24h | 7d | 30d

Overview

  • Google
  • Android

15 Sep 2026
Published
17 Sep 2026
Updated

CVSS
Pending
EPSS
0.11%

Description

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Statistics

  • 20 Posts
  • 13 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Google and CISA warned that an actively exploited zero-day vulnerability (CVE-2026-58704) affecting Pixel cellular modems.

This allows attackers to silently bypass permission checks and escalate privileges with no user interaction!

It was quickly added to CISA's Known Exploited Vulnerabilities (KEV) catalog [1.2.1, 1.5.1].

Would be an excellent idea for Pixel owners to ownload and apply the September Android OS patches ASAP!

  • 4
  • 0
  • 0
  • 10h ago
Profile picture fallback

@skyblitz CVE-2026-58704 is a modem firmware vulnerability with a patch released today and it will be included in our upcoming release.

  • 0
  • 7
  • 0
  • 19h ago
Profile picture fallback

If you've got a Google Pixel cell phone, do a system patch immediately. There is an active vulnerability that allows the hacker to take control of your device with no user interaction. It is being actively used in the wild.

cve.org/CVERecord?id=CVE-2026-

  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback

📰 Google Patches Actively Exploited Zero-Day Flaw in Pixel Modems

Google patches high-severity zero-day (CVE-2026-58704) in Pixel modems. The flaw allows for remote privilege escalation and is under limited, targeted exploitation. CISA added to KEV. Update your Pixel now! #Pixel #Android #ZeroDay

🔗 cyber.netsecops.io/articles/go

  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback

(CISA TS-MAN) The Cyber Mind TSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability

Actionable threat intelligence and end-to-end hardening strategies for CVE-2026-58704, addressing improper authorization flaws in Google Pixel cellular modems....

thecybermind.co/iuw6

  • 0
  • 0
  • 1
  • 11h ago
Profile picture fallback

Google confirmed a Pixel modem zero-day (CVE-2026-58704) exploited in a zero-click spyware attack to escape the modem sandbox. Update now.

securityexpress.info/pixel-mod

  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback

「Google、限定的な標的型攻撃の兆候が見られる中、Pixelモデムの脆弱性を修正 」: #TheHackerNews

「Googleは、 明らかにした。 同社のPixel Cellular Modemに存在する深刻なセキュリティ上の欠陥が、実際に悪用されていることを

(CVSSスコア:8.0)として追跡されているこの脆弱性は CVE-2026-58704 、権限昇格の欠陥です。

によると、「セルラーモデムには、コードの論理エラーにより権限がバイパスされる可能性がある」とのことです NIST(米国国立標準技術研究所)の国家脆弱性データベース(NVD)に掲載されているバグの説明 。「これにより、追加の実行権限を必要とせずに、リモート(近接/隣接)での権限昇格が可能になる可能性がある。悪用にはユーザーの操作は不要である。」 」

thehackernews.com/2026/09/goog

#prattohome

  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback

「Google Pixel端末がゼロクリック攻撃でハッキングされる
/CISAは連邦政府機関に対し、パッチ適用にわずか3日間しか猶予を与えていない。 」: #TheRegister

「Googleと米国政府は、Pixelスマートフォンの携帯モデムに存在するゼロデイ脆弱性を悪用した攻撃者が、権限チェックを回避し、ユーザーの操作なしに権限を昇格できると警告した。この脆弱性は、アップデートを行うことで既に修正されている。

Googleは 火曜日に、 CVE-2026-58704 として追跡されているこの重大な脆弱性 を公表し 、その際、このセキュリティホールが「限定的かつ標的を絞った悪用を受けている可能性がある」と警告した。つまり、Googleが問題を修正する前に、悪意のある人物がこのバグを発見し、悪用していたということだ。」

theregister.com/security/2026/

#prattohome

  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback

@GrapheneOS funny to see google fixing : CVE-2025-48595 that was fixed looooooong ago in your.

i don't see CVE-2026-58704, is it already fixed ?

