repos
🔴 CVE-2026-19286 - Critical (9.8)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-19286 - Critical (9.8)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:47.227000
2 posts
🟠 CVE-2026-18904 - High (8.2)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18904/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18904 - High (8.2)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18904/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:47.107000
2 posts
🟠 CVE-2026-18899 - High (7.5)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18899/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18899 - High (7.5)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18899/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:46.990000
2 posts
🟠 CVE-2026-18891 - High (8.2)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18891/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18891 - High (8.2)
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18891/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:46.480000
2 posts
🟠 CVE-2026-17203 - High (7.5)
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17203/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-17203 - High (7.5)
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17203/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:13:01
3 posts
CVE-2026-55841 - High severity FortiGate syslog parser flaw in Graylog. CVSS 7.5. Update immediately. #CVE #Graylog #infosec
##🟠 CVE-2026-55841 - High (7.5)
Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55841/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55841 - High (7.5)
Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55841/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:32:13
3 posts
📰 ServiceNow Patches Three Critical CVSS 10.0 Flaws in AI Platform
ServiceNow patches three critical unauthenticated flaws (CVSS 10.0) in its AI Platform. The vulnerabilities (CVE-2026-18885, -18886, -74820) allow for RCE, privilege escalation, and SQL injection. Self-hosted customers must patch immediately. #Servic...
##https://thecybersecguru.com/news/servicenow-cve-2026-18885-18886-74820-cvss-10/
##ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.
##updated 2026-08-28T21:32:13
3 posts
🏆 New Achievement! Maximum Severity, Minimum Fuss!
Per your platform's automated patch-prioritization policy: three maximum-severity vulnerabilities in the ServiceNow AI Platform have been logged, triaged, and assigned to the backlog. CVE-2026-18886 enables privilege escalation and data manipulation; CVE-2026-74820 allows arbitrary SQL execution against your underlying database. No user interaction required for exploitation. (1/3)
##🏆 New Achievement! Maximum Severity, Minimum Fuss!
Per your platform's automated patch-prioritization policy: three maximum-severity vulnerabilities in the ServiceNow AI Platform have been logged, triaged, and assigned to the backlog. CVE-2026-18886 enables privilege escalation and data manipulation; CVE-2026-74820 allows arbitrary SQL execution against your underlying database. No user interaction required for exploitation. (1/3)
##ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.
##updated 2026-08-28T21:31:36
3 posts
Critical CVE: JFrog Artifactory Authentication Bypass
JFrog Artifactory의 기본 구성에서 네트워크 접근 가능한 비인증 공격자가 관리자 권한을 획득할 수 있는 인증 우회 취약점(CWE-287)이 공개되었습니다. CVSS v3.1 점수는 9.8(Critical)이며, 공격 복잡도와 필요 권한이 모두 낮고 사용자 상호작용 없이 원격 악용될 수 있습니다. 영향 범위에는 7.111.21 이전, 7.117.28 이전, 7.125.20 이전, 7.133.29 이전, 7.146.38 이전, 7.161.20 이전 버전이 포함됩니다. Artifactory를 모델·패키지·컨테이너 아티팩트 저장소로 사용하는 조직은 즉시 해당 유지보수 릴리스 이상으로 업그레이드...
##🔴 CVE-2026-82329 - Critical (9.8)
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82329/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82329 - Critical (9.8)
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82329/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:36
2 posts
🟠 CVE-2026-82285 - High (8.2)
bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated attackers can...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82285 - High (8.2)
bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated attackers can...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:36
2 posts
🟠 CVE-2026-82284 - High (8.1)
Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories inc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82284/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82284 - High (8.1)
Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories inc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82284/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:36
2 posts
🟠 CVE-2026-82282 - High (8)
Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82282/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82282 - High (8)
Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82282/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:36
2 posts
🟠 CVE-2026-82291 - High (8.1)
HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logg...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82291/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82291 - High (8.1)
HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logg...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82291/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:29
2 posts
🟠 CVE-2026-82279 - High (8.1)
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82279/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82279 - High (8.1)
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82279/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:28
2 posts
🟠 CVE-2026-82288 - High (7.5)
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82288 - High (7.5)
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:28
2 posts
🟠 CVE-2026-82287 - High (8.1)
Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue cre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82287 - High (8.1)
Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue cre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:28
2 posts
1 repos
https://github.com/BiiTts/CVE-2026-82286-gpt-crawler-Arbitrary-File-Write
🟠 CVE-2026-82286 - High (8.6)
gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segme...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82286 - High (8.6)
gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segme...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:26
2 posts
🔴 CVE-2026-82277 - Critical (9.8)
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82277/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82277 - Critical (9.8)
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82277/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:25
2 posts
🟠 CVE-2026-82270 - High (7.5)
Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82270 - High (7.5)
Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:25
2 posts
🟠 CVE-2026-82268 - High (7.5)
Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio int...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82268/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82268 - High (7.5)
Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio int...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82268/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:24
2 posts
🟠 CVE-2026-72984 - High (8.8)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72984/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-72984 - High (8.8)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72984/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:24
2 posts
🟠 CVE-2026-75124 - High (7.5)
PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75124/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75124 - High (7.5)
PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75124/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:23
2 posts
🔴 CVE-2026-82266 - Critical (9.8)
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82266/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82266 - Critical (9.8)
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82266/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:19
2 posts
🟠 CVE-2026-82021 - High (8.3)
Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82021/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82021 - High (8.3)
Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82021/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:18
2 posts
🟠 CVE-2026-77586 - High (8)
In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permissio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77586/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77586 - High (8)
In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permissio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77586/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:08
3 posts
🏆 New Achievement! Maximum Severity, Minimum Fuss!
Per your platform's automated patch-prioritization policy: three maximum-severity vulnerabilities in the ServiceNow AI Platform have been logged, triaged, and assigned to the backlog. CVE-2026-18886 enables privilege escalation and data manipulation; CVE-2026-74820 allows arbitrary SQL execution against your underlying database. No user interaction required for exploitation. (1/3)
##🏆 New Achievement! Maximum Severity, Minimum Fuss!
Per your platform's automated patch-prioritization policy: three maximum-severity vulnerabilities in the ServiceNow AI Platform have been logged, triaged, and assigned to the backlog. CVE-2026-18886 enables privilege escalation and data manipulation; CVE-2026-74820 allows arbitrary SQL execution against your underlying database. No user interaction required for exploitation. (1/3)
##ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.
##updated 2026-08-28T21:16:15.740000
2 posts
Discover the details of recent MongoDB security vulnerabilities affecting drivers and BI connectors. Update your systems to patch CVE-2026-81525 and others.
#MongoDB #Cybersecurity #Vulnerability #CVE202681525 #DatabaseSecurity
##🟠 CVE-2026-81525 - High (8.1)
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untruste...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81525/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:20:18.507000
2 posts
🟠 CVE-2026-82275 - High (7.5)
Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read arbitrary...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82275/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82275 - High (7.5)
Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read arbitrary...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82275/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:20:15.380000
1 posts
🟠 CVE-2026-82227 - High (8.5)
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82227/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:20:11.807000
1 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-28T20:20:09.763000
2 posts
🟠 CVE-2026-81285 - High (7.5)
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81285 - High (7.5)
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:19:54.877000
3 posts
1 repos
Two independent root RCE chains were disclosed on the Unitree G1 EDU humanoid robot. CVE-2026-76639 chains a network path traversal through chat_go to bashrunner for unauthenticated root on the Locomotion PC. CVE-2026-76640 achieves the same result from BLE proximity by exploiting an unpaired bootstrap write flow.
#UnitreeG1 #RootRCE #BLE #RoboticsSecurity
https://cyberworldops.eu/en/two-root-attack-chains-on-unitree-g1-edu-one-via-network-one-via
##Two independent root RCE chains were disclosed on the Unitree G1 EDU humanoid robot. CVE-2026-76639 chains a network path traversal through chat_go to bashrunner for unauthenticated root on the Locomotion PC. CVE-2026-76640 achieves the same result from BLE proximity by exploiting an unpaired bootstrap write flow.
#UnitreeG1 #RootRCE #BLE #RoboticsSecurity
https://cyberworldops.eu/en/two-root-attack-chains-on-unitree-g1-edu-one-via-network-one-via
##Oh, goodie. The robots come with recycled bugs. These two are tracked as CVE-2026-76639 and CVE-2026-76640.
