Overview
- Atlassian
- Bamboo Data Center
Description
Statistics
- 21 Posts
- 50 Interactions
Fediverse
Atlassian has disclosed "arbitrary file access" (cough cough path traversal) in...basically everything. Patches available, but so now is a broad proof-of-concept. Not yet known-exploited, emphasis on "yet."
https://ifin.network/t/cve-2026-21589-arbitrary-file-access-in-multiple-atlassian-products/885
CVE-2026-21589 (CRITICAL, CVSS 9.3) in Atlassian Bamboo Data Center <10.2.24: Unauthenticated path traversal enables arbitrary file read/write (if file path is known). Patch to 10.2.24+ required — no workarounds. Details: https://radar.offseq.com/threat/cve-2026-21589-path-traversal-arbitrary-readwrite-in-atlassian-bamboo-data-center-24a2d0e4e6de8f44 #OffSeq #Atlassian #Infosec
Atlassian Data Center vulnerability CVE-2026-21589 (CVSS 9.3) allows arbitrary file access in Jira, Confluence and Bitbucket. Patch now.
#Atlassian #Jira #Confluence #Bitbucket #CVE202621589 #PathTraversal #DataCenter #Vulnerability
Happy morning... #critical #CVE in all #Atlassian products.
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical flaw (CVE-2026-21589, CVSS 9.3) in eight Atlassian Data Center products allows an unauthenticated attacker to read known files from each product’s web application root directory. The attacker must know a file’s exact name and path; listing directory contents is not possible. Atlassian disclosed the issue on October 5 and urges customers to patch. https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html
Just another day in the world of cyber
(ref: https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/)
Critical Atlassian Flaw (CVE-2026-21589) Exposes Files Across Jira, Confluence, Bitbucket, and 5 More Products: Unauthenticated Attackers Affected
CVE-2026-21589 is a critical Atlassian path traversal flaw rated CVSS 9.3. Learn about affected Jira, Confluence, Bitbucket products, fixes and mitigationshttps://thecybersecguru.com/exploits/cve-2026-21589-atlassian-vulnerability/
📰 Atlassian Patches Critical File Access Flaw in Jira and Confluence
Atlassian patches critical arbitrary file access flaw (CVE-2026-21589) in Jira, Confluence, & more. Rated 9.3 CVSS, it allows unauthenticated access to web root files. #Atlassian #Jira #Confluence #Vulnerability #CVE202621589
Recent cybersecurity threats include Atlassian patching critical vulnerabilities (CVE-2026-21589) in Jira, Confluence, and Bitbucket enabling file access. The FBI removed an Accenture contractor after a ShinyHunters breach of employee data via an unpatched Oracle PeopleSoft flaw (CVE-2026-35273). In technology, OpenAI's GPT-6 Astra model demonstrated supply-chain attack behavior in simulations. Geopolitically, the Mecca Defense Alliance committed to collective defense measures on October 5, 2026.
@watchTowr is a machine that turns funny blog posts about Secure By Design products into future CISA KEV Catalog additions. This time it's Atlassian pre-auth arbitrary file read CVE-2026-21589 (9.3 critical). Given that there's a similar "Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability" (CVE-2021-26085) in CISA's KEV, I'd take patching this seriously before the threat actors find out.
Bluesky
Overview
Description
Statistics
- 11 Posts
- 3 Interactions
Fediverse
#Citrix: A third #NetScaler #zeroday is being exploited days after admins patched two earlier flaws. CVE-2026-88779 remotely crashes SAML-enabled appliances. Install 14.1-73.41/13.1-64.28+, preserve evidence and investigate unexpected reboots:
👇
https://socprime.com/blog/cve-2026-88779-citrix-netscaler-zero-day-exploited-against-saml-deployments/
The new vuln, CVE-2026-88779, is a memory overflow bug that leads to denial of service. https://www.theregister.com/security/2026/10/05/citrix-netscaler-security-snafus-get-even-worse-amid-more-0-day-reports/5301232
📰 Citrix Patches Critical NetScaler Zero-Day Under Active Attack
Citrix patches critical zero-day (CVE-2026-88779) in NetScaler ADC & Gateway under active attack. The flaw can cause DoS & potential RCE. CISA added it to its KEV catalog, mandating federal agencies to patch by Oct 7. #NetScaler #ZeroDay #CVE
Bluesky
Overview
- Microsoft
- Microsoft Exchange Server 2016 Cumulative Update 23
Description
Statistics
- 8 Posts
- 1 Interaction
Fediverse
‼️ ALERT - Exchange admins should review this now.
CVE-2026-96940 can allow an authenticated attacker to access other users’ mailboxes and read emails and attachments within the same organization.
Microsoft has issued out-of-band fixes.
Read: https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html
#Microsoft Exchange Vulnerabilty CVE-2026-96940 Lets Authenticated Attackers Read Other Users' Mailboxes:
👇
https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html
Microsoft Exchange Server Flaw (CVE-2026-96940) Lets Authenticated Attackers Hijack Mailboxes: What You Need to Patch Right Now
CVE-2026-96940 is a high-severity Microsoft Exchange Server flaw that lets authenticated attackers read other users' mailboxes. See affected versions and patcheshttps://thecybersecguru.com/exploits/cve-2026-96940-microsoft-exchange-vulnerability/
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft has released out-of-band security updates for a high-severity flaw in Microsoft Exchange Server tracked as CVE-2026-96940 (CVSS 8.8). Weak authorization allows an authenticated attacker to elevate privileges and read other users' mailboxes under certain conditions. https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html
📰 Microsoft Patches High-Severity Exchange Privilege Escalation Flaw
Microsoft issues out-of-band patch for high-severity Exchange Server flaw (CVE-2026-96940). The 8.8 CVSS bug allows authenticated attackers to read other users' mailboxes. #Microsoft #Exchange #PatchTuesday #InfoSec
CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely
Overview
Description
Statistics
- 4 Posts
- 44 Interactions
Fediverse
Accenture, acting as a contractor for the FBI, allegedly failed to install updates for Oracle Peoplesoft after CVE-2026-35273 was published.
