24h | 7d | 30d

Overview

  • Microsoft
  • Windows Server 2012

12 May 2026
Published
01 Jun 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.10%

KEV

Description

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Statistics

  • 21 Posts
  • 605 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

So CVE-2026-41089 (CVSS 9.8) in Windows Netlogon can be triggered by sending a username that is AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA or longer.
How original.

  • 191
  • 329
  • 1
  • 21h ago
Profile picture fallback

:brdScream2: Hello, CVE-2026-41089. My name is AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA

  • 15
  • 42
  • 0
  • 18h ago
Profile picture fallback

hmm. CVE-2026-41089 looks like a super basic stack buffer overflow in LSASS, straight out of a remote packet. I know Microsoft runs CodeQL over their code, and I can't envision a world where LSASS doesn't have coverage, so that raises questions about how it wasn't identified. my best guess is a process gap somewhere, but it would be cool to see a post incident report with info.

(and before one of you mentions the slopcoding thought-terminating cliché, maybe think about it for a minute first)

  • 4
  • 18
  • 0
  • 16h ago
Profile picture fallback
CVE-2026-41089 — Microsoft Windows Netlogon BuildSamLogonResponse Stack-based Buffer Overflow RCE

https://aretiq.ai/research/vul260513-cve-2026-41089-microsoft-windows-netlogon-buildsamlogonresponse-stack-based-buffer-overflow-rce/
  • 2
  • 1
  • 0
  • 21h ago
Profile picture fallback

CVE-2026-41089 be like

  • 0
  • 1
  • 0
  • 18h ago
Profile picture fallback

@zombie042 :brdThink:

MS08-067
9 years later
MS17-010
9 years later
CVE-2026-41089

  • 0
  • 1
  • 0
  • 15h ago
Profile picture fallback

Am I mistaken that essentially zerologon v2 came out? CVE-2026-41089

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

Per Microsoft details:

How could an attacker exploit this vulnerability?

An attacker could send a specially crafted network request to a Windows server that is acting as a domain controller. If successful, this could cause the Netlogon service to improperly handle the request, potentially allowing the attacker to run code on the affected system without needing to sign in or have prior access.

msrc.microsoft.com/update-guid

I don't think they fully understand the words "specially crafted".

Screaming at a network login for compliance is special... but it's not the kind of special you are looking for.

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
CVE-2026-41089 — Microsoft Windows Netlogon BuildSamLogonResponse Stack-based Buffer Overflow RCE aretiq.ai -> Original->
  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback
Kritische Sicherheitslücke CVE-2026-41089 in Netlogon wird aktiv ausgenutzt. Ungepatchte Windows-Server können ohne Authentifizierung kompromittiert werden. CVSS 9,8. #Windows #Sicherheit
  • 0
  • 0
  • 1
  • 23h ago
Profile picture fallback
URGENT PATCH NOW: CVE-2026-41089 – The Zerologon-Level Netlogon RCE Being Mass-Exploited in the Wild + Video Introduction: CVE-2026-41089 is a CVSS 9.8 stack-based buffer overflow vulnerability in the Windows Netlogon service. This critical flaw allows an unauthenticated, remote attacker to…
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
Hang on, RCE in netlogon and Belgium is saying it’s actively being exploited? CVE-2026-41089 Either internal networks are going to be on fire or something ain’t right with the actively exploited bit ccb.belgium.be/advisories/w...
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Windows Netlogonのリモートコード実行(RCE)が悪用され、ドメインコントローラーが危険にさらされています(CVE-2026-41089) Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) #HelpNetSecurity (Jun 1) www.helpnetsecurity.com/2026/06/01/w...
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) - Help Net Security https://www.helpnetsecurity.com/2026/06/01/windows-netlogon-rce-exploited-cve-2026-41089/ オンプレでADサーバ建ててるなら対応済みと思いますががが
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
Windows NetlogonのRCE脆弱性が攻撃に悪用される(CVE-2026-41089) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45887/
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
🚨 Une faille critique déjà exploitée… êtes-vous protégé ? Le Centre pour la #cybersécurité de Belgique (CCB) a publié une alerte à propos de la CVE-2026-41089. 🔐 Ne laissez pas cette faille ouverte dans votre environnement #Windows
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
Critical Windows Netlogon RCE flaw now exploited in attacks #RCE #Windows (CVE-2026-41089) www.bleepingcomputer.com/news/microso...
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
📢 CVE-2026-41089 : exploitation active de la faille RCE critique Windows Netlogon 📝 ## 🗓️ Contexte Source : BleepingComputer, publié le 1er juin 2026. https://cyberveille.ch/posts/2026-06-02-cve-2026-41089-exploitation-active-de-la-faille-rce-critique-windows-netlogon/ #CVE_2026_33825 #Cyberveille
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • flippercode
  • WP Maps Pro

