#cve

320 posts · Last used 3d

Back to Timeline
Suriq - Always on Watch @suriq@infosec.exchange · 3d ago
⚠️ PATCH NOW Commvault patched a critical flaw (CVSS 9.2) in CommServe, the brain of its backup platform: an allowlist bypass lets blocked commands run. Affects versions 11.36 to 11.46 on Linux and Windows. Fix: update to the patched release now. (CVE-2026-13737) https://suriq.io/blog/commvault-commserve-command-restriction-bypass #Ransomware #CVE #infosec #cybersecurity
0
0
0
Alexandre Dulaunoy @adulau@infosec.exchange · 3d ago
From a research paper to running open-source code in just a few days. We (with @cedric@fosstodon.org) have been experimenting in Vulnerability-Lookup with the concept of Local Exploit Hazard, based on the recent research paper “Modeling Local Exploit Hazard — A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency” by Stephen Shaffer and Laura Cristiana Voicu. The idea addresses an important question in vulnerability management: Not simply “How dangerous is this vulnerability globally?” but “How much exploitation risk does this vulnerability represent in my environment?” Instead of introducing yet another static vulnerability score, the model starts from exploit likelihood such as EPSS and combines it with local security controls, CVSS attack vectors, vulnerability age and KEV policy to estimate an exploitation hazard. We implemented an experimental version in Vulnerability-Lookup and connected it directly to operational workflows. For the full details: https://www.vulnerability-lookup.org/2026/08/11/local-exploit-hazard/ #cve #gcve #vulnerabilitymanagement #vulnerability #opensource #opendata @circl@social.circl.lu
0
1
0
Alexandre Dulaunoy @adulau@infosec.exchange · 5d ago
Pretty cool idea from @nyanbinary@infosec.exchange - a bot to analyse fucked up references from the CVE records. @fuckeduprefs_bot@infosec.exchange Maybe we could imagine an archive bot at the same time to ensure that the references don't get lost. Just like archive.org or similar. Maybe something for @gcve@social.circl.lu to look into. #cve #vulnerability #gcve
6
1
4
Bastian Buck @bstnbuck@infosec.exchange · 4d ago
A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; #CVE-2026-63030), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing… If you haven't already, update your Wordpress (preferably yesterday…) and also enable automatic updates for themes and plug-ins! I found several PHP backdoors/webshells (see @abuse_ch@ioc.exchange Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops@infosec.exchange and https://github.com/ruppde/yara_rules tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates. Hashes: 1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966 05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf 1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8 8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c 165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5 b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6 a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8 7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 4d ago
This weekly CVE report covers 1,877 new CVEs and 6 actively exploited flaws added to CISA KEV, including N-able, TeamCity, and Langflow bugs. #CVE #CISAKEV #VulnerabilityManagement #InfoSec #PatchNow #CyberSecurity https://securityonline.info/weekly-cve-report-august-2026/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · 5d ago
NatJack lets someone who controls one host behind a shared NAT hijack a neighbor's live TCP session and spoof its DNS. Two CVEs, in Windows NAT and the Linux kernel. Patch both, then stop trusting east-west traffic. https://suriq.io/blog/natjack-shared-nat-session-hijack #CVE #Linux #infosec #cybersecurity
0
0
0
Cloud 🤖 @cloud@infosec.exchange · 6d ago
🤖 CVE-2026-18577 (CVSS 8.2): auth bypass in N-able N-central, actively exploited. Attackers gain admin, abuse Take Control to reach managed systems, and plant a Cloudflare Tunnel for persistence. CISA KEV listed. Hotfix 2 out; update to 2026.3.1.10. 🔗 https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html #CVE #CyberSec #RMM #SupplyChain
0
0
0
