#advisory

42 posts · Last used 18d

Critical Arbitrary File Upload Flaw in Gravity Forms Leads to Remote Code Execution

Gravity Forms patched a critical vulnerability (CVE-2026-84434) that allows unauthenticated attackers to upload executable files and gain remote code execution.

If you use Gravity Forms on WordPress, update it to version 3.1.1 or later ASAP. If you can't update immediately, disable file upload fields on any public forms, then check your upload folders for unexpected PHP files and your logs for suspicious activity. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/critical-arbitrary-file-upload-flaw-in-gravity-forms-leads-to-remote-code-execution-3-5-o-c-z/gD2P6Ple2L

0
0
0
0

Apple Patches Hundreds of Vulnerabilities in September 2026 Security Update

Apple's September 14, 2026 release of iOS 27, macOS Golden Gate 27, Safari 27 and its sibling updates patches over 200 CVEs, concentrated in WebKit, the kernel and drivers, and file-sharing/file-system code (SMB, WebDAV, autofs, disk images). The flaws enable universal XSS, root privilege escalation, kernel memory corruption from hostile servers or crafted volumes, Gatekeeper and sandbox bypasses, and arbitrary code execution from images and 3D models.

If you use any Apple devices: iPhone, iPad, Mac, Apple Watch, Apple TV or Vision Pro, update them ASAP to the latest version (iOS/iPadOS 27 or 26.7, macOS Golden Gate 27, Tahoe 26.7 or Sequoia 15.8, tvOS/watchOS/visionOS 27, and Safari 27). The September releases patch a huge number of issues. Until you've updated, be extra careful about visiting unfamiliar websites, opening files or images from strangers, and connecting to unknown file-sharing servers or Wi-Fi networks. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/apple-patches-hundreds-of-vulnerabilities-in-september-2026-security-update-j-s-p-c-n/gD2P6Ple2L

1
0
2
0
🔒 New CSAF advisory published VDE-2026-091 TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576 The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin… HTML: https://certvde.com/en/advisories/VDE-2026-091 CSAF JSON: https://trumpf.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-091.json #OT #Advisory
0
0
0
0

SonicWall Patches Chained Zero-Day Vulnerabilities in SMA 1000 Series VPNs

SonicWall has patched two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its SMA 1000 series VPN appliances that attackers are chaining to achieve unauthenticated remote code execution.

If you run SonicWall SMA 1000 appliances (models 6210, 7210, or 8200v), update immediately to version 12.4.3-03526 or 12.5.0-02952. These devices are actively attacked to take over VPN gateways. After patching review your logs for signs of compromise, if anything looks suspicious, re-image the appliance, change all passwords and reset TOTP tokens, and only restore backups from before the breach. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/sonicwall-patches-chained-zero-day-vulnerabilities-in-sma-1000-series-vpns-k-n-b-f-y/gD2P6Ple2L

0
0
0
0
🔄 CSAF advisory updated (version 2.0.0) VDE-2026-051 iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator CVE-2026-8024 Changes: Added ibaLogic to the affected products and the mitigation for this product. HTML: https://certvde.com/en/advisories/VDE-2026-051 CSAF JSON: https://iba.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-051.json #OT #Advisory
0
0
0
0

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/veeam-patches-critical-credential-theft-and-rce-flaws-in-service-provider-console-y-k-8-e-6/gD2P6Ple2L

0
0
0
0

Django Patches High-Severity File-Write Flaw in GeoDjango and Three Other Vulnerabilities

Django 6.0.8 and 5.2.17 are out, fixing four security issues: most urgently a GeoDjango flaw (CVSS 8.8) that lets any staff user with view permission on a spatial-field model trigger SSRF or file writes, potentially leading to remote code execution.

If you run Django, upgrade now to Django 6.0.8 or 5.2.17. If you're on an older unsupported version like 5.1, 5.0 or 4.2, assume you're vulnerable and plan a move to a supported branch. If you use GeoDjango, test your spatial lookups before deploying because the fix intentionally breaks some old behaviour, and check who has staff/view access to models with map or location fields. That level of access is all an attacker needs for the most serious flaw. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/django-patches-high-severity-file-write-flaw-in-geodjango-and-three-other-vulnerabilities-d-x-1-q-e/gD2P6Ple2L

0
0
0
0
#OT #Advisory VDE-2026-065 Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory. #CVE CVE-2026-9593 https://certvde.com/en/advisories/vde-2026-065/ #CSAF https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-065.json
0
0
0
0

IBM Patches Critical Remote Code Execution and Privilege Escalation Flaws in WebSphere

IBM issued emergency patches for WebSphere Application Server to fix four vulnerabilities, including two critical flaws with CVSS scores of 9.8. These vulnerabilities allow unauthenticated attackers to execute code, escalate privileges, and perform server-side request forgery.

If you run IBM WebSphere Application Server (traditional 8.5 or 9.0) or WebSphere Liberty, plan a quick patch. Update to packs 9.0.5.29 or 8.5.5.31 for traditional WebSphere, or upgrade Liberty to 26.0.0.9. WebSphere systems may be exposed to the internet by design, so prioritize those systems. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/ibm-patches-critical-remote-code-execution-and-privilege-escalation-flaws-in-websphere-7-h-7-4-3/gD2P6Ple2L

1
0
0
0
#OT #Advisory VDE-2026-008 Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability. #CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102 https://certvde.com/en/advisories/vde-2026-008/ #CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
0
0
0
0
#OT #Advisory VDE-2026-041 CODESYS PROFINET Controller - Out-of-bounds Write CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. #CVE CVE-2026-35226 https://certvde.com/en/advisories/vde-2026-041/ #CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-06_vde-2026-041.json
0
0
0
0

JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution

JetBrains patched a critical authentication bypass (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated remote code execution. The flaw affects all on-premises versions and could lead to a full takeover of CI/CD pipelines.

If you run TeamCity On-Premises, urgently update to version 2025.11.7 or 2026.1.3 to patch CVE-2026-63077. All on-premises versions are vulnerable to a full server takeover. TeamCity Cloud is already patched and needs no action. If you can't update right away, install the security patch plugin (for versions 2017.1 and later) and restrict access to your TeamCity server to trusted internal networks or a VPN. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/jetbrains-fixes-critical-teamcity-authentication-bypass-allowing-remote-code-execution-c-x-w-3-z/gD2P6Ple2L

0
0
0
0

GitLab Remote Code Execution Chain Exploits Long-Standing Memory Flaws in Oj Parser

GitLab patched a critical remote code execution chain involving two memory corruption flaws in the Oj Ruby JSON parser that allow authenticated users to take over servers via malicious Jupyter notebook diffs.

If you run self-managed GitLab, upgrade immediately to version 18.10.8, 18.11.5, or 19.0.2. There's a working exploit published and any user who can push code to a project can take over the server. If you're on version 15.2 through 18.9, those are no longer supported and won't get a patch, so you must move to a supported release to be protected. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/gitlab-remote-code-execution-chain-exploits-long-standing-memory-flaws-in-oj-parser-q-z-g-i-b/gD2P6Ple2L

1
0
0
0
#OT #Advisory VDE-2026-081 Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0. #CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510 https://certvde.com/en/advisories/vde-2026-081/ #CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
0
0
0
0
#OT #Advisory VDE-2026-076 ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0. #CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510 https://certvde.com/en/advisories/vde-2026-076/ #CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
0
0
0
0