24h | 7d | 30d

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts
  • 5 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Defend against the CVE-2026-51990 Sogou exploit. Discover how hackers use this one-click flaw to drop backdoors and how to secure your systems today.

securityonline.info/cve-2026-5

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.
  • 3
  • 2
  • 0
  • 12h ago

Overview

  • checkpoint
  • Quantum Security Gateway

09 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.33%

KEV

Description

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Statistics

  • 4 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

@cyberwald Bevor man hier einen Hersteller zu CVEs verurteilt, sollte man vielleicht tiefer recherchieren und dazu ein paar Fakten hinzufügen.

Beide Schwachstellen wurden intern entdeckt und bis zur Veröffentlichung gab es keine Hinweise darauf, dass sie in freier Wildbahn ausgenutzt wurden. Weiterhin gab es zu jedem CVE direkt entsprechende Anweisungen und Patches:

Darüber hinaus gibt es mittlerweile die Funktion Check Point Live Patch (CPLP), welches ein im Betriebssystem Gaia enthaltener Dienst zur Bereitstellung von Abwehrmaßnahmen ist. Es schließt kritische Schwachstellen im laufenden Betrieb durch gezielte In-Memory-Korrekturen (Live-Patches). -> support.checkpoint.com/results



  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback

Check Point patches two critical VPN gateway flaws scoring 9.8 on CVSS

Check Point patches two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, rated CVSS 9.8 and capable of unauthenticated remote code execution

thecybersecguru.com/news/check

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

📰 Check Point patches two critical 9.8 CVSS flaws in VPN products

Check Point patches two critical 9.8 CVSS vulnerabilities (CVE-2026-85102, CVE-2026-85103) in its VPN products. Flaws could allow unauthenticated RCE. Admins are urged to apply hotfixes immediately. #CyberSecurity #Vulnerability #VPN #PatchNow

🔗 cyber.netsecops.io/articles/ch

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • Last hour

Overview

  • irontec
  • sngrep

12 Sep 2026
Published
12 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Bluesky

Profile picture fallback
sngrep: fix CVE-2026-90558 https://github.com/NixOS/nixpkgs/pull/562971 https://tracker.security.nixos.org/issues/NIXPKGS-2026-2567 #security
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
Merged PRs for 2026-09-13 Packages #563033 wlr-utils: 1.7.0 -> 1.8.0 #563024 linux_testing: 7.3-rc2 -> 7.3-rc3 #563020 vaultwarden: 1.37.2 -> 1.37.3 #562984 npb: add changelog #562972 workflows/periodic-merge: use correct permissions #562971 sngrep: fix CVE-2026-90558
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • checkpoint
  • Quantum Security Gateway

09 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.36%

KEV

Description

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

Statistics

  • 4 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

@cyberwald Bevor man hier einen Hersteller zu CVEs verurteilt, sollte man vielleicht tiefer recherchieren und dazu ein paar Fakten hinzufügen.

Beide Schwachstellen wurden intern entdeckt und bis zur Veröffentlichung gab es keine Hinweise darauf, dass sie in freier Wildbahn ausgenutzt wurden. Weiterhin gab es zu jedem CVE direkt entsprechende Anweisungen und Patches:

Darüber hinaus gibt es mittlerweile die Funktion Check Point Live Patch (CPLP), welches ein im Betriebssystem Gaia enthaltener Dienst zur Bereitstellung von Abwehrmaßnahmen ist. Es schließt kritische Schwachstellen im laufenden Betrieb durch gezielte In-Memory-Korrekturen (Live-Patches). -> support.checkpoint.com/results



  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback

Check Point patches two critical VPN gateway flaws scoring 9.8 on CVSS

Check Point patches two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, rated CVSS 9.8 and capable of unauthenticated remote code execution

thecybersecguru.com/news/check

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

📰 Check Point patches two critical 9.8 CVSS flaws in VPN products

Check Point patches two critical 9.8 CVSS vulnerabilities (CVE-2026-85102, CVE-2026-85103) in its VPN products. Flaws could allow unauthenticated RCE. Admins are urged to apply hotfixes immediately. #CyberSecurity #Vulnerability #VPN #PatchNow