29 May 2026
Published
29 May 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.07%

KEV

Description

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonce field of the wpgmp_local JavaScript object, rendering the check ineffective as an access control mechanism. This makes it possible for unauthenticated attackers to invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wp_insert_user() and returns a magic login URL that, when visited, calls wp_set_auth_cookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.

Statistics

  • 18 Posts
  • 2 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

A WordPress plugin sold to 15,000 sites has a flaw that lets anyone create an admin account, and attackers are already using it
thenextweb.com/news/wp-maps-pr

Posted into Sustainability @sustainability-thenextweb

  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback

WP Maps Pro Vulnerability Used to Generate Admin Accounts on WordPress Websites #wordpress

Critical WordPress alert: A vulnerability in WP Maps Pro (CVE-2026-8732) allows unauthenticated creation of admin accounts on affected sites (versions 6.1.0 and earlier). Exploits enable backdoors, content changes, and full site takeover. Update to WP Maps Pro 6.1.1 now. More details: ift.tt/rD2835w

Source: ift.tt/rD2835w | Image: ift.tt/8Bei13V

  • 0
  • 1
  • 0
  • 17h ago
Profile picture fallback

Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts

**Critical Alert:** A severe vulnerability (CVE-2026-8732) has been identified and requires immediate attention from security teams worldwide.

## The Details

securitycyber.uk

Resources: securitycyber.uk | hackthebox.com

  • 0
  • 0
  • 7
  • 16h ago
Profile picture fallback

WP Maps Pro CVE-2026-8732 (CVSS 9.8) — privilege escalation unauthenticated. Attackers creano admin account istantanei, takeover completo. 3.600 exploit attempts/giorno. Fix: upgrade a 6.1.1. #wordpress #cybersecurity

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

⚠️ CRITICAL: Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts

Critical privilege escalation vulnerability CVE-2026-8732 in WP Maps Pro is actively being exploited to create unauthorized administrator accounts on WordPress sites. Any unpatched installation is at immediate risk of complete site takeover. This affects all versions prior to 6.1.1.

threatnoir.com/focus

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
CVE-2026-8732 in WP Maps Pro is being actively exploited — 2,858 attacks in 24 hours. Attackers are creating admin accounts on unpatched WordPress sites. Update or disable the plugin now. #WordPress #Cybersecurity snip.ly/cwy2ra
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
📢 CVE-2026-8732 : faille critique dans WP Maps Pro exploitée pour créer des comptes admin WordPress 📝 ## 🗓️ Contexte Source : Bleeping… https://cyberveille.ch/posts/2026-06-01-cve-2026-8732-faille-critique-dans-wp-maps-pro-exploitee-pour-creer-des-comptes-admin-wordpress/ #CVE_2026_8732 #Cyberveille
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Unauthenticated attackers exploit CVE-2026-8732 in WP Maps Pro to create administrator accounts and gain full site control via a weak nonce-protected AJAX endpoint.
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
WP Maps Pro CVE-2026-8732 is being exploited to create admin accounts and seize WordPress sites. The flaw scores 9.8 CVSS and was patched in version 6.1.1. #WPMapsPro #CVE20268732 #WordPress
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
CVE-2026-8732:WP Maps Proの脆弱性により、誰でもパスワードなしでWordPress管理画面を作成できてしまう CVE-2026-8732: The WP Maps Pro Flaw That Lets Anyone Create a WordPress Admin Without a Password #SecurityAffairs (Jun 1) securityaffairs.com/192977/hacki...
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
WordPressプラグイン WP Maps Proで重大な脆弱性 CVE-2026-8732-サイバー攻撃への悪用確認 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Palo Alto Networks
  • Cloud NGFW