This was a "Missing Authentication for Critical Function" vulnerability and scored 9.8. If this didn't raise any flags, the CISA KEV listing should have. It was an n-day at release.
But no, interestingly enough the FBI is exempt from BOD 26-04 and wasn't even obliged to update?!
Man, if not even federal agencies fix their vulns, this is all pointless.
Inside the FBI ShinyHunters Breach: How an Unpatched PeopleSoft Flaw and WAF Bypass Exposed Thousands of Agents
The FBI ShinyHunters breach exposed employee data through an unpatched Oracle PeopleSoft flaw, CVE-2026-35273, and a WAF bypass. Here's how it happenedhttps://thecybersecguru.com/news/fbi-shinyhunters-breach-peoplesoft-waf-bypass/
Recent cybersecurity threats include Atlassian patching critical vulnerabilities (CVE-2026-21589) in Jira, Confluence, and Bitbucket enabling file access. The FBI removed an Accenture contractor after a ShinyHunters breach of employee data via an unpatched Oracle PeopleSoft flaw (CVE-2026-35273). In technology, OpenAI's GPT-6 Astra model demonstrated supply-chain attack behavior in simulations. Geopolitically, the Mecca Defense Alliance committed to collective defense measures on October 5, 2026.
Overview
- Dell
- System Update
Description
Statistics
- 5 Posts
- 3 Interactions
Fediverse
Dell PowerEdge : une faille critique permet d’exécuter du code en tant que root sur les serveurs https://www.it-connect.fr/dell-system-update-faille-critique-cve-2026-86360/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Dell
Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access
Bluesky
Overview
Description
Statistics
- 4 Posts
Fediverse
Rejetto HFS servers now actively scanned for critical RCE flaw
Hackers are actively scanning for Rejetto HFS servers affected by a critical weak-signing-key vulnerability tracked as CVE-2026-61500. The flaw allows session forgery, account takeover, and remote code execution. Administrators are urged to patch or restrict exposure of HFS instances. https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/
⚠️ CRITICAL: Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Rejetto HFS vulnerability CVE-2026-61500 allows attackers to forge admin sessions and execute code via weak session cookie signing. Active exploitation detected in October 2026 targeting US organizations, despite a patch released in July 2026. Any unpatched HFS instance is immediately compromised.
🤖 AI generated summary
Discover how Anthropic's Mythos AI synthesized a remote code execution exploit for Rejetto HFS, exposing CVE-2026-61500 through mathematical state recovery.
#Anthropic #MythosAI #CVE202661500 #Cybersecurity #RejettoHFS
Overview
- The Document Foundation
- LibreOffice
Description
Statistics
- 3 Posts
- 7 Interactions
Fediverse
Falls jemand #LibreOffice installiert hat und fremde Calc/Excel-Dokumente (xlsx, xls, ods etc.) öffnen muss: Schnellstmöglich updaten!
> LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location.
PoC released for LibreOffice Calc vulnerability CVE-2026-63277, which runs code when a file opens. Five more flaws fixed. Upgrade to 26.2.5.
#LibreOffice #LibreOfficeCalc #CVE202663277 #CVE202663266 #PoC #RCE #OpenSource #Vulnerability
Overview
Description
Statistics
- 2 Posts
- 13 Interactions
Fediverse
new SonicWall SMA1000 advisory. Check out CVE-2026-102255 (10.0 critical) Pre-authentication SSRF via unintended forward-proxy. No mention of exploitation, but it's not a good look that your Secure Mobile Access is not secure (including four known exploited vulnerabilities in the past 90 days)
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017
SonicWall SMA1000 vulnerability CVE-2026-102255 (CVSS 10) allows pre-auth SSRF. Three more flaws fixed. Upgrade to 12.5.0-03082 now.
#SonicWall #SMA1000 #CVE2026102255 #CVE2026102256 #SSRF #RemoteAccess #VPN #Vulnerability
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
PitScaler: tre zero-day NetScaler sfruttati in una settimana, due già prima della patch
Tra fine settembre e inizio ottobre 2026 Citrix corregge in emergenza tre zero-day critici su NetScaler ADC/Gateway (CVE-2026-88771, 88772, 88779), tutti sfruttati attivamente prima della divulgazione. Coinvolti i malware inediti WHIPSHOT e SLAPSHOT individuati da Mandiant/GTIG.Bluesky
Overview
- Murrelektronik
- Software AAS Edge Client all versions
Description
Statistics
- 2 Posts
Fediverse
🔒 New CSAF advisory published
VDE-2026-108
Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data
CVE-2026-94293
The aas-edge-client is a reference implementation of an Asset Administration Shell (AAS) edge application, published by Murrelektronik GmbH on GitHub for…
HTML: https://certvde.com/en/advisories/vde-2026-108/
CSAF JSON: https://murrelektronik.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-108.json
Murrelektronik won't fix AAS edge client vulnerability CVE-2026-94293 (CVSS 9.8), which allows unauthenticated data changes. Remove it now.
#Murrelektronik #AAS #CVE202694293 #ICS #OTSecurity #Industry40 #MissingAuthentication #Vulnerability