🔗 cyber.netsecops.io/articles/ch

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • Last hour

Overview

  • jfrog
  • artifactory

28 Aug 2026
Published
03 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
7.67%

Description

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Statistics

  • 2 Posts

Last activity: Last hour

Bluesky

Profile picture fallback
Critical Authentication Bypass in JFrog Artifactory CVE-2026-82329 https://simplysecuregroup.com/attackers-exploit-critical-jfrog-artifactory-flaw-to-mint-admin-tokens-days-after-disclosure https://flagthis.com/tldr/6838 ##SupplyChain ##Vulnerability ##JFrog ##AuthenticationBypass
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • NetScaler
  • ADC

19 Aug 2026
Published
10 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
5.60%

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Statistics

  • 2 Posts

Last activity: 13 hours ago

Fediverse

Profile picture fallback

¿Seguimos confiando demasiado?

Anderson hablaba de confianza en seguridad informática a comienzos de los años 70.

Más de cincuenta años después tenemos Cloud, SaaS, Zero Trust, MFA, PAM, EDR y tecnologías que en aquella época hubieran parecido ciencia ficción.

Entonces me hice una pregunta:

¿El problema también cambió?

En lugar de buscar la respuesta en otro paper, decidí mirar algunas vulnerabilidades recientes:

CVE-2026-20079
CVE-2026-19490
CVE-2025-25249
CVE-2026-20212

Authentication bypass, problemas de memoria, componentes de infraestructura...

Vulnerabilidades técnicamente muy diferentes.

Pero hay una pregunta interesante que podemos hacerle a cada una:

¿Qué tuvo que asumir el sistema para que esa vulnerabilidad pudiera existir?

De eso hablaremos próximamente

¿Seguimos confiando demasiado? —
De Anderson a la Inteligencia Artificial

  • 0
  • 0
  • 0
  • 13h ago

Bluesky

Profile picture fallback
Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

💡 Tabs & Accordions v3.1.0

Changes:
⚠️ [SECURITY FIX] Fixes crafted data-rlta-alias attributes allowing JavaScript execution when matching links are clicked (CVE-2026-85191)
👉 Adds an open-narrow attribute to set a different initial open state on narrow screens
👉 Adds the documented JavaScript function for closing a specific tab or accordion
👉 and 9 more

Changelog: regularlabs.com/tabsaccordions

  • 1
  • 1
  • 0
  • 11h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

💡 ReReplacer v16.2.0

With ReReplacer you can replace whatever you want in your entire site.

Changes:
⚠️ [SECURITY FIX] [PRO] Fixes Condition Set labels allowing access to unrelated database fields (CVE-2026-85188)
👉 [PRO] Adds settings to restrict who can save PHP Condition Rules
👉 [PRO] Removes the automatic Download Key popup (inline field remains available)
👉 and 17 more

Changelog: regularlabs.com/rereplacer/cha

  • 1
  • 1
  • 1
  • 11h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

💡 Quick Index v5.0.5

With Quick Index you can easily add an index (or ToC) to your content.

Changes:
⚠️ [SECURITY FIX] Fixes crafted index class options allowing JavaScript injection (CVE-2026-85190)
👉 [PRO] Removes the automatic Download Key popup (inline field remains available)
👉 [PRO] Fixes "Only when ordered" heading numbers also appearing on unordered individual levels
👉 and 9 more

Changelog: regularlabs.com/quickindex/cha

  • 1
  • 1
  • 0
  • 11h ago

Overview

  • GitLab
  • GitLab

12 Sep 2026
Published
12 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
1.16%

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 21 hours ago

Fediverse

Profile picture fallback

2026-W37 — Weekly Threat Roundup

🤖 AI is no longer just a defender's tool: state-sponsored groups and criminals weaponized Claude, ChatGPT, and OpenAI agents to automate exploitation, rebuild malware, and generate one million personalized phishing emails in three days.
🔓 GitLab's CVSS 10.0 path traversal flaw (CVE-2026-85706) wa…

threatnoir.com/weekly/2026-w37

🤖 AI generated summary

  • 1
  • 0
  • 0
  • 21h ago
Showing 1 to 10 of 55 CVEs