24h | 7d | 30d

Overview

  • Microsoft
  • Microsoft Entra

20 Aug 2026
Published
22 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
1.37%

KEV

Description

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Microsoft ontdekt en fixt een zeer gevaarlijke bug in Entra ID

Het gaat om een bug met de maximale kwetsbaarheidsscore 10 en een CVSS 3.1 vector van AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Dat betekent geen authenticatie, geen gebruikersinteractie, een lage aanvalscomplexiteit, over het netwerk uitvoerbaar en met volledige impact op vertrouwelijkheid, integriteit รฉn beschikbaarheid.

#EntraID #CVE202669836 #CyberSecurity #CloudSecurity #digitalsovereignty๐Ÿ‘‡

linkedin.com/posts/janguldento

  • 0
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) - Help Net Security www.helpnetsecurity.com/2026/08/21/m...
  • 1
  • 1
  • 0
  • 13h ago
Profile picture fallback
Microsoft corregge una falla Entra ID da CVSS 10 con rischio di RCE CVE-2026-69836 colpisce Microsoft Entra ID con una falla RCE da CVSS 10.0: Microsoft ... https://www.ilsoftware.it/microsoft-corregge-una-falla-entra-id-da-cvss-10-con-rischio-di-rce/
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • GitLab
  • GitLab

17 Aug 2026
Published
17 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
1.94%

KEV

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

Critical GitLab vulnerability CVE-2026-19478 lets unauthenticated attackers delete public projects. It is exploited in the wild with public PoC.

securityonline.info/gitlab-cve

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure thehackernews.com/2026/08/gitl...
  • 1
  • 2
  • 0
  • 14h ago

Overview

  • westguard
  • WS Form LITE โ€“ Drag & Drop Contact Form Builder

22 Aug 2026
Published
22 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.90%

KEV

Description

The WS Form LITE โ€“ Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-4703 - Critical PHP Object Injection in WS Form for WordPress leads to remote code execution via insecure deserialization. CVSS 9.8. Update now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-470

  • 0
  • 1
  • 0
  • 7h ago
Profile picture fallback

CVE-2026-4703: WS Form LITE โ‰ค1.10.80 has a CRITICAL PHP Object Injection vuln via form meta deserialization. Exploitable if a POP chain exists in another plugin/theme โ€” possible RCE, file deletion, or data leak. Audit plugins/themes. radar.offseq.com/threat/the-ws

  • 0
  • 0
  • 0
  • 19h ago

Overview

  • chirpmyradio
  • CHIRP

23 Aug 2026
Published
23 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.21%

KEV

Description

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-78136 - CHIRP RCE via eval injection in crafted CSV (kenwood_itm.py). CVSS 7.8. Unpatched - upgrade once available. #CVE #infosec #CHIRP

valtersit.com/cve/CVE-2026-781

  • 0
  • 1
  • 0
  • 10h ago
Profile picture fallback

CVE-2026-78136: HIGH severity eval injection in chirpmyradio CHIRP (<39178db). Malicious CSV data can trigger arbitrary code execution. No patch yet โ€” avoid untrusted files. Full details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 15h ago

Overview

  • PTC
  • Windchill PDMLink

18 Jun 2026
Published
01 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
30.20%

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.ย  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 13 hours ago

Fediverse

Profile picture fallback

โš ๏ธ Cl0p names 40 Windchill victims

Cl0p exploited CVE-2026-12569 to deploy web shells and steal blueprints and project data.

๐Ÿ”— read more: securityaffairs.com/197587/cyb

#ransomNews #cyberthreats #Cl0p

  • 1
  • 1
  • 0
  • 13h ago

Overview

  • nltk
  • nltk

22 Aug 2026
Published
22 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.66%

KEV

Description

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-62384 - Symlink sandbox bypass in NLTK leads to arbitrary file read. CVSS 7.5. Update to version 3.10.2 now. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-623

  • 1
  • 1
  • 0
  • 4h ago
Profile picture fallback

CVE-2026-62384 - Symlink sandbox bypass in NLTK FramenetCorpusReader. Arbitrary XML file read. CVSS 7.5. Update to 3.10.2 now. #CVE #NLTK #infosec

valtersit.com/cve/CVE-2026-623

  • 0
  • 1
  • 0
  • 9h ago

Overview

  • nltk
  • nltk

22 Aug 2026
Published
22 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.49%

KEV

Description

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unhandled RecursionError that crashes the Python process.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

CVE-2026-66393 - DoS vulnerability in NLTK. Deeply nested JSON triggers unhandled recursion crash in Python. CVSS 7.5. Update to 3.9.4 immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-663

  • 1
  • 1
  • 0
  • 6h ago

Overview

  • marc4
  • Security Hardener

22 Aug 2026
Published
22 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.59%

KEV

Description

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_endpoints filter via secure_user_endpoints() and overwrites every registered handler's permission_callback on both the /wp/v2/users and /wp/v2/users/(?P<id>[\d]+) routes โ€” including POST, PUT, PATCH, and DELETE handlers โ€” with a bare closure that returns only is_user_logged_in(), completely stripping WordPress Core's original capability checks such as create_users, promote_user, edit_users, and delete_users that WP_REST_Users_Controller normally enforces. This makes it possible for authenticated attackers with Subscriber-level access and above to create new Administrator accounts by sending POST request to /wp/v2/users with administrator role, or to reset an existing Administrator's password by issuing a PUT/POST request to /wp/v2/users/<id>. Because the block_user_enum option defaults to enabled, no special plugin configuration is required โ€” the overwrite is active on every request as soon as the plugin is installed.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

CVE-2026-16149 (HIGH, CVSS 8.8): marc4 Security Hardener <=2.4.4 allows Subscriber-level users to create Admin accounts or reset passwords via REST API. Disable plugin or limit API access pending patch. radar.offseq.com/threat/cve-20

  • 1
  • 1
  • 0
  • 9h ago

Overview

  • Comfast
  • CF-N1-S

22 Aug 2026
Published
22 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.79%

KEV

Description

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_client_enabled results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 21 hours ago

Fediverse

Profile picture fallback

CRITICAL: CVE-2026-78050 in Comfast CF-N1-S (2.6.0.1) enables remote code execution via stack-based buffer overflow in web mgmt (/cgi-bin/mbox-config). Public exploit out, no patch yet. Restrict access! radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 21h ago

Overview

  • strongSwan
  • strongSwan

22 Aug 2026
Published
23 Aug 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.45%

KEV

Description

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

CVE-2026-47895 - Double-Free vulnerability in strongSwan EAP identity parsing. CVSS 7.5. Update to version 6.0.7 immediately. #CVE #strongSwan #infosec

valtersit.com/cve/CVE-2026-478

  • 0
  • 1
  • 0
  • 3h ago
Showing 1 to 10 of 24 CVEs