24h | 7d | 30d

Overview

  • Cisco
  • Cisco Identity Services Engine Software

16 Sep 2026
Published
17 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.78%

Description

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 16 hours ago

Fediverse

Profile picture fallback

Noch ein Cisco Zero-Day (perfekte 10) unter Angriff

Ja, Cisco-Evangelisten müssen dieser Tage ganz stark sein. Kurz nach dem Desaster mit dem "sicheren" E-Mail-Gateway ist die nächste "Sicherheitslücke" aufgefallen, weil sie bereits angegriffen wird. CVE-2026-76460 hat eine perfekte 10 (von 10) als Risiko-Einstufung erhalten. Die "Sicherheitslücke" steckt in der Cisco Identity Services Engine (ISE). Wie der Name nahelegt, ist die Aufgabe dieser Funktion, Benutzer/innen zu identifizieren und dann für bestimmte Tätigkeiten zu autorisieren. Die Schwachstelle entsteht durch, ich zitiere: "... insufficient authentication control ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #backdoor #closedsource #exploits #hersteller #identität #sicherheit #UnplugTrump #zeroday #cisco

  • 1
  • 0
  • 0
  • 19h ago
Profile picture fallback

Cisco ISE zero-day CVE-2026-76460 is being actively exploited.

The CVSS 10.0 flaw allows remote, unauthenticated attackers to bypass authentication and potentially execute commands with root privileges.

Cisco says there is no complete workaround and recommends upgrading immediately.

Read more here:
forum.hashpwn.net/post/16740

  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback

📰 Cisco ISE Zero-Day (CVSS 10.0) Under Active Attack, Bypasses Auth

Cisco warns of a critical (CVSS 10.0) zero-day in Identity Services Engine (ISE) actively exploited in the wild. The flaw, CVE-2026-76460, allows full authentication bypass. CISA added to KEV catalog. Patch immediately! #Cisco #ZeroDay #CyberSecurity

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 16h ago

Overview

  • checkpoint
  • Quantum Security Management

16 Sep 2026
Published
17 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.50%

KEV

Description

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 13 hours ago

Fediverse

Profile picture fallback

Check Point Security Mgmt & Log Server face CRITICAL stack buffer overflow (CVE-2026-91843). Remote, unauthenticated RCE as root possible. Patch now or restrict access, monitor for 'Username too long' login failures. radar.offseq.com/threat/new-ch

  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback

📰 Check Point Patches Critical RCE Flaw in Management Servers

Check Point patches critical RCE flaw (CVE-2026-91843, CVSS 9.8) in Security Management Servers. Unauthenticated attackers can gain root access via a long username. LivePatch is available. Restrict trusted client access now! #CyberSecurity #CheckPoin...

🔗 cyber.netsecops.io/articles/ch

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
A Check Point flaw (CVE-2026-91843) lets an attacker run code with root privileges, reportedly by sending an oversized username that triggers the bug. Detection is straightforward: watch for "Administrator failed to log in: Username too long" alerts in admin login logs. Patch and check those logs.
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Google
  • Android

15 Sep 2026
Published
17 Sep 2026
Updated

CVSS
Pending
EPSS
0.21%

Description

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Statistics

  • 2 Posts

Last activity: 22 hours ago

Bluesky

Profile picture fallback
📢 [VULN] Google confirme un piratage des Pixel via une faille du modem - CVE-2026-58704 Google a confirmé que ses smartphones Pixel ont été piratés à la suite d’attaques ciblées exploitant une faille de type zero-day dans le modem. #ZeroDay #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
CVE-2026-58704 was exploited in Pixel cellular modems before fixes, enabling privilege escalation without user interaction; CISA ordered federal agencies to patch within three days.
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

11 Aug 2026
Published
16 Sep 2026
Updated

CVSS v3.1
HIGH (7.0)
EPSS
6.18%

Description

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Bluesky

Profile picture fallback
"August 2026 Threat Trend Report on APT Groups" published by Ahnlab. #Trend, #DreamJob, #Kimsuky, #Lazarus, #FamousChollima, #JasperSleet, #PolinRider, #CVE202668820 https://asec.ahnlab.com/en/95478
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
~Asec~ APT groups abused legitimate services, AI, supply chains and zero-days for espionage and access. - IOCs: webhook[.]Site, CVE-2026-68820 - #APT #SupplyChain #ThreatIntel
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • HCL Software
  • HCL BigFix Service Management

18 Sep 2026
Published
18 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.35%

KEV

Description

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.

Statistics

  • 2 Posts

Last activity: 22 hours ago

Fediverse

Profile picture fallback

CVE-2026-67100: HCL BigFix Service Management v23 faces CRITICAL SQL injection & cross-tenant data exposure (CVSS 9.8). Authenticated attackers can access PII across orgs. No patch yet — restrict access & monitor logs. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback

HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.

securityonline.info/hcl-bigfix

  • 0
  • 0
  • 0
  • 22h ago

Overview

  • GNU
  • inetutils

13 Mar 2026
Published
23 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
23.67%

KEV

Description

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

Statistics

  • 1 Post
  • 7 Interactions

Last activity: 21 hours ago

Overview

  • conductor-oss
  • conductor

30 Jun 2026
Published
14 Jul 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
9.26%

KEV

Description

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 23 hours ago

Bluesky

Profile picture fallback
CVE-2026-58138 enables unauthenticated remote code execution in Orkes Conductor via hostile INLINE workflow expressions that run OS commands as the Conductor process.
  • 1
  • 0
  • 0
  • 23h ago

Overview

  • Linux
  • Linux

25 Jun 2026
Published
19 Sep 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.12%

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 16 hours ago

Fediverse

Profile picture fallback

CISA warned of exploited Linux kernel vulnerabilities in the KEV catalog. Patch these Linux kernel vulnerabilities to block privilege escalation.

securityonline.info/linux-kern

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
~Cisa~ CISA reports active exploitation and urges rapid remediation. - IOCs: CVE-2025-39964, CVE-2026-53266 - #CVE-2025-39964 #CVE-2026-53266 #ThreatIntel
  • 1
  • 0
  • 0
  • 16h ago

Overview

  • Linux
  • Linux

13 Oct 2025
Published
19 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.32%

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 16 hours ago

Fediverse

Profile picture fallback

CISA warned of exploited Linux kernel vulnerabilities in the KEV catalog. Patch these Linux kernel vulnerabilities to block privilege escalation.

securityonline.info/linux-kern

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
~Cisa~ CISA reports active exploitation and urges rapid remediation. - IOCs: CVE-2025-39964, CVE-2026-53266 - #CVE-2025-39964 #CVE-2026-53266 #ThreatIntel
  • 1
  • 0
  • 0
  • 16h ago

Overview

  • ModelTC
  • LightLLM
  • LightLLM

18 Sep 2026
Published
18 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Go hack more LLM shit.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.

  • 0
  • 4
  • 0
  • 10h ago
Showing 1 to 10 of 58 CVEs