bleepingcomputer.com/news/secu

  • 1
  • 1
  • 0
  • 20h ago

Bluesky

Profile picture fallback
CVE-2026-58704 in Pixel Cellular Modem enables privilege escalation via permission bypass, with limited targeted exploitation indicated and no user interaction required.
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
Google patched a high-severity Pixel modem zero-day (CVE-2026-58704) with limited targeted exploitation, enabling remote privilege escalation without user interaction.
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
Pixel, Google chiude una falla zero-day nel modem già sfruttata in attacchi Google corregge sui Pixel CVE-2026-58704, falla nel modem cellulare già associata ad attacchi mirati. La pat... https://www.ilsoftware.it/google-pixel-zero-day-modem-attacchi/
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
A Pixel modem software bug (CVE-2026-58704) enabled zero-click privilege escalation in targeted attacks and has been patched by Google.
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
~Cisa~ CISA added CVE-2026-58704 to its KEV Catalog after evidence of active exploitation. - IOCs: CVE-2026-58704 - #CVE-2026-58704 #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
~Cybergcca~ Seven advisories cover Android, Chrome, ICS, HPE, Oracle, Apple and BIND; CVE-2026-58704 is exploited in the wild. - IOCs: CVE-2026-58704 - #CVE-2026-58704 #CyberSecurity #ThreatIntel
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Google Pixel Vulnerability Exploited: CVE-2026-58704 Enables Zero-Click Privilege Escalation(Google Pixelの脆弱性CVE-2026-58704、ゼロクリック攻撃で悪用) #SecurityOnline (Sep 16) securityonline.info/google-pixel...
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
CISA Adds One Known Exploited Vulnerability to Catalog(CISA、悪用が確認された1件の脆弱性をKEVカタログに追加) #CISA (Sep 16) CVE-2026-58704 Google Pixelの不適切な認証の脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
Google Pixel phones were targeted by zero-click attacks exploiting a cellular modem vulnerability (CVE-2026-58704). This flaw allowed privilege escalation without user interaction. The vulnerability has since been patched. Ensure your device is updated. #cybersecurity #News
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
Google Pixelスマートフォンがゼロクリック攻撃の標的に(CVE-2026-58704) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47781/
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Cisco
  • Cisco Identity Services Engine Software

16 Sep 2026
Published
17 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
Pending

Description

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Statistics

  • 8 Posts
  • 17 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Patch your Cisco ISE. CVE-2026-76460 a perfect 10 and is EITW. 🥳

sec.cloudapps.cisco.com/securi

The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.

  • 10
  • 5
  • 0
  • 14h ago
Profile picture fallback

CRITICAL auth bypass (CVE-2026-76460) in Cisco ISE & ISE-PIC is being actively exploited. Remote attackers gain root on management interface via crafted API calls. Patch ASAP — no workarounds except ACLs. Details: radar.offseq.com/threat/active

  • 0
  • 1
  • 0
  • Last hour
Profile picture fallback

An exploited Cisco ISE vulnerability (CVE-2026-76460) allows remote root access. Patch this critical Cisco ISE vulnerability to secure networks.

securityonline.info/cisco-ise-

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

「Ciscoは、ISEのゼロデイ脆弱性が攻撃に悪用され、深刻な被害を受ける可能性があると警告している。 」: #BLEEPINGCOMPUTER

「シスコは、攻撃者が実際に悪用している、深刻度が最大レベルのアイデンティティサービスエンジンの脆弱性に対処するためのセキュリティアップデートをリリースしました。

Cisco ISEは、IT管理者がエンドポイント、ユーザー、およびデバイスのネットワークリソースへのアクセスを管理するために使用する集中型ポリシープラットフォームであり、多くの場合、ゼロトラストセキュリティモデルを適用しながら使用されます。

このセキュリティ上の欠陥( CVE-2026-76460 として追跡)により、リモートの攻撃者は、Cisco Identity Services Engine(ISE)およびCisco ISE Passive Identity Connector(ISE-PIC)のAPIの脆弱性を悪用することで、設定に関係なく認証を回避できます。 」

bleepingcomputer.com/news/secu

#prattohome

  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
Cisco released urgent patches for CVE-2026-76460, a zero-day authentication bypass in Cisco ISE that enables web management access and root command execution.
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
Cisco ISE Flaw Under Active Exploitation With Maximum Severity Score Tracked as CVE-2026-76460, the flaw carries a CVSS score of 10.0 and could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access to affected systems.
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
~Cisa~ CISA added Cisco ISE and Acronis Backup flaws to its KEV Catalog, citing active exploitation. - IOCs: CVE-2026-76460, CVE-2026-87886 - #CVE-2026-76460 #CVE-2026-87886 #ThreatIntel
  • 1
  • 0
  • 0
  • 12h ago
Profile picture fallback
CISA Adds Two Known Exploited Vulnerabilities to Catalog(CISA、悪用が確認された2件の脆弱性をKEVカタログに追加) #CISA (Sep 16) CVE-2026-76460 Cisco Identity Services Engineにおける特権APIの不適切な使用に関する脆弱性 CVE-2026-87886 Acronis Backupのデフォルト権限設定の誤りに関する脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Cisco
  • Cisco Secure Email

14 Sep 2026
Published
15 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.01%

Description

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Statistics

  • 9 Posts
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Global cybersecurity agencies, including CISA & NSA, issued guidance to mitigate 17 Active Directory compromise techniques (Sept 16). Cisco patched an actively exploited email gateway zero-day (CVE-2026-76461). Geopolitically, the US confirmed deploying space weapons, drawing warnings from China about an arms race (Sept 15). AI is now the leading driver for new cybersecurity spending.