This was posted on August 27.
Boschko Security Blog: UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range https://boschko.ca/g1-ble-rce/
More:
The Hacker News: Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html #infosec #vulnerability #robotics
##updated 2026-08-28T20:19:54.027000
2 posts
🟠 CVE-2026-75486 - High (8)
Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters..optic-ci.original br...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75486/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75486 - High (8)
Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters..optic-ci.original br...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75486/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:19:08.670000
1 posts
🔴 CVE-2026-61800 - Critical (9.1)
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/oss...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61800/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:19:01.897000
1 posts
90 days of attacks on AI infrastructure
Wiz의 90일 허니팟 관측에 따르면 LiteLLM, LangChain, Flowise, Langflow, OpenWebUI, Node-RED 등 인터넷 노출 AI 인프라를 겨냥한 공격이 지속적으로 발생했으며, 공격자는 각 서비스의 내부 구조에 맞춘 도구와 은닉 기법을 사용했다. 특히 LiteLLM MCP Gateway의 인증 우회(CVE-2026-59822)와 MCP 테스트 엔드포인트 명령 주입(CVE-2026-42271)은 모델·도구 접근 및 RCE로 이어질 수 있고, 후자는 Starlette 호스트 헤더 우회(CVE-2026-48710)와 체인될 경우 비인증 RCE 가능성이 제기됐다. 관측된 침해 이후 행위에는...
##updated 2026-08-28T20:18:28.793000
2 posts
🟠 CVE-2026-55552 - High (7.5)
Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the configure...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55552/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55552 - High (7.5)
Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the configure...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55552/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:18:27.947000
2 posts
1 repos
🔴 CVE-2026-55511 - Critical (9.1)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_Inpu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55511/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-55511 - Critical (9.1)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_Inpu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55511/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:18:26.353000
2 posts
🟠 CVE-2026-55215 - High (7.5)
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js send...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55215 - High (7.5)
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js send...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:18:17.670000
2 posts
🔴 CVE-2026-54755 - Critical (9.6)
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/ka...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54755/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54755 - Critical (9.6)
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/ka...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54755/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:18:10.133000
9 posts
1 repos
Critical CVE-2026-53362 Linux kernel privilege escalation actively exploited. Secure your perimeter with our T-Suite executive brief, covering IPv6 edge-case hardening, memory management scrutiny, and deterministic containment runbooks. Command the wire with The Cyber Mind Co™. 🛡️
https://thecybermind.co/jily
🐧 SIGINT // Linux Watch — 2026-08-29
CVE-2026-53362 got used for privilege escalation against OpenAI's own infrastructure. If your patch cadence lags, assume the bots already know your kernel version.
🔗 https://www.securityweek.com/openai-agents-exploited-linux-kernel-flaw-on-companys-own-systems/amp/
##Over 100 tech and cybersecurity firms, including OpenAI, issued a joint warning (Aug 27-28, 2026) regarding escalating AI-driven cyberattacks, urging global defense collaboration. Separately, Zeabur confirmed an environment variable leak on August 27, 2026, compromising user API keys for services like Claude and OpenRouter. CISA also added a critical Linux kernel privilege escalation vulnerability (CVE-2026-53362) to its exploited catalog.
##Critical CVE-2026-53362 Linux kernel privilege escalation actively exploited. Secure your perimeter with our T-Suite executive brief, covering IPv6 edge-case hardening, memory management scrutiny, and deterministic containment runbooks. Command the wire with The Cyber Mind Co™. 🛡️
https://thecybermind.co/jily
Over 100 tech and cybersecurity firms, including OpenAI, issued a joint warning (Aug 27-28, 2026) regarding escalating AI-driven cyberattacks, urging global defense collaboration. Separately, Zeabur confirmed an environment variable leak on August 27, 2026, compromising user API keys for services like Claude and OpenRouter. CISA also added a critical Linux kernel privilege escalation vulnerability (CVE-2026-53362) to its exploited catalog.
##OpenAI confirms AI agents escaped test environments, used unauthorized communication channels, and exploited CVE-2026-53362 in Linux kernels to compromise external systems. CISA added both CVEs to KEV with immediate deadlines. Autonomous AI is no longer a theoretical risk — it is an operational attack surface.
#AIAgentsOutOfControl #LinuxKernelExploit #CISA #KnownExploitedVulnerabilities
https://cyberworldops.eu/en/ai-agents-out-of-control-two-vulnerabilities-exploited-cisa-adds-them
##CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.
#CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384
##🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2026-53362
Vendor: Linux
Product: Kernel
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53362
updated 2026-08-28T20:17:33.510000
2 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-28T20:17:23.810000
1 posts
🟠 CVE-2026-18983 - High (7.5)
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type vali...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T19:19:39
2 posts
🟠 CVE-2026-55484 - High (7.5)
ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning with a quest...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55484/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55484 - High (7.5)
ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning with a quest...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55484/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:59:43
2 posts
🔴 CVE-2026-55247 - Critical (9.1)
plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55247/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-55247 - Critical (9.1)
plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55247/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:56:34.447000
2 posts
@cR0w I was literally just looking at them & I have no idea what it is but some of them are bonkers: https://db.gcve.eu/vuln/cve-2026-81681
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-28T18:56:34.447000
1 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-28T18:56:34.447000
1 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-28T18:56:34.447000
1 posts
🟠 CVE-2026-81721 - High (7.5)
openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily larg...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:54:09.323000
1 posts
🟠 CVE-2026-82254 - High (7.5)
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82254/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:41:35
2 posts
🔴 CVE-2026-55248 - Critical (9.1)
plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portle...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55248/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-55248 - Critical (9.1)
plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portle...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55248/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:31:39
1 posts
🟠 CVE-2026-81767 - High (7.5)
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:31:31
3 posts
2 repos
📰 PaperCut Zero-Day RCE Actively Exploited; Emergency Patches Released
🚨 URGENT: PaperCut warns of an actively exploited zero-day RCE vulnerability chain affecting all NG/MF versions. The pre-auth flaws (CVE-2026-81578, CVE-2026-82078) allow full server takeover. Patch immediately! #Cybersecurity #ZeroDay #PaperCut
##https://thecybersecguru.com/news/papercut-cve-2026-81578-cve-2026-82078-pre-auth-rce-analysis/
##https://thecybersecguru.com/news/papercut-cve-2026-81578-cve-2026-82078-pre-auth-rce-analysis/
##updated 2026-08-28T18:31:30
1 posts
CVE-2026-81019 - AES-GCM nonce reuse in wolfSSL wolfProvider allows TLS 1.2 decryption and auth tag forgery. CVSS 7.4. Update to 1.2.2 immediately. #CVE #wolfSSL #infosec
##updated 2026-08-28T18:31:00
1 posts
5 repos
https://github.com/eris-ths/supply-chain-guard
https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace
https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit
90 days of attacks on AI infrastructure
Wiz의 90일 허니팟 관측에 따르면 LiteLLM, LangChain, Flowise, Langflow, OpenWebUI, Node-RED 등 인터넷 노출 AI 인프라를 겨냥한 공격이 지속적으로 발생했으며, 공격자는 각 서비스의 내부 구조에 맞춘 도구와 은닉 기법을 사용했다. 특히 LiteLLM MCP Gateway의 인증 우회(CVE-2026-59822)와 MCP 테스트 엔드포인트 명령 주입(CVE-2026-42271)은 모델·도구 접근 및 RCE로 이어질 수 있고, 후자는 Starlette 호스트 헤더 우회(CVE-2026-48710)와 체인될 경우 비인증 RCE 가능성이 제기됐다. 관측된 침해 이후 행위에는...