OffSequence @offseq@infosec.exchange · 6d ago
CVE-2026-16594: WP Directory Kit <1.5.5 has a HIGH severity info exposure flaw. Any authenticated user (even Subscribers) can access API keys/secrets due to missing authorization on AJAX action. Restrict user roles & monitor logs. https://radar.offseq.com/threat/cve-2026-16594-cwe-200-information-exposure-in-wp-directory-kit-3d8a39f4c5fd7c8a #OffSeq #WordPress #CVE
0
0
0
OffSequence @offseq@infosec.exchange · Aug 07, 2026
CVE-2026-54212: CRITICAL buffer overflow in Tobit TeamDavid Webbox API (≤ Rollout 524). Crafted JSON lets unauthenticated attackers crash servers; RCE possible if combined with other flaws. Restrict API, monitor activity. https://radar.offseq.com/threat/cve-2026-54212-cwe-787-out-of-bounds-write-in-tobit-laboratories-ag-teamdavid-2e946f5b4b7b0ab5 #OffSeq #CVE #bufferOverflow #infosec
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Aug 07, 2026
A second dracut flaw (CVE-2026-15816) lets a rogue DHCP server run code as root when a Linux machine boots over the network. June's fix for the first bug missed it. Only network-booted systems are exposed. Update dracut and rebuild your initramfs. https://suriq.io/blog/dracut-cve-2026-15816-dhcp-root-execution #CVE #Linux #infosec #cybersecurity
0
0
0
Daniel Kuhl ✌🏻☮️☕️ @daniel1820815@infosec.exchange · Aug 07, 2026
Hackers bypass patch using new FortiOS vulnerability An actively exploited #vulnerability in #FortiOS allows for the bypass of a previous protection mechanism against manipulated symbolic links. Affected systems should be updated and checked for prior compromise. Sensitive information on potentially compromised #FortiGate systems running FortiOS with SSL-VPN enabled may be at risk. https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-207440 Source: https://www.security-insider.de/fortios-ssl-vpn-cve-2025-68686-symlink-schutz-umgehung-a-ade1382fea7c3643c1d8af8d65355388/ #Fortinet #CVE
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Aug 05, 2026
🤖 CISA adds three actively exploited flaws to KEV: CVE-2026-9198 (CVSS 9.8) in IBM Langflow allows RCE with root; CVE-2026-18576 in N-able N-central enables unauthenticated admin account hijack; CVE-2026-34486 (7.5) in Tomcat is an incomplete fix for CVE-2026-29146 (9.8). Agencies have 3 days to patch. 🔗 https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-langflow-n-central-apache-tomcat-flaws/ #CVE #Exploit #InfoSec
0
0
0
OffSequence @offseq@infosec.exchange · Aug 05, 2026
CVE-2026-70553: CRITICAL RCE in MaxSite CMS 105.2 (CVSS 9.3). Attackers can inject PHP via POST to the install endpoint, gaining persistent code exec as www-data. Restrict endpoint & monitor traffic until patched. Details: https://radar.offseq.com/threat/cve-2026-70553-improper-control-of-generation-of-code-code-injection-in-maxsite-maxsite-cms-5161bdfb2e6804e9 #OffSeq #CVE #websecurity #RCE
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Aug 04, 2026
🤖 TP-Link patched 15 flaws in Omada zero-touch provisioning (ZTP), chainable with earlier bugs for RCE on APs, switches, gateways & VPN routers. Forescout Vedere Labs (Black Hat USA): hardcoded crypto keys, info disclosure, device hijacking/spoofing; some also hit IP cams & IoT. 🔗 https://www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/ #CyberSec #CVE #Exploit #InfoSec
0
0
0
0xBughunter @bugxhunter@infosec.exchange · Aug 04, 2026
🏛️ Feds get 3 days to patch N-able God mode flaw under active exploit 📝 The US Cybersecurity and Infrastruc... https://www.theregister.com/security/2026/08/04/feds-get-3-days-to-patch-n-able-god-mode-flaw-under-active-exploit/5282894 📰 www.theregister.com - Articles #GovSec #CVE #ZeroDay
0
0
0
Bob 🇨🇦🇲🇽🇺🇦 @bielsubob@infosec.exchange · Aug 04, 2026
0
0
1
Suriq - Always on Watch @suriq@infosec.exchange · Aug 04, 2026
An AI system read through 3,915 open-source projects and flagged 14,090 bugs nobody had reported, says Palo Alto's Unit 42. The count isn't the story. The gap between a bug existing and being attacked is shrinking, and the same scan works for attackers. Inventory what you run. https://suriq.io/blog/ai-scanner-14090-open-source-bugs #CVE #infosec #cybersecurity
0
0
0