13 May 2026
Published
30 May 2026
Updated

CVSS v4.0
HIGH (7.8)
EPSS
36.34%

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Statistics

  • 9 Posts
  • 2 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Palo Alto: Neue Schwachstelle, neue Angriffe

Die Sicherheitslücke CVE-2026-0257 im Betriebssystem PAN-OS der Firma Palo Alto wurde am 2026-05-13 veröffentlicht. Die Firma hielt die Lücke für nicht sonderlich gefährlich; sie brachte Updates für die verschiedenen Ausgaben von PAN-OS nach und nach in den folgenden Tagen. Am 2026-05-29 berichtete das Sicherheitsunternehmen Rapid7, dass es erfolgreiche Angriffe gegen diese Sicherheitslücke beobachtet hat. Weitere Nachforschungen ergaben, dass die Sicherheitslücke mindestens seit 2026-05-17 angegriffen wird. Zumindest die frühen Angriffe müssen als Zero-Day angesehen werden

pc-fluesterer.info/wordpress/2

#Empfehlung #Hintergrund #Warnung #0day #cybercrime #exploits #firewall #router #sicherheit #spionage #UnplugTrump #vpn

  • 0
  • 1
  • 0
  • 7h ago
Profile picture fallback

📰 Actively Exploited PAN-OS Flaw (CVE-2026-0257) Allows VPN Hijack, CISA Adds to KEV

🚨 ACTIVE EXPLOITATION: A PAN-OS flaw (CVE-2026-0257) in GlobalProtect is being exploited to bypass auth & hijack VPNs. CISA has added it to the KEV catalog. Patch now! #CVE #Vulnerability #PaloAltoNetworks

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/pa

  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

**Critical Alert:** A severe vulnerability (CVE-2026-0257) has been identified and requires immediate attention from security teams worldwide.

## The Details

securitycyber.uk

Resources: securitycyber.uk | hackthebox.com

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

⚠️ CRITICAL: Attackers are exploiting Palo Alto Networks defect that initially flew under the radar

Palo Alto Networks GlobalProtect portals and gateways are under active attack via CVE-2026-0257, a critical authentication-bypass vulnerability. Attackers can forge valid auth cookies using public TLS certificates and gain VPN access with a single HTTP request. All affected customers are at immedia…

threatnoir.com/focus

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
Weekly recap: active exploitation of PAN-OS and Prisma Access flaw CVE-2026-0257, a critical Gogs zero-day, and AI-driven phishing, poisoned dev tools, and identity abuse across open-source and enterprise systems. #PANOS #Gogs #OAuth
  • 0
  • 1
  • 0
  • 12h ago
Profile picture fallback
📢 Exploitation active de CVE-2026-0257 : contournement d'authentification GlobalProtect VPN 📝 ## 🔍 Contexte Source : BleepingComputer, publié le 3… https://cyberveille.ch/posts/2026-06-01-exploitation-active-de-cve-2026-0257-contournement-d-authentification-globalprotect-vpn/ #CISA_KEV #Cyberveille
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Attackers are actively exploiting CVE-2026-0257 in Palo Alto PAN-OS GlobalProtect VPNs to bypass authentication and gain access without valid credentials. CISA has added the flaw to its Known Exploited Vulnerabilities catalog. via @darkreading.bsky.social www.darkreading.com/threat-intel...
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
ハッカーがPalo Alto GlobalProtect VPNの認証バイパス脆弱性(CVE-2026-0257)を悪用しています Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) #HelpNetSecurity (Jun 1) www.helpnetsecurity.com/2026/06/01/h...
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-0257) PAN-OS GlobalProtect Authentication Bypass via Forged Override Cookies". #cybersecurity #AttackSurfaceManagement #EASM https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Google
  • Android

01 Jun 2026
Published
02 Jun 2026
Updated

CVSS
Pending
EPSS
0.01%

KEV

Description

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Statistics

  • 9 Posts
  • 20 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Google disclosed CVE-2025-48595 to OEMs in a security preview release near the end of September 2025. Those patches are allowed to be shipped right away, so it was included in our 2025092501 release. We noted it was already publicly fixed so it was added to our regular releases too in 2025100300.

