Overview
- Atlassian
- Bamboo Data Center
Description
Statistics
- 24 Posts
- 221 Interactions
Fediverse
OK, this is an innovative directory traversal vuln:
GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1
This is from CVE-2026-21589, https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
The "::" gets replaced with "/" by some weird sanitation method, read more about it in the writeup.
Tagging @nynbinary for humorous memeing.
Daily Briefing: Church Cyberattacks Expose Member Data, Plus 3 Stories https://raymondtec.com/2026/10/church-cyberattacks-expose-member-data/
South Korean churches investigate breaches exposing member and donation data. Plus a critical Atlassian flaw, FICO layoffs, and Google’s new nuclear-power deal.
#TechNews #ArtificialIntelligenceAI #Atlassian #CVE202621589 #databreach #DataCenters #FICO
Recent developments include the US evacuating B-1 bombers from the UK due to an Iranian threat, while Hamas is reportedly plotting attacks in Gaza for October 7th. In cybersecurity, ASOS experienced a cloud breach via its Snowflake platform, and active exploitation of a critical Atlassian flaw (CVE-2026-21589) has begun. An FBI breach was also linked to a contractor error. Microsoft is hosting an AI-focused Surface event today.
CVE-2026-21589 exploitation is underway against Atlassian servers after researchers published arbitrary file read PoC and technical details.
#Atlassian #Jira #Confluence #Bitbucket #CVE202621589 #PathTraversal #ExploitedInTheWild #Vulnerability
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
Atlassian disclosed CVE-2026-21589 on Oct. 5, a critical flaw (CVSS 9.3) affecting eight self-hosted Data Center products that lets an unauthenticated attacker read specific files in each product’s web application root. The attacker must already know a file’s exact name and path and cannot list directory contents, The Hacker News reports. https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html
Atlassian Data Center flaw draws exploitation attempts within two hours of public details
Attackers began attempting to exploit the critical Atlassian Data Center flaw (CVE-2026-21589) within two hours of public details emerging, The Hacker News reports. The rapid move from disclosure to exploitation attempts shows how fast the patching window is closing. https://thehackernews.com/2026/10/atlassian-data-center-flaw-draws.html
An unauthenticated attacker can exploit CVE-2026-21589 to access specific files in the application's web root directory if they know the file's exact name and path. https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-atlassian-flaw-after-public-poc-release/
🚨 Rapid Response: CVE-2026-21589 (CVSS 9.3) is a critical arbitrary file access vulnerability affecting eight Atlassian Data Center products, including Confluence, Jira, Bitbucket, and Bamboo.
Censys currently detects 95,366 Internet-facing hosts and 431,502 web properties running affected products after excluding assets labeled as honeypots. This is product exposure, not a confirmed-vulnerable count.
Atlassian has released fixes for all eight products.
Full Censys ARC advisory: https://censys.com/advisory/cve-2026-21589/
Bluesky
Overview
Description
Statistics
- 10 Posts
- 11 Interactions
Fediverse
Chat, is it bad if your zero-trust VPN device forwards network requests without auth? Asking for thousands of friends.
SonicWall SMA1000 devices have a SSRF vulnerability that needs patching.
https://ifin.network/t/cve-2026-102255-pre-auth-ssrf-in-sonicwall-sma1000-devices/889
SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)
SonicWall has patched four vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances, including CVE-2026-102255, which could let remote unauthenticated attackers direct the appliance to issue requests on their behalf and perform unauthorized operations. The vendor says there is currently no evidence of in-the-wild exploitation, but attackers' track record with similar flaws suggests it could come soon. https://www.helpnetsecurity.com/2026/10/07/sonicwall-fixes-pre-auth-ssrf-flaw-in-sma-1000-appliances-cve-2026-102255/
Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/
SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances
🚨 Rapid Response: SonicWall has patched a critical CVSS 10.0 pre-authentication SSRF in SMA1000 appliances (CVE-2026-102255).
Censys detects 5,966 Internet-exposed hosts and 39,310 web properties running SMA1000/Secure Mobile Access after excluding honeypot-labeled systems. This indicates product presence, not confirmed-vulnerable systems.