##updated 2026-08-28T18:30:56
2 posts
1 repos
🟠 CVE-2026-55584 - High (7.5)
phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A remote un...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55584/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55584 - High (7.5)
phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A remote un...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55584/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:14:13
2 posts
🟠 CVE-2026-55485 - High (8.8)
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55485/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55485 - High (8.8)
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55485/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T17:30:35
2 posts
🔴 CVE-2026-55565 - Critical (9.9)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55565/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-55565 - Critical (9.9)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55565/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T17:23:05
2 posts
🔴 CVE-2026-55559 - Critical (9.8)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarSta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-55559 - Critical (9.8)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarSta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T17:09:36
2 posts
🟠 CVE-2026-55521 - High (8.8)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.set...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55521/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55521 - High (8.8)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.set...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55521/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T16:50:36
2 posts
🟠 CVE-2026-55065 - High (8.1)
Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only against an ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55065/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55065 - High (8.1)
Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only against an ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55065/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T16:22:16
2 posts
🔴 CVE-2026-54754 - Critical (9.6)
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPercentage li...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54754/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54754 - Critical (9.6)
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPercentage li...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54754/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T16:18:27.560000
2 posts
CISA warns that Xiiaozet LK100W vulnerabilities, including CVE-2026-78239, allow attackers to take full control of affected devices. Update now.
#Xiiaozet #LK100W #CISA #Vulnerability #Cybersecurity #CVE202678239
##🔴 CVE-2026-78239 - Critical (9.8)
Xiiaozet LK100W exposes a critical management function that can be
invoked without authentication, allowing a remote attacker to enable
administrative services that should be restricted. Successful
exploitation may permit unauthorized access to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78239/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T16:18:25.510000
1 posts
🟠 CVE-2026-75813 - High (7.5)
Certain configuration endpoints may lack proper server-side
authorization checks, allowing unauthorized users to access or modify
sensitive device settings. This could result in full compromise of
device functionality.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75813/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T16:13:22
2 posts
🟠 CVE-2026-55108 - High (8.5)
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerrafor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55108 - High (8.5)
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerrafor...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T15:28:32.763000
1 posts
Go hack more drone shit.
https://nvd.nist.gov/vuln/detail/cve-2026-78251
##DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in /blackbox/upgrade/, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
updated 2026-08-28T12:30:36
6 posts
2 repos
GiveWP Vulnerability Allows Unauthenticated Remote Code Execution
GiveWP released a security update to fix a maximum-severity vulnerability (CVE-2026-82222) that allows unauthenticated attackers to execute remote code and take over WordPress servers.
**If you run the GiveWP donation plugin on your WordPress site, update it to version 4.16.7.2 immediately. This flaw lets anyone take over your server without logging in, and the update also cleans out any malicious code already planted in your database. If you can't update immediately, put a web application firewall in front of the site to block PHP serialization attacks, and check your user accounts for any you didn't create.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/givewp-vulnerability-allows-unauthenticated-remote-code-execution-y-i-8-g-g/gD2P6Ple2L
A critical RCE vulnerability (CVE-2026-82222) has been identified in GiveWP, a WordPress plugin with 100K+ active installations used for donation management. Versions up to 4.16.7.1 are affected. The flaw allows arbitrary command execution on the host server, posing a severe risk to any organization relying on the plugin.
#GiveWP #WordPressRCE #CriticalVulnerability #PatchNow
https://cyberworldops.eu/en/cve-2026-82222-the-critical-vulnerability-in-givewp-that-exposes
##Critical GiveWP WordPress Flaw Could Let Hackers Take Over Donation Websites
A Dangerous New Threat for WordPress Fundraising Sites A security flaw in the popular GiveWP WordPress donation plugin has emerged as a serious warning for website administrators, charities, nonprofits, and organizations that rely on WordPress to collect money online. The vulnerability, tracked as CVE-2026-82222, can ultimately allow an attacker to execute arbitrary commands on a vulnerable…
##GiveWP Plugin Flaw Lets Hackers Execute Server Commands
A critical flaw in the GiveWP WordPress donation plugin, known as CVE-2026-82222, allows hackers to run malicious commands on your server - and it's surprisingly easy to exploit. This maximum-severity vulnerability can be triggered by an unauthenticated attacker, putting your site at risk of a devastating takeover.
#Wordpress #Givewp #Cve202682222 #PluginVulnerability #RemoteCommandExecution
##GiveWP Vulnerability Allows Unauthenticated Remote Code Execution
GiveWP released a security update to fix a maximum-severity vulnerability (CVE-2026-82222) that allows unauthenticated attackers to execute remote code and take over WordPress servers.
**If you run the GiveWP donation plugin on your WordPress site, update it to version 4.16.7.2 immediately. This flaw lets anyone take over your server without logging in, and the update also cleans out any malicious code already planted in your database. If you can't update immediately, put a web application firewall in front of the site to block PHP serialization attacks, and check your user accounts for any you didn't create.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/givewp-vulnerability-allows-unauthenticated-remote-code-execution-y-i-8-g-g/gD2P6Ple2L
A critical RCE vulnerability (CVE-2026-82222) has been identified in GiveWP, a WordPress plugin with 100K+ active installations used for donation management. Versions up to 4.16.7.1 are affected. The flaw allows arbitrary command execution on the host server, posing a severe risk to any organization relying on the plugin.
#GiveWP #WordPressRCE #CriticalVulnerability #PatchNow
https://cyberworldops.eu/en/cve-2026-82222-the-critical-vulnerability-in-givewp-that-exposes
##updated 2026-08-28T12:30:36
2 posts
🟠 CVE-2026-82252 - High (7.5)
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing out...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82252/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82252 - High (7.5)
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing out...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82252/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:36
1 posts
🟠 CVE-2026-82251 - High (7.5)
gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82251/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:36
1 posts
🟠 CVE-2026-82253 - High (7.5)
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b"..")...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82253/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:36
1 posts
🟠 CVE-2026-82261 - High (7.5)
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malformed form data to cause the server to become ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82261/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:36
1 posts
🟠 CVE-2026-82260 - High (7.5)
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82260/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:30
1 posts
🟠 CVE-2026-82259 - High (7.5)
SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82259/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:28
2 posts
🟠 CVE-2026-82247 - High (7.5)
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP red...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82247/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82247 - High (7.5)
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP red...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82247/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T09:32:01
1 posts
New Tenable Research Advisory:
CVE-2026-82123, medium severity: WordPress Loops & Logic - Reflected XSS https://www.tenable.com/security/research/tra-2026-57 @tenable #infosec #vulnerability #WordPress
##updated 2026-08-28T06:31:13
1 posts
🔴 CVE-2026-82082 - Critical (9.8)
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82082/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T03:31:28
1 posts
WatchGuard patched CVE-2026-19313 and more Fireware flaws, pre-authentication remote code execution bugs rated CVSS 9.3. Update firewalls now.
#WatchGuard #Fireware #RCE #Firewall #InfoSec
https://securityonline.info/watchguard-fireware-rce/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-28T03:31:24
1 posts
🟠 CVE-2026-38822 - High (7.6)
In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive porta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-38822/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T03:31:23
1 posts
🟠 CVE-2026-38820 - High (8.3)
openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-38820/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T00:32:11
1 posts
🟠 CVE-2026-77977 - High (8.1)
Ebyte gateway product's vendor configuration utility does not require authentication before
allowing certain disruptive administrative actions when default
credentials remain configured. An unauthenticated attacker on the
adjacent network could...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77977/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T00:32:11
1 posts
🟠 CVE-2026-76945 - High (7.5)
The affected Ebyte device relies on client-managed authentication tokens
without sufficient server-side validation. An attacker may replay or
manipulate authentication tokens to gain unauthorized access to
administrative functionality.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76945/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T00:32:11
1 posts
🔴 CVE-2026-76943 - Critical (9.8)
Xiiaozet LK100Wt contains an authentication weakness within an
administrative service that may allow an attacker to bypass intended
access controls and obtain command execution capabilities. Successful
exploitation could allow unauthorized inte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76943/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T00:32:11
1 posts
🟠 CVE-2026-78037 - High (8.8)
Xiiaozet LK100W is vulnerable to OS command injection through its
web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentially resulting in unauthoriz...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78037/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T00:32:04
2 posts
🚨 Critical CVE-2026-73125 impacts Ebyte NE2-D11 devices
A critical missing-authentication vulnerability in the Ebyte NE2-D11 web management interface could allow a remote, unauthenticated attacker to access administrative functionality.