  • 1
  • 4
  • 1
  • Last hour
Profile picture fallback

📰 Android Zero-Day Under Attack: Google Issues Urgent Patch for Privilege Escalation Flaw

⚠️ ANDROID ZERO-DAY! Google has patched CVE-2025-48595, a privilege escalation flaw actively exploited in the wild. The fix is in the June 2026 security update, which patches 124 flaws total. Update your Android device NOW! #Android #ZeroDay #CyberSe...

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/go

  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
June 2026 Android Security Bulletin notes CVE-2025-48595 is being exploited in the wild. It's being widely misreported in tech media as a 0-day vulnerability being exploited. That's a major misunderstanding of Android Security Bulletins and how poorly OEMs keep up with patches.
  • 1
  • 12
  • 1
  • Last hour
Profile picture fallback
Google fixes actively exploited Android vulnerability (CVE-2025-48595) 📖 Read more: www.helpnetsecurity.com/2026/06/02/a... #cybersecurity #cybersecuritynews #vulnerability #securityupdate #CVE #Android
  • 1
  • 1
  • 0
  • 4h ago
Profile picture fallback
Android update patches 124 vulnerabilities, including exploited zero-day CVE-2025-48595, with additional critical and high issues enabling privilege escalation, DoS, and one remote code execution flaw.
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
Google пусна юнските актуализации за сигурност на Android, които отстраняват 124 уязвимости, включително една уязвимост от типа „нулев ден“ (CVE-2025-48595), активно експлоатирана от злонамерени лица в целенасочени атаки за получаване на достъп до изпълнение на код и повишаване на привилегиите на...
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
~Cybergcca~ CCCS issued 3 advisories, noting Android CVE-2025-48595 may be under targeted exploitation. - IOCs: CVE-2025-48595 - #Android #CVE202548595 #ThreatIntel
  • 0
  • 0
  • 0
  • Last hour

Overview

  • themeum
  • Kirki – Freeform Page Builder, Website Builder & Customizer

02 Jun 2026
Published
02 Jun 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.12%

KEV

Description

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

🚩 CRITICAL: CVE-2026-8206 in Kirki Page Builder (v6.0.0 – 6.0.6) lets unauth attackers reset any user password & hijack WordPress accounts. No patch yet — admins should disable or monitor plugin. Details: radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 11h ago
Profile picture fallback

CVE-2026-8206 - Critical Privilege Escalation in Kirki WordPress plugin (v6.0.0-6.0.6). Unauthenticated account takeover via password reset email manipulation. CVSS 9.8. No patch available—disable immediately. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-820

  • 1
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
Vulnerabilità nel plug-in Kirki: migliaia di siti WordPress a rischio 📌 Link all'articolo : www.redhotcyber.com/post/vulnera... A cura di Carolina Vivianti #redhotcyber #news #cybersecurity #hacking #wordpress #kirki #vulnerabilita #CVE20268206
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Oracle Corporation
  • WebLogic Server

16 Jul 2024
Published
02 Jun 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
89.65%

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Statistics

  • 3 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
~Cisa~ CISA added Oracle WebLogic Server vulnerability CVE-2024-21182 to its KEV catalog due to active exploitation. - IOCs: CVE-2024-21182 - #CVE202421182 #ThreatIntel #WebLogic
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
CISAが既知の悪用された脆弱性を1件カタログに追加 CISA Adds One Known Exploited Vulnerability to Catalog #CISA (Jun 1) CVE-2024-21182 Oracle WebLogic Serverの特定されていない脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
CISA warns that Oracle WebLogic CVE-2024-21182 is being exploited remotely and without authentication, and federal agencies must remediate it by June 4.
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Microsoft
  • Microsoft Malware Protection Engine

