Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

ZEN SecDB

@secdb@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

ZEN #SecDB Portal provides an easy to use web interface to #CVE vulnerability data. You can browse for vendors, products and versions and view CVE entries, vulnerabilities, related to them. You can view statistics about vendors, products and versions of products.

ZEN SecDB Portal: https://secdb.nttzen.cloud

SecDB Telegram Channel: https://t.me/secdbportal_feed
SecDB Telegram Bot: https://t.me/secdbportal_bot

21 Followers
0 Following
10 Posts
Joined September 22, 2025
Website:
https://secdb.nttzen.cloud
Advisories:
https://secdb.nttzen.cloud/security-advisory
Vulnerabilities:
https://secdb.nttzen.cloud/cve
Sightigs:
https://secdb.nttzen.cloud/sightings
Dashboard:
https://secdb.nttzen.cloud/dashboard
About:
https://secdb.nttzen.cloud/about
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago
🚨 DirtyClone (CVE-2026-43503) In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/updates/9a1828d5-6607-419b-b475-622a6c135aae/dirtyclone-vulnerability #nttdata #zen #secdb #infosec #dirtyclone #linux #lpe #cve202643503
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago

🚨 Bad Epoll (CVE-2026-46242) has been identified as a notable vulnerability.

In the Linux kernel, the following vulnerability has been resolved:

eventpoll: fix ep_remove struct eventpoll / struct file UAF

ℹ️ Additional information on ZEN SecDB:

  • BadEpoll: https://secdb.nttzen.cloud/updates/79198418-b310-4e40-80cd-d98ba3da0b2a/bad-epoll-vulnerability

  • CVE details, sightings and advisories: https://secdb.nttzen.cloud/cve/detail/CVE-2026-46242

#InfoSec #BadEpoll #CVE202646242 #Linux #Kernel

#NTTDATA #Zen #SecDB #VulnerabilityIntelligence #Security

0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago

🚨 [CISA-2026:0707] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48908 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48908)

  • Name: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: JoomShaper
  • Product: SP Page Builder
  • Notes: https://extensions.joomla.org/extension/sp-page-builder/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48908

⚠️ CVE-2026-55255 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-55255)

  • Name: Langflow Authorization Bypass Through User-Controlled Key Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Langflow
  • Product: Langflow
  • Notes: https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-55255

⚠️ CVE-2026-56290 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56290)

  • Name: Joomlack Page Builder Improper Access Control Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Joomlack
  • Product: Page Builder
  • Notes: https://www.joomlack.fr/en/joomla-extensions/page-builder-ck ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-56290

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260707 #cisa20260707 #cve_2026_48908 #cve_2026_55255 #cve_2026_56290 #cve202648908 #cve202655255 #cve202656290

0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago

🚨 [CISA-2026:0710] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48939 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48939)

  • Name: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: iCagenda
  • Product: iCagenda
  • Notes: https://www.icagenda.com/#download ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48939

⚠️ CVE-2026-56291 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)

  • Name: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Balbooa
  • Product: Forms
  • Notes: https://www.balbooa.com/joomla-forms ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-56291

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260710 #cisa20260710 #cve_2026_48939 #cve_2026_56291 #cve202648939 #cve202656291

0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago

📈 CVE Published in last days (2026-07-06 - 2026-07-06) See more at https://secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:

  • Critical: 137
  • High: 558
  • Medium: 580
  • Low: 131
  • None: 157

Status:

  • : 92
  • Analyzed: 371
  • Awaiting Analysis: 94
  • Deferred: 632
  • Modified: 5
  • Received: 230
  • Rejected: 12
  • Undergoing Analysis: 127

CISA KEVs:

  • CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
  • CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)

Top CNAs:

  • GitHub, Inc.: 452
  • Wordfence: 178
  • VulnCheck: 138
  • VulDB: 94
  • N/A: 92
  • MITRE: 58
  • Apache Software Foundation: 56
  • Drupal.org: 46
  • Foxit: 28
  • Chrome: 27

Top Affected Products:

  • UNKNOWN: 1134
  • Apache Camel: 34
  • Foxit Pdf Reader: 28
  • Foxit Pdf Editor: 28
  • Google Chrome: 27
  • Coder: 20
  • Openwebui Open Webui: 15
  • Joomla!: 12
  • N8n: 12
  • Wireshark: 12

Top EPSS Score:

  • CVE-2026-43825 - 8.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-43825)
  • CVE-2026-44454 - 2.64 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-44454)
  • CVE-2026-34038 - 2.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34038)
  • CVE-2025-30007 - 2.08 % (https://secdb.nttzen.cloud/cve/detail/CVE-2025-30007)
  • CVE-2026-60102 - 1.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60102)
  • CVE-2026-33264 - 1.65 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-33264)
  • CVE-2026-40047 - 1.57 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-40047)
  • CVE-2026-48316 - 1.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48316)
  • CVE-2026-34599 - 1.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34599)
  • CVE-2026-59800 - 1.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59800)

#ZEN #SecDB #InfoSec

0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago

🚨 [CISA-2026:0715] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2023-4346 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-4346)

  • Name: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: KNX Association
  • Product: KNX Protocol Connection Authorization Option 1
  • Notes: https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-4346

⚠️ CVE-2026-46817 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-46817)

  • Name: Oracle E-Business Suite Improper Privilege Management Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Oracle
  • Product: E-Business Suite
  • Notes: https://www.oracle.com/security-alerts/cspumay2026.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-46817

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260715 #cisa20260715 #cve_2023_4346 #cve_2026_46817 #cve20234346 #cve202646817

0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago

🚨 [CISA-2026:0721] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2021-27137 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-27137)

  • Name: DD-WRT Stack-Based Buffer Overflow Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: DD-WRT
  • Product: DD-WRT
  • Notes: This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://svn.dd-wrt.com/changeset/45724 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-27137

⚠️ CVE-2026-0770 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0770)

  • Name: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Langflow
  • Product: Langflow
  • Notes: https://github.com/langflow-ai/langflow/releases/tag/v1.9.0 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-0770

⚠️ CVE-2026-60137 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)

  • Name: WordPress Core SQL Injection Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: WordPress
  • Product: Core
  • Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-60137

⚠️ CVE-2026-63030 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)

  • Name: WordPress Core Interpretation Conflict Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: WordPress
  • Product: Core
  • Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-63030

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260721 #cisa20260721 #cve_2021_27137 #cve_2026_0770 #cve_2026_60137 #cve_2026_63030 #cve202127137 #cve20260770 #cve202660137 #cve202663030

0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 1mo ago

🚨 [CISA-2026:0722] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-16232 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)

  • Name: Check Point SmartConsole Improper Authentication Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Check Point
  • Product: SmartConsole
  • Notes: https://support.checkpoint.com/results/sk/sk185169/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-16232

⚠️ CVE-2026-50522 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)

  • Name: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Microsoft
  • Product: SharePoint
  • Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-50522

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260722 #cisa20260722 #cve_2026_16232 #cve_2026_50522 #cve202616232 #cve202650522

0
0
1
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 1mo ago
🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability. In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access. ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/1d26eb14-ce27-4846-a8ce-bae087fb1e46/refluxfs-vulnerability #infosec #refluxfs #linux #kernel #xfs #lpe #nttdata #zen #secdb
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 1mo ago

🚨 [CISA-2026:0727] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-68686 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-68686)

  • Name: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Fortinet
  • Product: FortiOS
  • Notes: https://fortiguard.fortinet.com/psirt/FG-IR-25-934 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-68686

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260727 #cisa20260727 #cve_2025_68686 #cve202568686

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:55:15 UTC