#Cybersecurity #Geopolitics #TechNews

  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback

Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution esecurityplanet.com/threats/ne

  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback

Recent developments include Cisco patching a critical zero-day (CVE-2026-76461) in its Secure Email Gateway, which was actively exploited for root command execution. Geopolitically, China warned against weaponizing space after the US confirmed orbital weapon deployments. In technology, debates continue on AI safety versus national competitive advantage, with US Speaker Johnson rejecting development pauses.

#Cybersecurity #Geopolitics #AnonNews_irc

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) - Help Net Security www.helpnetsecurity.com/2026/09/15/c...
  • 0
  • 1
  • 0
  • 19h ago
Profile picture fallback
Cisco Secure Email GatewayにCVE-2026-76461 細工メールでroot権限RCE、実際のサイバー攻撃で悪用確認 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ
  • 0
  • 0
  • 1
  • 6h ago
Profile picture fallback
~Arcticwolf~ Unauthenticated attackers actively exploit Cisco Secure Email Gateway to execute root code via crafted email; patch now. - IOCs: CVE-2026-76461 - #CVE202676461 #Cisco #ThreatIntel
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
The latest update for #ArcticWolf includes "CVE-2026-76461: Active Exploitation of Cisco Secure Email Gateway Critical Zero-Day Vulnerability Immediate Mitigation Required" and "We Need to Pace AI Development. We Can't Pace AI Defense". #cybersecurity #infosec #networks https://opsmtrs.com/2ZFbaTl
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-70756) Oracle WebLogic Server Takeover via T3 and IIOP" and "Emerging Threat: (CVE-2026-76461) Cisco Secure Email Gateway Root RCE via Email Parsing". #cybersecurity #AttackSurfaceManagement #EASM https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • checkpoint
  • Quantum Security Management

16 Sep 2026
Published
17 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

Statistics

  • 5 Posts
  • 13 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

🚨New Censys Advisory: CVE-2026-91843

A critical (CVSS 9.8) unauthenticated RCE affects Check Point Quantum Security Management and Log Servers.

Censys observes 3,836 hosts globally exposing the management/log server role. This is total product presence, not a confirmed-vulnerable count.

No public PoC or confirmed exploitation has been reported as of publication. Check Point has released patches for supported versions via LivePatch.

Read the analysis and remediation details: censys.com/advisory/cve-2026-9

  • 2
  • 2
  • 0
  • 9h ago
Profile picture fallback

🚨 Please read this important update from Check Point:

CVE-2026-91843 - Stack overflow in login process to the Security Management and Log Servers

support.checkpoint.com/results

  • 1
  • 1
  • 0
  • 12h ago
Profile picture fallback

Check Point fixed a critical Check Point login flaw (CVE-2026-91843). Patch this Check Point login flaw now to block unauthenticated remote root takeovers.

securityonline.info/check-poin

  • 1
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
🚨CVE-2026-91843 is a critical (CVSS 9.8) pre-auth RCE affecting Check Point Quantum Security Management and Log Servers. Censys sees 3,836 hosts globally with the management/log server role. No public PoC or confirmed exploitation as of publication. Patches are available. https://bit.ly/4cRApEJ
  • 3
  • 3
  • 0
  • 9h ago
Profile picture fallback
Check Point Login Flaw CVE-2026-91843: Critical Root RCE via Unauthenticated Login(Check Pointのログイン処理に重大な脆弱性、認証不要でroot権限のRCE) #SecurityOnline (Sep 16) securityonline.info/check-point-...
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Issabel Foundation
  • Issabel Framework

15 Sep 2026
Published
15 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.52%

KEV

Description

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.

Statistics

  • 4 Posts
  • 3 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

‼️ Attackers are exploiting a critical Issabel Framework flaw.

CVE-2026-89026 uses a hard-coded JWT signing key, letting unauthenticated remote attackers forge tokens and execute OS commands as the Asterisk user. A fix is available.