20 May 2026
Published
01 Jun 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
8.01%

Description

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Statistics

  • 3 Posts

Last activity: 5 hours ago

Bluesky

Profile picture fallback
🚨 Manual de Emergencia: Alerta de #Microsoft por #Filtración de 6 Zero-Days (CVE-2026-41091) www.newstecnicas.com/2026/05/manu...
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
📢 RedSun (CVE-2026-41091) : Élévation de privilèges via le workflow de remédiation de Windows Defender 📝 📰 **Source** : blog.calif.i… https://cyberveille.ch/posts/2026-06-02-redsun-cve-2026-41091-elevation-de-privileges-via-le-workflow-de-remediation-de-windows-defender/ #CVE_2026_41091 #Cyberveille
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
🚨 #Vulnerabilidad crítica de escalada de privilegios en #Microsoft #Defender (CVE-2026-41091 / CVE-2026-45498) (+MITIGACIÓN) www.newstecnicas.com/2026/05/vuln...
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • Microsoft
  • Microsoft Defender Antimalware Platform

14 Apr 2026
Published
01 Jun 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
7.07%

Description

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Statistics

  • 2 Posts

Last activity: 1 hour ago

Bluesky

Profile picture fallback
🛡️ #Vulnerabilidad CVE-2026-33825 en #Windows Defender: Solución y Mitigación Paso a Paso www.newstecnicas.com/2026/06/vuln...
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
📢 CVE-2026-41089 : exploitation active de la faille RCE critique Windows Netlogon 📝 ## 🗓️ Contexte Source : BleepingComputer, publié le 1er juin 2026. https://cyberveille.ch/posts/2026-06-02-cve-2026-41089-exploitation-active-de-la-faille-rce-critique-windows-netlogon/ #CVE_2026_33825 #Cyberveille
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Linux
  • Linux

01 Jun 2026
Published
02 Jun 2026
Updated

CVSS
Pending
EPSS
0.02%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that cifs.upcall treats as kernel-originating inputs. However, userspace can also create keys of this type through request_key(2) or add_key(2), allowing those fields to be supplied without CIFS origin. Only accept cifs.spnego descriptions while CIFS is using its private spnego_cred to request the key.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 7 hours ago

Bluesky

Profile picture fallback
🧵 Un investigador armat amb un framework d'IA ha descobert una vulnerabilitat crítica al kernel Linux que permet escalar a root. El codi vulnerable portava 19 anys amagat. El bug: CVE-2026-46243, "CIFSwitch" heyitsas.im/posts/cifswi...
  • 2
  • 1
  • 0
  • 7h ago

Overview

  • Microsoft
  • Windows 11 Version 24H2

19 May 2026
Published
01 Jun 2026
Updated

CVSS v3.1
MEDIUM (6.8)
EPSS
0.11%

KEV

Description

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. Mitigation FAQs Should I leverage the temporary mitigation? Microsoft recommends that you consider implementing these mitigations if you are concerned your devices and data are at risk of being compromised or stolen. For example, if your organization’s employees take their work devices home or on business travel. What impact to service availability/management could be caused by implementing the mitigations? Implementing these mitigations will not impact service availability or management operations. Do customers need to revert the changes made to mitigate the vulnerability once the security update to protect against this vulnerability is available? No. The security update will maintain the mitigation's behavior once the security update is installed. I am using TPM+PIN, am I at risk of this vulnerability being exploited No, if you are using TPM+PIN the vulnerability is not exploitable.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 15 hours ago

Fediverse

Profile picture fallback

@maxleibman

“When I actively asked you to communicate with me, you refused, humiliated me and made sure to insult me in front of people,” they wrote on Saturday. “You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so and I still happily did like an idiot.”

Nightmare also noted that “Microsoft still has chains in my hands,” preventing them from releasing “documents” yet, or anytime in June, and then warned: “Mark this date July 14th, I will make sure your bones are shattered that day.”

turn off the Internet till morale improves.

reddit.com/r/sysadmin/comments

@Kierkegaanks

Why does he sound like Ea Nassir?

reddit.com/r/sysadmin/comments

  • 1
  • 1
  • 0
  • 15h ago
Showing 1 to 10 of 54 CVEs