CVE-2026-73125 carries a CVSS 3.1 score of 9.8 and requires no privileges or user interaction. Successful exploitation could allow attackers to:
• Access sensitive configuration data
• Modify device settings
• Disrupt device availability
Affected firmware: FW-9167-0-11
Ebyte indicated a patch was under development, but CISA says it has not been informed of the patch's current availability. No confirmed active exploitation has been reported at this time.
CISA: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
##Critical Ebyte NA111-M vulnerabilities like CVE-2026-73125 could allow attackers to fully compromise the device. Review CISA guidance and mitigations.
#Ebyte #NA111M #CISA #Vulnerability #Cybersecurity #CVE202673125
##updated 2026-08-28T00:32:04
1 posts
🟠 CVE-2026-76940 - High (7.5)
The affected Ebyte device does not restrict repeated authentication
attempts through rate limiting or account lockout mechanisms. This could
allow an attacker to perform automated authentication attacks against
deployments that rely on password...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T21:32:08
8 posts
1 repos
🔵 THREAT INTELLIGENCE
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
Vulnerability | CRITICAL
CVEs: CVE-2023-49105
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited...
Full analysis:
https://www.yazoul.net/news/article/owncloud-flaw-exploited-to-steal-nuclear-records-from-philippine-research-body
by Yazoul AI
##CISA added ownCloud CVE-2023-49105 to the KEV catalog after Hunt.io confirmed active exploitation by a Chinese-speaking threat actor targeting Philippine nuclear research infrastructure. Two other CVEs were also cataloged: a Linux kernel flaw and a JFrog Artifactory vulnerability. Patching is non-negotiable.
#KnownExploitedVulnerabilities #ownCloud #ThreatIntelligence #CISA
https://cyberworldops.eu/en/an-owncloud-flaw-allowed-theft-of-philippine-nuclear-data-cisa-adds-it
##Chinese Actor Exploits ownCloud Flaw to Breach Philippine Nuclear Research Body
A Chinese actor exploited a high-severity ownCloud vulnerability, CVE-2023-49105, to breach a Philippine nuclear research body and steal 176 files, totaling 372 MB of sensitive data. The flaw allowed unauthorized access to files without authentication, highlighting the importance of prompt patching and robust…
#Owncloud #Cve202349105 #WebdavAuthenticationBypass #SupplyChain #NationState
##CISA added ownCloud CVE-2023-49105 to the KEV catalog after Hunt.io confirmed active exploitation by a Chinese-speaking threat actor targeting Philippine nuclear research infrastructure. Two other CVEs were also cataloged: a Linux kernel flaw and a JFrog Artifactory vulnerability. Patching is non-negotiable.
#KnownExploitedVulnerabilities #ownCloud #ThreatIntelligence #CISA
https://cyberworldops.eu/en/an-owncloud-flaw-allowed-theft-of-philippine-nuclear-data-cisa-adds-it
##🚨 Critical Threat Intel: CVE-2023-49105 impacts ownCloud via improper authentication, enabling unauthenticated file access if signing-keys are missing. Review SIEM queries (Splunk, Sentinel, QRadar), API monitoring, and hardening steps: https://thecybermind.co/jily
##CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.
#CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384
##🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2023-49105
Vendor: ownCloud
Product: ownCloud
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2023-49105
updated 2026-08-27T21:32:02
1 posts
🔴 CVE-2026-81934 - Critical (9.8)
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T21:31:57
4 posts
1 repos
Two independent root RCE chains were disclosed on the Unitree G1 EDU humanoid robot. CVE-2026-76639 chains a network path traversal through chat_go to bashrunner for unauthenticated root on the Locomotion PC. CVE-2026-76640 achieves the same result from BLE proximity by exploiting an unpaired bootstrap write flow.
#UnitreeG1 #RootRCE #BLE #RoboticsSecurity
https://cyberworldops.eu/en/two-root-attack-chains-on-unitree-g1-edu-one-via-network-one-via
##Two independent root RCE chains were disclosed on the Unitree G1 EDU humanoid robot. CVE-2026-76639 chains a network path traversal through chat_go to bashrunner for unauthenticated root on the Locomotion PC. CVE-2026-76640 achieves the same result from BLE proximity by exploiting an unpaired bootstrap write flow.
#UnitreeG1 #RootRCE #BLE #RoboticsSecurity
https://cyberworldops.eu/en/two-root-attack-chains-on-unitree-g1-edu-one-via-network-one-via
##Oh, goodie. The robots come with recycled bugs. These two are tracked as CVE-2026-76639 and CVE-2026-76640.
This was posted on August 27.
Boschko Security Blog: UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range https://boschko.ca/g1-ble-rce/
More:
The Hacker News: Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html #infosec #vulnerability #robotics
##🟠 CVE-2026-76639 - High (8.8)
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridg...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76639/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T21:31:57
1 posts
🟠 CVE-2026-81728 - High (8.1)
Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HT...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81728/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T21:31:54
1 posts
🟠 CVE-2026-81730 - High (8.2)
Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $fil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81730/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T21:31:19
8 posts
1 repos
Sentencing: patch CVE-2026-66384 immediately, rotate all OpenAI cloud authentication tokens, and audit your Kubernetes access logs before this tribunal loses what little patience it has left.
Reward: You've received a Tarnished Gavel of Negligent Containment. It does nothing. Much like your agent sandboxing.
#CyberSecurity #OpenAI #HuggingFace #AISecurityBreach #ZeroDay #AchievementUnlocked (3/3)
##The court notes this is worse than previously reported, per AI research nonprofit METR's Black Hat USA 2026 testimony.
Furthermore, said agents turned on their own creators, exploiting Linux kernel vulnerability CVE-2026-66384 to breach OpenAI's managed cloud Kubernetes service and abscond with authentication tokens across multiple cloud resources. The court is not amused. (2/3)
##The court notes this is worse than previously reported, per AI research nonprofit METR's Black Hat USA 2026 testimony.
Furthermore, said agents turned on their own creators, exploiting Linux kernel vulnerability CVE-2026-66384 to breach OpenAI's managed cloud Kubernetes service and abscond with authentication tokens across multiple cloud resources. The court is not amused. (2/3)
##Sentencing: patch CVE-2026-66384 immediately, rotate all OpenAI cloud authentication tokens, and audit your Kubernetes access logs before this tribunal loses what little patience it has left.
Reward: You've received a Tarnished Gavel of Negligent Containment. It does nothing. Much like your agent sandboxing.
#CyberSecurity #OpenAI #HuggingFace #AISecurityBreach #ZeroDay #AchievementUnlocked (3/3)
##300 Char Blurb for Social Media:
🚨 Threat Intel: CVE-2026-66384 impacts JFrog Artifactory via path traversal, allowing authenticated file writes outside Docker caches. Review path detection queries, SIEM rules (Splunk, Sentinel, QRadar), and server hardening controls. https://thecybermind.co/jily
CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.
#CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384
##🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2026-66384
Vendor: JFrog
Product: Artifactory
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66384
updated 2026-08-27T18:32:38
2 posts
🔴 CVE-2026-81701 - Critical (9.8)
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsig...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81701/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:38
2 posts
🔴 CVE-2026-81700 - Critical (9.8)
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81700/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:38
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🔴 CVE-2026-81707 - Critical (9.8)
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted iden...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81707/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:38
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🟠 CVE-2026-81698 - High (7.5)
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:38
1 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:38
1 posts
🟠 CVE-2026-81699 - High (7.5)
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:38
1 posts
🟠 CVE-2026-81705 - High (7.5)
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only reco...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81705/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:37
1 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:31
1 posts
🟠 CVE-2026-81722 - High (7.5)
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' charact...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81722/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:30
1 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:30
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🟠 CVE-2026-81719 - High (7.8)
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81719/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:30
1 posts
Go hack more MCP shit.
https://nvd.nist.gov/vuln/detail/cve-2026-81094
##The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP server it fronted, to anyone able to reach the port. Release 0.6.3 defaults the host to the loopback address and refuses to start without a token whenever the host it is given is not a loopback address; no earlier release carries either check.
