24h | 7d | 30d

Overview

  • N-able
  • N-central

02 Aug 2026
Published
03 Aug 2026
Updated

CVSS v4.0
HIGH (8.2)
EPSS
1.48%

KEV

Description

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Statistics

  • 5 Posts
  • 17 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Some time ago I discovered a meddler in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse:

status.n-able.com/2026/08/02/n

  • 5
  • 5
  • 0
  • 9h ago
Profile picture fallback

CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.

securityonline.info/cve-2026-1

  • 1
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers.
  • 2
  • 2
  • 0
  • 2h ago
Profile picture fallback
CVE-2026-18577 enables authentication bypass in N-central, letting attackers take over accounts, gain admin access, and persist via Cloudflare tunnels.
  • 1
  • 0
  • 0
  • 7h ago
Profile picture fallback
Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) 🔗 Read more: www.helpnetsecurity.com/2026/08/03/c... #vulnerability #remotemanagement #cybersecuritynews
  • 1
  • 0
  • 0
  • 5h ago

Overview

  • rails
  • rails

30 Jul 2026
Published
01 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.70%

KEV

Description

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

Statistics

  • 4 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

📰 Ruby on Rails Patches Critical RCE Flaw (CVE-2026-66066)

Ruby on Rails patches critical RCE vulnerability CVE-2026-66066 (CVSS 9.5). The flaw in Active Storage allows arbitrary file read via crafted image uploads, leading to potential RCE. Update immediately. #RubyOnRails #CVE #CyberSecurity

🔗 cyber.netsecops.io/articles/ru

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) 📖 Read more: www.helpnetsecurity.com/2026/08/03/k... #securityupdate #tips #vulnerability #webapplicationsecurity #cybersecurity #cybersecuritynews @rubyonrails.org.web.brid.gy @ethiack.com
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
📢 Ruby on Rails corrige une vulnérabilité critique RCE via lecture arbitraire de fichiers (CVE-2026-66066) 📰 Source : SecurityWeek, publié le 1er août 2026. L'article rapporte la publication de correctifs par les mainteneurs de Ruby… 🟡 vérification factuelle moyenne #RCE #RubyOnRails #Cyberveille
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
📢 CVE-2026-66066 : faille critique dans Rails Active Storage avec potentiel RCE 📰 Source : BleepingComputer — publié le 1er août 2026 🔍 Contexte Les mainteneurs de Ruby on Rails ont publié un avis de sécurité concernant… 🟡 vérification factuelle moyenne #ActiveStorage #RCE #Cyberveille
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

14 May 2026
Published
19 Jun 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
70.31%

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati


@informatica
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per installare OWAReaper, una backdoor che sopravvive a reset password e reimaging. Colpiti enti

  • 2
  • 0
  • 0
  • 7h ago
Profile picture fallback

📰 Russian Group Midnight Blizzard Exploits Outlook XSS Flaw (CVE-2026-42897)

Russian actor Midnight Blizzard (Storm-2945) exploits Outlook XSS flaw CVE-2026-42897 to access mailboxes. Also hijacks hotel Wi-Fi in 'CaptiveCrunch' campaign to steal M365 tokens with CornFlake & ChocoShell malware. #ThreatIntel #APT

🔗 cyber.netsecops.io/articles/ru

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
~Checkpoint~ Critical vulnerabilities in VMware, Cisco, and JetBrains are actively exploited alongside state-sponsored phishing and supply chain attacks. - IOCs: CVE-2026-59309, CVE-2026-20316, CVE-2026-42897 - #Phishing #ThreatIntel #Vulnerabilities
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • TP-Link Systems Inc.
  • TL-WR940N v6

29 Jul 2026
Published
30 Jul 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.81%

KEV

Description

The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occurs when a LAN client initiates a connection to a malicious RTSP server controlled by an attacker. A specially crafted RTSP message may trigger improper memory handling within the kernel module Successful exploitation of this vulnerability may result in a denial-of-service (DoS) condition or allow remote code execution (RCE), potentially leading to full compromise of the device. This vulnerability can be exploited by an unauthenticated attacker under the device's default configuration.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 14 hours ago