Full Censys ARC advisory: https://censys.com/advisory/cve-2026-102255/
Bluesky
Overview
- Microsoft
- Microsoft Exchange Server 2016 Cumulative Update 23
Description
Statistics
- 7 Posts
Fediverse
CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely
Microsoft has released out-of-band security updates for Exchange Server to fix CVE-2026-96940, a high-severity (CVSS 8.8) weak authorization flaw that can let an authenticated attacker gain higher privileges. Microsoft assesses exploitation as more likely, SecurityAffairs reports. https://securityaffairs.com/200476/security/cve-2026-96940-microsoft-fixes-high-severity-exchange-server-flaw.html
Microsoft Exchange : la faille CVE-2026-96940 permet de lire les boîtes aux lettres des autres utilisateurs https://www.it-connect.fr/exchange-server-cve-2026-96940/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft
Bluesky
Overview
Description
Statistics
- 5 Posts
- 3 Interactions
Fediverse
eSentire tracks four clusters behind CVE-2026-88771 exploitation, planting NetScaler web shells and backdoor accounts. Learn how to detect them.
#CVE202688771 #CitrixNetScaler #WebShell #ZeroDay #Platypus #eSentire #EdgeSecurity #CyberSecurity
https://securityonline.info/cve-2026-88771-netscaler/?utm_source=mastodon&utm_medium=jetpack_social
@pndc Perl is back... well at least in some circles -> https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/#grep-sed-and-awkward (also a very funny read aside from the perl reference)
Jokes aside, good luck with the interview
Bluesky
Overview
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
Vorfall-Lagebild: Citrix NetScaler: Zero-Day CVE-2026-88779 wird aktiv
Nach 24 Stunden: was bekannt ist, was offen ist und was wahrscheinlich passiert ist – Citrix NetScaler: Zero-Day CVE-2026-88779 wird aktiv ausgenutzt – SAML-G
#OTSecurity #ICS #KRITIS #NIS2 #Cybersicherheit
https://ot-cyber.de/blog/vorfall-lagebild-citrix-netscaler-zero-day-cve-2026-88779-wird-aktiv.html
Citrix reveals CVE-2026-88779, a critical memory overflow flaw in NetScaler SAML configurations leading to DoS, following recent RCE zero-day attacks.
#CitrixNetScaler #Cybersecurity #CVE202688779 #SAML #ZeroDay
Overview
- Dell
- System Update
Description
Statistics
- 3 Posts
Fediverse
Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access
Dell is urging customers to patch a critical flaw (CVE-2026-86360, CVSS 9.6) in its System Update (DSU) tool, warning the path traversal vulnerability can let attackers run code as root. Affected PowerEdge systems should be patched as soon as possible, SecurityAffairs reports. https://securityaffairs.com/200458/security/dell-urges-customers-to-patch-critical-dsu-flaw-that-can-give-attackers-root-access.html
Bluesky
Overview
- Veeam
- Backup and Replication
Description
Statistics
- 2 Posts
- 6 Interactions
Fediverse
Overview
- The Document Foundation
- LibreOffice
Description
Statistics
- 2 Posts
Fediverse
A Locally exploitable vunerability in older versions of LibreOffice Calc is being Hyped.
Claims are LO is unsafe to use.
NOT TRUE, keep LibreOffice updated please read.
https://cvetodo.com/cve/CVE-2026-63277
Update to version 26.2.5 or newer as soon as possible.
Configure LibreOffice to disable or restrict external data source links, especially those referencing remote locations.
Educate users, your kids to avoid opening untrusted documents.
Difficult as kids and students may receive docs from schools.
Overview
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
Chrome 155 patches 247 vulnerabilities, including 4 CRITICAL use-after-free bugs (CVE-2026-106382, - 106197, - 106358, - 106347) across Chromecast, Browser, Navigation & Track. Update on Windows, macOS & Linux. No active exploits. https://radar.offseq.com/threat/chrome-155-update-patches-247-vulnerabilities-28750e8d96fdecb9 #OffSeq #Chrome #Security
The Chrome 155 security update fixes 247 flaws, including critical use after free bugs CVE-2026-106382 and CVE-2026-106197. Update now.
#Chrome #GoogleChrome #Chrome155 #CVE2026106382 #UseAfterFree #BrowserSecurity #PatchNow #Vulnerability
Overview
Description
Statistics
- 2 Posts
Fediverse
ASUS Router XSS (CVE-2026-14911, CRITICAL, CVSS 9.3): Remote attackers can exploit improper input neutralization to execute scripts, alter settings, or cause DoS if visited by authenticated users. No patch yet. Details: https://radar.offseq.com/threat/cve-2026-14911-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-81fca42ab40cabc9 #OffSeq #XSS #Cybersecurity
Four ASUS router vulnerabilities are fixed, including critical XSS flaw CVE-2026-14911 and code execution bug CVE-2026-19386. Update firmware now.
#ASUS #ASUSRouter #RouterSecurity #CVE202614911 #CVE202619386 #XSS #FirmwareUpdate #Vulnerability