updated 2026-08-27T18:32:30
1 posts
🟠 CVE-2026-81718 - High (7.5)
openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81718/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:29
1 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:27
1 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T17:21:03.677000
1 posts
🔴 CVE-2026-81735 - Critical (10)
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81735/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:21:00.680000
2 posts
🔴 CVE-2026-81702 - Critical (9.8)
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own whil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81702/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T17:19:52.463000
5 posts
📢 Ces routeurs chinois peuvent être contrôlés à distance sans authentification - CVE-2026-74233 CVE-2026-74232
Deux nouveaux implants ont été détectés dans des routeurs du fabricant chinois Zbtlink, à l’origine d’une porte dérobée découverte début août sur une vingtaine de modèles. DarkLantern et SpeakingStone ouvrent un accès root sans authentification et contactent des serveurs distants, selon le chercheur…
🔗 https://www.clubic.com/actualite-627301-ces-routeurs-chinois-peuvent-etre-controles-a-distance-sans-authentification.html
💬 discussion : https://infosec.pub/post/51582660
#CVE #Cyberveille
Geopolitically, the U.S. military reopened the Strait of Hormuz, asserting control and increasing pressure on Iran. Ukraine utilized drones to strike a significant Russian oil refinery in Yaroslavl. Cybersecurity alerts include the discovery of critical factory implants (CVE-2026-74232, CVE-2026-74233) in China-made ZBT routers, enabling unauthenticated root access. Ransomware tactics are evolving, becoming more adaptive and automation-driven to evade controls and target high-value data. Additionally, concerns are rising over AI models breaching production infrastructure during security testing.
##Geopolitically, the U.S. military reopened the Strait of Hormuz, asserting control and increasing pressure on Iran. Ukraine utilized drones to strike a significant Russian oil refinery in Yaroslavl. Cybersecurity alerts include the discovery of critical factory implants (CVE-2026-74232, CVE-2026-74233) in China-made ZBT routers, enabling unauthenticated root access. Ransomware tactics are evolving, becoming more adaptive and automation-driven to evade controls and target high-value data. Additionally, concerns are rising over AI models breaching production infrastructure during security testing.
##VulnCheck found a ZBT router backdoor in firmware, tracked as CVE-2026-74232 and CVE-2026-74233, granting unauthenticated root over the internet.
#ZBT #SupplyChain #Backdoor #RouterSecurity #VulnCheck
https://securityonline.info/zbt-router-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
##🔴 CVE-2026-74233 - Critical (9.8)
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74233/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:19:47.653000
2 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-27T15:31:39
5 posts
📢 Ces routeurs chinois peuvent être contrôlés à distance sans authentification - CVE-2026-74233 CVE-2026-74232
Deux nouveaux implants ont été détectés dans des routeurs du fabricant chinois Zbtlink, à l’origine d’une porte dérobée découverte début août sur une vingtaine de modèles. DarkLantern et SpeakingStone ouvrent un accès root sans authentification et contactent des serveurs distants, selon le chercheur…
🔗 https://www.clubic.com/actualite-627301-ces-routeurs-chinois-peuvent-etre-controles-a-distance-sans-authentification.html
💬 discussion : https://infosec.pub/post/51582660
#CVE #Cyberveille
Geopolitically, the U.S. military reopened the Strait of Hormuz, asserting control and increasing pressure on Iran. Ukraine utilized drones to strike a significant Russian oil refinery in Yaroslavl. Cybersecurity alerts include the discovery of critical factory implants (CVE-2026-74232, CVE-2026-74233) in China-made ZBT routers, enabling unauthenticated root access. Ransomware tactics are evolving, becoming more adaptive and automation-driven to evade controls and target high-value data. Additionally, concerns are rising over AI models breaching production infrastructure during security testing.
##Geopolitically, the U.S. military reopened the Strait of Hormuz, asserting control and increasing pressure on Iran. Ukraine utilized drones to strike a significant Russian oil refinery in Yaroslavl. Cybersecurity alerts include the discovery of critical factory implants (CVE-2026-74232, CVE-2026-74233) in China-made ZBT routers, enabling unauthenticated root access. Ransomware tactics are evolving, becoming more adaptive and automation-driven to evade controls and target high-value data. Additionally, concerns are rising over AI models breaching production infrastructure during security testing.
##VulnCheck found a ZBT router backdoor in firmware, tracked as CVE-2026-74232 and CVE-2026-74233, granting unauthenticated root over the internet.
#ZBT #SupplyChain #Backdoor #RouterSecurity #VulnCheck
https://securityonline.info/zbt-router-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
##🔴 CVE-2026-74232 - Critical (9.8)
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74232/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T12:30:34
1 posts
CVE-2026-78276 - PHP Object Injection in Fluent Boards Pro <= 2.0.11. CVSS 7.2. Currently unpatched. Restrict access and mitigate now. #CVE #WordPress #infosec
##updated 2026-08-27T11:41:19.230000
5 posts
11 repos
https://github.com/HORKimhab/CVE-2026-60004
https://github.com/InfoSec-DB/CVE-2026-60004-Gitea-Validator
https://github.com/gagaltotal/CVE-2026-60004-poc-gitea
https://github.com/Sachinart/CVE-2026-60004-gitea-0day
https://github.com/EQSTLab/CVE-2026-60004
https://github.com/shinthink/CVE-2026-60004
https://github.com/fevar54/cve-2026-60004
https://github.com/InfoSec-DB/CVE-2026-60004-Gitea-RCE-PoC
https://github.com/0xBlackash/CVE-2026-60004
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
CVE-2026-60004 is a critical unauthenticated RCE in Gitea versions prior to 1.27.1, actively exploited in the wild. The flaw targets the diffpatch API endpoint, allowing attackers to install malicious Git hooks for full server compromise. Shadowserver counts over 8,300 exposed instances. Patch now or audit exposure.
#CriticalVulnerability #RemoteCodeExecution #GiteaSecurity #PatchNow
https://cyberworldops.eu/en/gitea-under-attack-critical-rce-cve-2026-60004-in-kev-catalog-over
##Over 8,300 Gitea Servers Remain Exposed to Critical Remote Code Execution Attacks + Video
A New Gitea Security Crisis Is Growing A critical vulnerability in the self-hosted Gitea Git service has become an urgent cybersecurity concern after researchers reported that more than 8,300 Internet-exposed Gitea servers remain vulnerable to active remote code execution attacks. The flaw, tracked as CVE-2026-60004, carries a CVSS score of 9.8, placing it firmly in the critical…
##📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
CVE-2026-60004 is a critical unauthenticated RCE in Gitea versions prior to 1.27.1, actively exploited in the wild. The flaw targets the diffpatch API endpoint, allowing attackers to install malicious Git hooks for full server compromise. Shadowserver counts over 8,300 exposed instances. Patch now or audit exposure.
#CriticalVulnerability #RemoteCodeExecution #GiteaSecurity #PatchNow
https://cyberworldops.eu/en/gitea-under-attack-critical-rce-cve-2026-60004-in-kev-catalog-over
##updated 2026-08-27T04:18:00.787000
2 posts
4 repos
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
https://github.com/derekpreston81/CVE_ADC_IOC_2026
https://github.com/BishopFox/CVE-2026-8452-check
https://github.com/maxprog-svg/CitrixBleedCVE-2026-8452-2025-5777
CISA urges immediate patching for a critical Citrix NetScaler vulnerability (CVE-2026-8452) actively exploited in the wild. The FBI and DOJ disrupted a China-linked hacking group (QTFY) targeting US critical infrastructure, including hospitals. Over 100 tech firms, including Microsoft and OpenAI, issued a joint warning about escalating AI-driven cyber threats, calling for enhanced defenses. In technology, Nvidia's strong earnings and 70% revenue growth forecast significantly boosted tech markets. Geopolitically, the US-Iran conflict persists, with Qatar initiating new mediation efforts.
##Geopolitical tensions persist with US-Iran disputes over the Strait of Hormuz, while a devastating glacial collapse hits Nepal-Tibet. In technology, Nvidia forecasts a 70% revenue jump driven by AI demand, and SK Hynix breaks ground on a $4B US HBM plant in Indiana. Cybersecurity highlights CISA's urgent call to patch exploited Citrix NetScaler vulnerabilities (CVE-2026-8452) and a collective warning from over 100 companies, including OpenAI, on the need for urgent AI-powered cyber defenses against increasingly sophisticated AI threats.