How the flaw works: thehackernews.com/2026/09/atta

  • 1
  • 1
  • 0
  • 9h ago
Profile picture fallback

An Issabel PBX vulnerability exploited in active attacks allows remote code execution. Patch this Issabel PBX vulnerability to secure systems.

securityonline.info/issabel-pb

  • 0
  • 0
  • 0
  • 22h ago

Bluesky

Profile picture fallback
CVE-2026-89026 enables unauthenticated remote command execution in Issabel Framework via a hard-coded JWT signing key.
  • 1
  • 0
  • 0
  • 15h ago
Profile picture fallback
Critical Issabel Framework flaw CVE-2026-89026 (CVSS 9.8) is being exploited to forge JWT tokens and run OS commands without authentication. Patch released Aug 1, 2026. #Issabel #CVE-2026-89026 #Shadowserver
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • ConnectWise
  • ScreenConnect

08 Sep 2026
Published
12 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.69%

Description

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

Statistics

  • 3 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-84869 – ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

C-Suite threat intelligence and mitigation protocols for CVE-2026-84869, addressing active exploitation vectors within enterprise ConnectWise environments....

thecybermind.co/pxxw

  • 0
  • 0
  • 0
  • 17h ago

Bluesky

Profile picture fallback
CISA says CVE-2026-84869 is being actively exploited in ConnectWise ScreenConnect, enabling file transfer or execution. Over 1,000 exposed instances remain unpatched. #ScreenConnect #CISA #ConnectWise
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
~Arcticwolf~ Active exploitation enables unauthorized file transfer and code execution; upgrade to 26.6.5+. - IOCs: CVE-2026-84869 - #CVE202684869 #ScreenConnect #ThreatIntel
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 7 hours ago

Bluesky

Profile picture fallback
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886) 📖 Read more: www.helpnetsecurity.com/2026/09/16/a... #backup #Linux #MSP #plugin #securityupdate #vulnerability #webhosting #cybersecurity #cybersecuritynews
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)(Acronisバックアッププラグインの脆弱性、標的型攻撃で悪用) #HelpNetSecurity (Sep 16) www.helpnetsecurity.com/2026/09/16/a...
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
~Cisa~ CISA added Cisco ISE and Acronis Backup flaws to its KEV Catalog, citing active exploitation. - IOCs: CVE-2026-76460, CVE-2026-87886 - #CVE-2026-76460 #CVE-2026-87886 #ThreatIntel
  • 1
  • 0
  • 0
  • 12h ago
Profile picture fallback
CISA Adds Two Known Exploited Vulnerabilities to Catalog(CISA、悪用が確認された2件の脆弱性をKEVカタログに追加) #CISA (Sep 16) CVE-2026-76460 Cisco Identity Services Engineにおける特権APIの不適切な使用に関する脆弱性 CVE-2026-87886 Acronis Backupのデフォルト権限設定の誤りに関する脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • NLnet Labs
  • Unbound

16 Sep 2026
Published
16 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.1)
EPSS
0.52%

KEV

Description

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CVE-2026-81642: CRITICAL heap buffer overflow in NLnet Labs Unbound ≤1.26.0. Exploitable via DNSKEY with owner compression pointer — possible DoS & RCE. Patch ASAP. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 23h ago
Profile picture fallback

NLnet Labs patched critical Unbound DNS vulnerabilities. Upgrade now to fix Unbound DNS vulnerabilities and block remote code execution attacks.

securityonline.info/unbound-dn

  • 0
  • 0
  • 0
  • 5h ago

Overview

  • WSO2
  • WSO2 Universal Gateway

06 Aug 2026
Published
06 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.32%

KEV

Description

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 16 hours ago

Fediverse

Profile picture fallback

📰 Critical WSO2 API Flaw Under Active Attack, Exposes Enterprise Data

Critical auth bypass (CVE-2026-5430, CVSS 10.0) in WSO2 API Manager is now actively exploited. Attackers can take over admin accounts. Patched in April 2026, ensure your systems are updated! #WSO2 #APISecurity #CyberAttack

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
CVE-2026-5430 in WSO2 middleware is being exploited to bypass JWT authentication, enabling account takeover and access to API backends and credentials.
  • 1
  • 0
  • 0
  • 23h ago

Overview

  • WNC
  • T-Mobile 5G Box IDU

16 Sep 2026
Published
16 Sep 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
Pending

KEV

Description

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory entries such as "." or ".." in the cookie, allowing unauthorized access to the administration panel.This issue has been fixed in firmware version 1.1.0.651412

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Vulnerabilities in a 5g router from T-Mobile, the company known for its security?! I'm shocked. Shocked! Well, not that shocked.

cert.pl/posts/2026/09/CVE-2026


  • 0
  • 2
  • 0
  • 17h ago
Profile picture fallback

Patch the critical T-Mobile 5G Box vulnerabilities today. Learn how WNC router flaws allow auth bypass and command injection, and secure your network.

securityonline.info/t-mobile-5

  • 0
  • 0
  • 0
  • 6h ago
Showing 1 to 10 of 96 CVEs