Fediverse

Profile picture fallback

A TP-Link TL-WR940N flaw, CVE-2026-12935, allows unauthenticated remote code execution via an RTSP stack buffer overflow. Update the router firmware now.

securityonline.info/tp-link-wr

  • 1
  • 1
  • 0
  • 18h ago

Bluesky

Profile picture fallback
TP-Link TL-WR940N CVE-2026-12935 認証なしでのリモートコード実行を可能にする脆弱性 TP-Link TL-WR940N CVE-2026-12935 Allows Unauthenticated Remote Code Execution #DailyCyberSecurity (Aug 3) securityonline.info/tp-link-wr94...
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • checkpoint
  • Security Management Server

03 Aug 2026
Published
03 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

CRITICAL auth bypass (CVE-2026-18574, CVSS 9.3) affects Check Point Security Management Server & MDS. Remote attackers can execute commands w/o auth. No patch yet — restrict management access. radar.offseq.com/threat/cve-20 🔒

  • 0
  • 1
  • 0
  • 6h ago
Profile picture fallback

CVE-2026-18574 is a Check Point authentication bypass rated CVSS 9.3, letting attackers run commands as admin. Patch via the latest Jumbo Hotfix.

securityonline.info/cve-2026-1

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

14 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
1.05%

KEV

Description

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Statistics

  • 2 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Certighost: cuando un usuario de dominio puede acabar obteniendo un certificado de un Domain Controller (CVE-2026-54121)

Si durante los últimos años ha habido una tecnología de Active Directory que ha pasado de ser la gran olvidada a convertirse en uno de los objetivos favoritos de Red Teams y atacantes reales, esa es Active Directory Certificate Services (AD CS). Desde la publicación de Certified Pre-Owned...

hackplayers.com/2026/07/certig

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
Microsoft trava falha Certighost que entregava controlo total de redes corporativas. A Microsoft disponibilizou atualizações de segurança para corrigir a CVE-2026-54121, uma falha de gravidade alta no Active Directory Certificate Services (ADCS) que permitia a um utilizador com acessos básicos manip
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Adobe
  • Adobe Campaign Classic

30 Jul 2026
Published
03 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.54%

KEV

Description

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Nutzt wer Adobe Campaign Classic (ACC) und hat noch nicht gepatcht? Zwei fette Sicherheitslücken (CVSS 3.x von 10.0 bei einer).

borncity.com/blog/2026/08/03/a

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now.

securityexpress.info/adobe-cam

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Cisco
  • Cisco Secure Firewall Management Center (FMC)

29 Jul 2026
Published
01 Aug 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
0.79%

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Statistics

  • 2 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

📰 CISA Warns of Actively Exploited Cisco Firewall Management Flaw

📢 CISA WARNING: A static credential flaw in Cisco Secure Firewall Management Center (CVE-2026-20316) is actively exploited. The flaw allows unauthorized access. CISA adds it to KEV catalog, mandating federal action. #CVE202620316 #Cisco #KEV

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
~Checkpoint~ Critical vulnerabilities in VMware, Cisco, and JetBrains are actively exploited alongside state-sponsored phishing and supply chain attacks. - IOCs: CVE-2026-59309, CVE-2026-20316, CVE-2026-42897 - #Phishing #ThreatIntel #Vulnerabilities
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • ArcadeData
  • arcadedb

01 Aug 2026
Published
03 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.32%

KEV

Description

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints with arbitrary database parameters.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-67342 - Critical auth bypass in ArcadeDB HTTP endpoints. Attackers can access or modify unauthorized databases. CVSS 9.8. No patch yet, restrict exposure immediately. #CVE #ArcadeDB #infosec

valtersit.com/cve/CVE-2026-673

  • 1
  • 2
  • 0
  • 7h ago

Overview

  • Ubiquiti Inc
  • UniFi Protect Floodlight

02 Jul 2026
Published
02 Jul 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.34%

KEV

Description

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the UniFi Protect Floodlight.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-55111 - Path Traversal in UniFi Protect Floodlight exposes device files. CVSS 7.5. No patch yet, restrict network access now. #CVE #Ubiquiti #infosec

valtersit.com/cve/cve-2026-551

  • 1
  • 1
  • 0
  • 4h ago
Showing 1 to 10 of 50 CVEs