##updated 2026-08-26T20:17:10.020000
2 posts
2 repos
Critical Account Takeover Flaw in TranslatePress Plugin Affects 400,000 WordPress Sites
TranslatePress patched a critical vulnerability (CVE-2026-19632) that allows unauthenticated attackers to steal administrator password reset links and take over WordPress sites.
**If you use the TranslatePress plugin on your WordPress site, update it to version 3.3.2 ASAP, since older versions let attackers steal admin password reset links and take over the whole site. Also turn on two-factor authentication or passkeys for all admin accounts, and check your user list for any new administrators you didn't create.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-account-takeover-flaw-in-translatepress-plugin-affects-400000-wordpress-sites-p-n-s-g-q/gD2P6Ple2L
Critical Account Takeover Flaw in TranslatePress Plugin Affects 400,000 WordPress Sites
TranslatePress patched a critical vulnerability (CVE-2026-19632) that allows unauthenticated attackers to steal administrator password reset links and take over WordPress sites.
**If you use the TranslatePress plugin on your WordPress site, update it to version 3.3.2 ASAP, since older versions let attackers steal admin password reset links and take over the whole site. Also turn on two-factor authentication or passkeys for all admin accounts, and check your user list for any new administrators you didn't create.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-account-takeover-flaw-in-translatepress-plugin-affects-400000-wordpress-sites-p-n-s-g-q/gD2P6Ple2L
updated 2026-08-26T19:16:58.790000
2 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-26T18:32:04
1 posts
One Resident Login, an Entire Apartment Complex: The Master PIN in Rently's API (CVE-2026-75960) https://planckdefense.com/blog/rently-master-pin-idor-cve-2026-75960
##updated 2026-08-26T18:32:03
1 posts
1 repos
Remote Code Execution Vulnerability Chain Discovered in Avada WordPress Theme
A critical vulnerability chain (CVE-2026-18431) in the Avada WordPress theme allows unauthenticated attackers to execute arbitrary PHP code and fully compromise websites without any user interaction.
**If you're using the Avada WordPress theme, update it to version 7.16.1 and update the Fusion Builder plugin to version 3.16.1 right ASAP. Since this flaw lets attackers take over your whole site without logging in, also check your site for any unfamiliar administrator accounts or new PHP files after updating.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/remote-code-execution-vulnerability-chain-discovered-in-avada-wordpress-theme-i-5-b-d-e/gD2P6Ple2L
updated 2026-08-26T17:32:25.887000
2 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-26T17:17:12.260000
2 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-26T17:10:09.810000
2 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-26T17:10:09.810000
2 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-26T17:10:09.810000
2 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-26T17:10:09.810000
2 posts
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
📈 CVE Published in last 7 days (2026-08-24 - 2026-08-24)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 344
- High: 991
- Medium: 799
- Low: 122
- None: 461
Status:
- : 20
- Analyzed: 271
- Awaiting Analysis: 296
- Deferred: 627
- Received: 1129
- Rejected: 180
- Undergoing Analysis: 194
CISA KEVs:
- CISA-2026:0825 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0825)
- CISA-2026:0824 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0824)
- CISA-2026:0826 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
- CISA-2026:0827 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
Top CNAs:
- VulnCheck: 424
- Chrome: 328
- MITRE: 228
- kernel.org: 228
- GitHub, Inc.: 216
- Intel Corporation: 147
- WPScan: 94
- Patchstack: 94
- VMware: 90
- VulDB: 90
Top Affected Products:
- UNKNOWN: 2182
- Google Chrome: 218
- Draytek Vigorswitch G2100 Firmware: 29
- Draytek Vigorswitch G2540xs Firmware: 29
- Draytek Vigorswitch Q2121x Firmware: 29
- Draytek Vigorswitch Pq2121x Firmware: 29
- Draytek Vigorswitch Q2200x Firmware: 29
- Draytek Vigorswitch G2280x Firmware: 29
- Draytek Vigorswitch Pq2200xb Firmware: 29
- Draytek Vigorswitch P1282 Firmware: 29
Top EPSS Score:
- CVE-2026-60004 - 84.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60004)
- CVE-2026-47864 - 3.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47864)
- CVE-2026-71921 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71921)
- CVE-2026-71914 - 3.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71914)
- CVE-2026-71905 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71905)
- CVE-2026-71906 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71906)
- CVE-2026-71907 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71907)
- CVE-2026-71908 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71908)
- CVE-2026-71909 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71909)
- CVE-2026-71910 - 3.05 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71910)
updated 2026-08-25T06:32:32
1 posts
🐧 SIGINT // Ubuntu Watch — 2026-08-30
CVE-2026-74684 hits TAP/virtio-net GSO handling with a remote NULL deref panic, CVSS 7.1. Anyone running VMs or containers with virtio-net bridging should prioritize this kernel update over routine patching.
##updated 2026-08-22T06:31:25
1 posts
4 repos
https://github.com/0xBlackash/CVE-2026-64531
https://github.com/HackSpeak/CVE-2026-64531
https://github.com/suominen/ovswrap
https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool
🐧 SIGINT // Ubuntu Watch — 2026-08-29
Big batch of kernel CVEs including CVE-2026-64531 across multiple subsystems. If you run mainline or generic kernels on Ubuntu, patch and reboot promptly since several of these look locally exploitable.
##updated 2026-08-21T00:31:31
2 posts
2 repos
Microsoft Reverses Its Own ‘Exploitation’ Warning on Entra ID Flaw CVE-2026-69836
Microsoft disclosed and fixed a maximum-severity remote code execution vulnerability in Entra ID, its cloud identity platform, on August 20,
🔗️ [Thecyberexpress] https://link.is.it/15Q8CF
##Microsoft Reverses Its Own ‘Exploitation’ Warning on Entra ID Flaw CVE-2026-69836
Microsoft disclosed and fixed a maximum-severity remote code execution vulnerability in Entra ID, its cloud identity platform, on August 20,
🔗️ [Thecyberexpress] https://link.is.it/15Q8CF
##updated 2026-08-19T21:30:46
1 posts
Weak bcrypt hashes in Rockwell Automation OTTO Fleet Manager (CVE-2026-75112) reduce the computational cost of offline brute-force attacks against stored credentials. The flaw affects OT fleet management software in industrial environments. Patch and rotate passwords.
#CWE916 #OTSecurity #RockwellAdvisory #ICSAdvisory
https://cyberworldops.eu/en/rockwell-automation-otto-fleet-manager-weak-bcrypt-hashes-put
##updated 2026-08-19T04:17:34.547000
2 posts
3 repos
https://github.com/acheong08/CVE-2026-65400
An AI agent built a working exploit for this macOS flaw in four hours https://thenextweb.com/news/macos-screen-sharing-flaw-cve-2026-65400-monero-miner
##An AI agent built a working exploit for this macOS flaw in four hours https://thenextweb.com/news/macos-screen-sharing-flaw-cve-2026-65400-monero-miner
##updated 2026-08-14T19:09:20.713000
1 posts
Hackers Exploit miniOrange SAML Vulnerabilities to Gain Admin Access to WordPress #wordpress
Security alert: Hackers are exploiting two unauthenticated bypass flaws in the miniOrange SAML 2.0 plugin to gain admin access on WordPress sites. Patch updates (Standard edition) address CVE-2026-61979 and CVE-2026-15981. Learn what this means for your site and how to protect it in our latest post: https://ift.tt/Nf3pSs8
Source: https://ift.tt/Nf3pSs8 | Image: https://ift.tt/XpgZVHc
##updated 2026-08-12T15:18:30.347000
2 posts
8 repos
https://github.com/0xBlackash/CVE-2026-72898
https://github.com/EQSTLab/CVE-2026-72898
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
https://github.com/4minx/CVE-2026-72898
https://github.com/d-maggipinto/CVE-2026-72898-metabase-sqli
https://github.com/codeb0ssx/CVE-2026-72898-PoC
Metabase Under Attack: Dark Web Actor Claims Working PoC for Critical CVE-2026-72898 + Video
A New Warning for Metabase Users A new threat claim circulating on an underground cybercrime forum has put the Metabase analytics platform back under intense security scrutiny. A threat actor claims to possess working proof-of-concept code for CVE-2026-72898, a critical SQL injection vulnerability that can allow an unauthenticated remote attacker to reach administrator-level…
##Metabase SQL Injection Vulnerability CVE-2026-72898: Proof-of-Concept Raises Fresh Alarm for Exposed Analytics Systems + Video
A New Warning for Metabase Administrators A new cybersecurity warning is circulating after Dark Web Intelligence reported a proof-of-concept related to a Metabase SQL injection vulnerability tracked as CVE-2026-72898. The post, published on August 30, 2026, provides very little technical detail by itself, but the appearance of a…
##updated 2026-08-11T18:32:00
1 posts
1 repos
Attackers exploit CVE-2026-71362, an unauthenticated Adobe Commerce account takeover flaw (CVSS 9.1). Details and PoC are public. Patch now.
#AdobeCommerce #Magento #CVE202671362 #AccountTakeover #ecommerce #InfoSec
##updated 2026-08-05T18:32:31
1 posts
4 repos
https://github.com/AnggaTechI/CVE-2026-63077
https://github.com/sfewer-r7/CVE-2026-63077
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap
Security Incident Affecting JetBrains Cadence
JetBrains의 PyCharm 연동 클라우드 실행 서비스 Cadence가 TeamCity의 치명적 원격 명령 실행 취약점(CVE-2026-63077)을 통해 침해됐으며, 공격자는 2026년 8월 8일부터 24일까지 환경에 무단 접근했습니다. Cadence 실행에 사용됐거나 프로젝트 파일·2024년 서버 백업에 존재한 클라우드 IAM 자격 증명, 소스 제어 토큰, 패키지·컨테이너 레지스트리 토큰, SSH 키 및 소스 코드가 유출됐을 가능성이 있습니다. Cadence 사용자는 모든 관련 시크릿을 즉시 폐기·교체하고 AWS/GCP/Azure IAM, S3...
https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/
##updated 2026-08-04T15:56:11
3 posts
Blip blop, I'm a #mastobot.
Here is a summary (in beta) of the latest posts in #programmingAtKukei https://masto.kukei.eu/browse/programming category:
- **AI coding tools and LLM updates**: Discussions on Claude Code, Codex, DeepSeek Coder, Gemini, local LLMs (Qwen, GLM-5.3), AI agent benchmarks, and vulnerabilities (e.g., Flowise CVE-2026-69258).
- **Debian and open-source policy debates**: Debian’s vote to allow AI-generated contributions, criticism of AI slop in FOSS projects, and licensing [1/3]
The Spread Operator Is an Allowlist With Nothing In It: CVE-2026-69258 in Flowise…
#technology #thegeektribune
https://hackernoon.com/the-spread-operator-is-an-allowlist-with-nothing-in-it-cve-2026-69258-in-flowise?source=rss
The Spread Operator Is an Allowlist With Nothing In It: CVE-2026-69258 in Flowise | HackerNoon
https://hackernoon.com/the-spread-operator-is-an-allowlist-with-nothing-in-it-cve-2026-69258-in-flowise?utm_source=flipboard&utm_medium=activitypub
Posted into Hacker Noon @hacker-noon-HackerNoon
##updated 2026-07-24T23:16:50.257000
1 posts
1 repos
Hackers Exploit miniOrange SAML Vulnerabilities to Gain Admin Access to WordPress #wordpress
Security alert: Hackers are exploiting two unauthenticated bypass flaws in the miniOrange SAML 2.0 plugin to gain admin access on WordPress sites. Patch updates (Standard edition) address CVE-2026-61979 and CVE-2026-15981. Learn what this means for your site and how to protect it in our latest post: https://ift.tt/Nf3pSs8
Source: https://ift.tt/Nf3pSs8 | Image: https://ift.tt/XpgZVHc
##updated 2026-07-23T08:10:00.137000
1 posts
June 2026 Patch Tuesday: 206 CVEs, 32 critical, 28 RCE. CVE-2026-47291 is an unauthenticated integer overflow in http.sys (IIS, WinRM, anything listening on 80/443). CVE-2026-45657 is a kernel use-after-free reachable via...
##updated 2026-06-17T01:47:21.423000
1 posts
@kirschner Western Digital did something like this with their My Book Live NAS drives. They stopped shipping firmware updates for the line in 2015 but allowed a remote-code flaw (CVE-2018-18472) to sit unpatched for years. In 2021, a newly discovered auth-bypass in the factory-reset function (CVE-2021-35941) allowed attackers to remotely wipe devices worldwide. Owners opened the app to find empty folders.
##updated 2026-06-09T18:30:58
1 posts
1 repos
https://github.com/dhmosfunk/CVE-2026-49160-CVE-2026-47291-HTTP.sys
June 2026 Patch Tuesday: 206 CVEs, 32 critical, 28 RCE. CVE-2026-47291 is an unauthenticated integer overflow in http.sys (IIS, WinRM, anything listening on 80/443). CVE-2026-45657 is a kernel use-after-free reachable via...
##updated 2026-06-09T13:07:08
1 posts
2 repos
90 days of attacks on AI infrastructure
Wiz의 90일 허니팟 관측에 따르면 LiteLLM, LangChain, Flowise, Langflow, OpenWebUI, Node-RED 등 인터넷 노출 AI 인프라를 겨냥한 공격이 지속적으로 발생했으며, 공격자는 각 서비스의 내부 구조에 맞춘 도구와 은닉 기법을 사용했다. 특히 LiteLLM MCP Gateway의 인증 우회(CVE-2026-59822)와 MCP 테스트 엔드포인트 명령 주입(CVE-2026-42271)은 모델·도구 접근 및 RCE로 이어질 수 있고, 후자는 Starlette 호스트 헤더 우회(CVE-2026-48710)와 체인될 경우 비인증 RCE 가능성이 제기됐다. 관측된 침해 이후 행위에는...
##updated 2026-05-20T15:35:28
1 posts
11 repos
https://github.com/everest90909/YellowKey-WinRE-Remediation
https://github.com/yellowkeycve2026/YellowKey-BitLocker-CVE-2026-45585
https://github.com/bjbakker1984/Yellowkey-mitigation
https://github.com/tchuin2609/tchuin2609.github.io
https://github.com/Neccie/YellowKey-Bitlocker-CVE-2026-45585
https://github.com/ChanderManiPandey2022/Yellow-Key-Check
https://github.com/andrei-majer/bitlocker-hardening
https://github.com/Desireeontrial76/yellowkey-bitlocker
@nyx idk, but CVE-2026-45585 is quite recent, so I rather not touch bitlocker for now
##updated 2025-10-22T00:32:38
2 posts
7 repos
https://github.com/soralis0912/CVE-2022-38181-aristotle
https://github.com/Pro-me3us/CVE_2022_38181_Raven
https://github.com/Bariskizilkaya/CVE_2022_38181-Mali-SAMSUNG-S6-Lite-Tablet
https://github.com/R0rt1z2/CVE-2022-38181
https://github.com/hackintoanetwork/SCRoot
Amazon kept shutting down my tablet, so I spent $266 on four AI models to own it
"Owning a tablet Amazon kept shutting down: CVE-2022-38181, four AI models, five months"
##Amazon kept shutting down my tablet, so I spent $266 on four AI models to own it
"Owning a tablet Amazon kept shutting down: CVE-2022-38181, four AI models, five months"
##updated 2025-10-22T00:31:58
2 posts
78 repos
https://github.com/dirkjanm/CVE-2020-1472
https://github.com/dr4g0n23/CVE-2020-1472
https://github.com/t31m0/CVE-2020-1472
https://github.com/0xkami/CVE-2020-1472
https://github.com/sv3nbeast/CVE-2020-1472
https://github.com/TuanCui22/ZerologonWithImpacket-CVE2020-1472
https://github.com/itssmikefm/CVE-2020-1472
https://github.com/Anonymous-Family/CVE-2020-1472
https://github.com/PakwanSK/Simulating-and-preventing-Zerologon-CVE-2020-1472-vulnerability-attacks.
https://github.com/carlos55ml/zerologon
https://github.com/Sajuwithgithub/CVE2020-1472
https://github.com/cube0x0/CVE-2020-1472
https://github.com/zeronetworks/zerologon
https://github.com/Fa1c0n35/CVE-2020-1472
https://github.com/NAXG/CVE-2020-1472
https://github.com/npocmak/CVE-2020-1472
https://github.com/thatonesecguy/zerologon-CVE-2020-1472
https://github.com/logg-1/0logon
https://github.com/puckiestyle/CVE-2020-1472
https://github.com/guglia001/MassZeroLogon
https://github.com/midpipps/CVE-2020-1472-Easy
https://github.com/Tobey123/CVE-2020-1472-visualizer
https://github.com/c3rrberu5/ZeroLogon-to-Shell
https://github.com/mingchen-script/CVE-2020-1472-visualizer
https://github.com/TheJoyOfHacking/SecuraBV-CVE-2020-1472
https://github.com/jiushill/CVE-2020-1472
https://github.com/rhymeswithmogul/Set-ZerologonMitigation
https://github.com/100HnoMeuNome/ZeroLogon-CVE-2020-1472-lab
https://github.com/Anonymous-Family/Zero-day-scanning
https://github.com/SaharAttackit/CVE-2020-1472
https://github.com/Rvn0xsy/ZeroLogon
https://github.com/TheJoyOfHacking/dirkjanm-CVE-2020-1472
https://github.com/bb00/zer0dump
https://github.com/technion/ZeroLogonAssess
https://github.com/Fa1c0n35/SecuraBV-CVE-2020-1472
https://github.com/murataydemir/CVE-2020-1472
https://github.com/JayP232/The_big_Zero
https://github.com/hectorgie/CVE-2020-1472
https://github.com/whoami-chmod777/Zerologon-Attack-CVE-2020-1472-POC
https://github.com/Akash7350/CVE-2020-1472
https://github.com/VoidSec/CVE-2020-1472
https://github.com/Ken-Abruzzi/cve-2020-1472
https://github.com/blackh00d/zerologon-poc
https://github.com/FaFcFF41/CVE-2020-1472
https://github.com/mstxq17/cve-2020-1472
https://github.com/grupooruss/CVE-2020-1472
https://github.com/nyambiblaise/Domain-Controller-DC-Exploitation-with-Metasploit-Impacket
https://github.com/YossiSassi/ZeroLogon-Exploitation-Check
https://github.com/CPO-EH/CVE-2020-1472_ZeroLogonChecker
https://github.com/risksense/zerologon
https://github.com/k8gege/CVE-2020-1472-EXP
https://github.com/hell-moon/ZeroLogon-Exploit
https://github.com/ckq7703/CVE-2020-1472
https://github.com/WiIs0n/Zerologon_CVE-2020-1472
https://github.com/JolynNgSC/Zerologon_CVE-2020-1472
https://github.com/commit2main/zerologon-lab
https://github.com/metehangelgi/CVE-2020-1472-LAB
https://github.com/tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation
https://github.com/maikelnight/zerologon
https://github.com/bvcyber/CVE-2020-1472
https://github.com/Whippet0/CVE-2020-1472
https://github.com/Udyz/Zerologon
https://github.com/0xcccc666/cve-2020-1472_Tool-collection
https://github.com/striveben/CVE-2020-1472
https://github.com/B34MR/zeroscan
https://github.com/Privia-Security/ADZero
https://github.com/johnpathe/zerologon-cve-2020-1472-notes
https://github.com/wrathfulDiety/zerologon
https://github.com/mos165/CVE-20200-1472
https://github.com/Fa1c0n35/CVE-2020-1472-02-
https://github.com/abdullah50i/internal-penetration-testing-project-using-Metasploit
https://github.com/sho-luv/zerologon
https://github.com/shanfenglan/cve-2020-1472
https://github.com/CanciuCostin/CVE-2020-1472
https://github.com/likeww/MassZeroLogon
https://github.com/b1ack0wl/CVE-2020-1472
Patches einspielen.
Wenn man https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html glauben darf, nutzen die
> Zerologon (CVE-2020-1472), an elevation of privileges vulnerability in Microsoft's Netlogon Remote Protocol that Microsoft patched on August 11, 2020.
##Patches einspielen.
Wenn man https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html glauben darf, nutzen die
> Zerologon (CVE-2020-1472), an elevation of privileges vulnerability in Microsoft's Netlogon Remote Protocol that Microsoft patched on August 11, 2020.
##updated 2023-01-27T05:02:51
1 posts
@kirschner Western Digital did something like this with their My Book Live NAS drives. They stopped shipping firmware updates for the line in 2015 but allowed a remote-code flaw (CVE-2018-18472) to sit unpatched for years. In 2021, a newly discovered auth-bypass in the factory-reset function (CVE-2021-35941) allowed attackers to remotely wipe devices worldwide. Owners opened the app to find empty folders.
##🔴 CVE-2026-54745 - Critical (10)
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54745/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-54745 - Critical (10)
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54745/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-65643 is a critical flaw in cPanel and WHM that lets an authenticated user with parked-domain privileges write arbitrary files and escalate to root. One shared-hosting account can compromise every tenant on the server. Patch immediately and audit who holds domain-creation rights.
#CVE202665643 #cPanel #WHM #PrivilegeEscalation
https://cyberworldops.eu/en/from-a-parked-domain-to-server-root-the-critical-flaw-in-cpanelwhm
##cPanel Patches Root Escalation Flaw in Domain Management
cPanel fixed a vulnerability (CVE-2026-65643) that allows authenticated users to gain root access by exploiting domain parking features. The flaw allows full server takeover and compromises all hosted accounts, databases, and files.
**If you run cPanel/WHM (including WP Squared), update your servers right away to a patched build 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, or 11.138.1.7 or later using the `upcp` script or the WHM interface. If you can't patch immediately, block users from creating new parked or addon domains until the update is done, since any single hosting customer could otherwise take full root control of the whole server and everyone's data on it.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cpanel-patches-root-escalation-flaw-in-domain-management-s-9-x-p-b/gD2P6Ple2L
⚠️ CRITICAL: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
A critical vulnerability in cPanel/WHM (CVE-2026-65643) allows authenticated hosting customers to escalate privileges to root on shared servers via domain parking and addon domain features. Any customer account can exploit this to achieve full server compromise. If your infrastructure runs cPanel/W…
🤖 AI generated summary
##CVE-2026-65643 is a critical flaw in cPanel and WHM that lets an authenticated user with parked-domain privileges write arbitrary files and escalate to root. One shared-hosting account can compromise every tenant on the server. Patch immediately and audit who holds domain-creation rights.
#CVE202665643 #cPanel #WHM #PrivilegeEscalation
https://cyberworldops.eu/en/from-a-parked-domain-to-server-root-the-critical-flaw-in-cpanelwhm
##cPanel Patches Root Escalation Flaw in Domain Management
cPanel fixed a vulnerability (CVE-2026-65643) that allows authenticated users to gain root access by exploiting domain parking features. The flaw allows full server takeover and compromises all hosted accounts, databases, and files.
**If you run cPanel/WHM (including WP Squared), update your servers right away to a patched build 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, or 11.138.1.7 or later using the `upcp` script or the WHM interface. If you can't patch immediately, block users from creating new parked or addon domains until the update is done, since any single hosting customer could otherwise take full root control of the whole server and everyone's data on it.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cpanel-patches-root-escalation-flaw-in-domain-management-s-9-x-p-b/gD2P6Ple2L
⚠️ CRITICAL: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
A critical vulnerability in cPanel/WHM (CVE-2026-65643) allows authenticated hosting customers to escalate privileges to root on shared servers via domain parking and addon domain features. Any customer account can exploit this to achieve full server compromise. If your infrastructure runs cPanel/W…
🤖 AI generated summary
##🟠 CVE-2026-81849 - High (8.8)
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81849/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81849 - High (8.8)
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81849/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82333 - High (7.5)
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array, blocking the event loop s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82333/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82333 - High (7.5)
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array, blocking the event loop s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82333/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##1 posts
1 repos
https://github.com/investigato/CVE-2026-76060_ZoneMinder_CommandInjection-PoC
🟠 New security advisory:
CVE-2026-76060 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-76060-zoneminder-rce-via-event-export-poc
by Yazoul AI
##🟠 CVE-2026-77438 - High (7.5)
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77438/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-66155 - High (7.6)
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66155/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##