24h | 7d | 30d

Overview

  • jfrog
  • artifactory

28 Aug 2026
Published
02 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.24%

Description

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Statistics

  • 8 Posts
  • 4 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

Geopolitical tensions persist between the U.S. and Iran regarding actions in the Strait of Hormuz (Sept 1, 2026). On the cybersecurity front, critical infrastructure, including Midwest water utilities, faces new ransomware attacks. Additionally, a severe authentication bypass flaw (CVE-2026-82329) in JFrog Artifactory is actively being exploited. OpenAI has issued a stark warning regarding the escalating threat of AI-enabled cyberattacks.

#AnonNews_irc #Cybersecurity #Anonymous #News

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback

: Attackers are already exploiting critical auth bypass CVE-2026-82329 (CVSS 9.8) to mint admin tokens. Compromising your organisation's artifact repository could poison builds and trigger attacks - patch now!
👇
csoonline.com/article/4217534/

  • 0
  • 0
  • 1
  • 13h ago
Profile picture fallback

Angreifer nutzen derzeit eine kritische Schwachstelle in JFrog Artifactory (CVE-2026-82329) aktiv aus. Die Sicherheitslücke erlaubt das Umgehen der Authentifizierung, wodurch unberechtigte administrative Token erstellt werden können. Betroffene Betreiber müssen umgehend die bereitgestellten Software-Aktualisierungen einspielen und bestehende Tokens prüfen.

#InfoSec #CyberSecurity #ITSecurity #Vulnerability #JFrog

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access.
  • 2
  • 2
  • 0
  • 11h ago
Profile picture fallback
Critical JFrog Artifactory flaw CVE-2026-82329 is being exploited days after patching, allowing auth bypass, admin token theft, and possible supply chain compromise in default 7.x setups. #JFrogArtifactory #CVE202682329 #JFrogAccess
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
Active exploitation of CVE-2026-82329 in JFrog Artifactory lets attackers forge admin tokens on self-managed instances, risking package poisoning and downstream code execution. #JFrogArtifactory #watchTowr #CVE202682329
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
~Cybergcca~ SonicWall CVE-2026-83548/83549 and JFrog CVE-2026-82329 are being exploited and added to CISA KEV. - IOCs: CVE-2026-83548, CVE-2026-83549, CVE-2026-82329 - #CVE #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

11 Aug 2026
Published
02 Sep 2026
Updated

CVSS v3.1
HIGH (8.0)
EPSS
1.32%

KEV

Description

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Statistics

  • 5 Posts
  • 6 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Exchange Server : près de 22 000 serveurs exposés sont vulnérables à la CVE-2026-62911 it-connect.fr/microsoft-exchan #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #Exchange

  • 3
  • 1
  • 0
  • 18h ago
Profile picture fallback

Más de 21,000 servidores Microsoft Exchange siguen expuestos al CVE-2026-62911

blog.elhacker.net/2026/09/mas-

  • 0
  • 1
  • 0
  • 19h ago

Bluesky

Profile picture fallback
🛑 22 000 C'est le nombre de serveurs Exchange exposés sur le Web et potentiellement vulnérables à la faille CVE-2026-62911. Il s'agit d'une faille patchée en août 2026 par Microsoft. Plus d'infos par ici : - www.it-connect.fr/microsoft-ex... #exchange #microsoft #infosec
  • 0
  • 1
  • 0
  • 21h ago
Profile picture fallback
Microsoft Exchange ServerのCVE-2026-62911、PoC公開で警戒高まる 約2万2,000台が未更新と報道 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)(約2万2,000台のMicrosoft Exchangeサーバーが重大な脆弱性CVE-2026-62911に未対応) #HelpNetSecurity (Sep 2) www.helpnetsecurity.com/2026/09/02/m...
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • SonicWall
  • SMA1000

01 Sep 2026
Published
02 Sep 2026
Updated

CVSS
Pending
EPSS
0.27%

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Statistics

  • 11 Posts
  • 10 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

SonicWall weist aktuell auf 2 Schwachstellen in seiner SMA1000-Serie hin.
Während die nach CVSS mit 10 von 10 bewertete CVE-2026-83548 für sich alleine bereits ein erhebliches Bedrohungspotenzial für Betreiber mitbringt, ist auch eine Kombination mit der zweiten Sicherheitslücke - CVE-2026-83549 (7.8) - denkbar.
Der Hersteller berichtet von beobachteten Angriffen. IT-Sicherheitsverantwortliche sollten daher schnellstmöglich handeln: bsi.bund.de/SharedDocs/Cybersi

  • 3
  • 2
  • 0
  • 12h ago
Profile picture fallback

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

  • 2
  • 1
  • 1
  • 14h ago
Profile picture fallback

Tiens, encore du SMA1000 ...

Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.

La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.

Sont concernés les SMA1000 6210, 7210 et 8200v.

Pas de workaround : hotfix à appliquer au plus vite. ☹️

Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.

À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.

Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃

Advisory 🩹
👇
psirt.global.sonicwall.com/vul

  • 1
  • 0
  • 0
  • 20h ago
Profile picture fallback

Warning about two #vulnerabilities (CVE-2026-83548, CVE-2026-83549) in the #SMA1000 series from #SonicWall. These are already being exploited in attacks, so apply the patches.

borncity.com/win/2026/09/02/so

  • 0
  • 1
  • 0
  • 6h ago
Profile picture fallback

📰 SonicWall Warns of Two Actively Exploited Zero-Days in SMA1000

🚨 BREAKING: SonicWall warns of two actively exploited zero-days (CVE-2026-83548, CVE-2026-83549) in SMA 1000 appliances. Attackers chain the flaws for unauthenticated RCE. Patches are available and must be applied immediately. #ZeroDay #SonicWall #C...

🔗 cyber.netsecops.io/articles/so

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
SonicWall SMA1000の2件のゼロデイ 脆弱性、サイバー攻撃で悪用確認 CVE-2026-83548はCVSS 10.0、早急な更新を rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
SonicWall says attackers are chaining two actively exploited SMA1000 zero-days, CVE-2026-83548 and CVE-2026-83549, for remote code execution on 6210, 7210, and 8200v appliances. #SonicWall #SMA1000 #CVE202683548
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
Warnung vor zwei #Schwachstellen (CVE-2026-83548, CVE-2026-83549) in der #SMA1000-Series des Herstellers #SonicWall. Diese werden bereits bei Angriffen ausgenutzt, also patchen. borncity.com/blog/2026/09...
  • 0
  • 0
  • 1
  • 6h ago
Profile picture fallback
~Cybergcca~ SonicWall CVE-2026-83548/83549 and JFrog CVE-2026-82329 are being exploited and added to CISA KEV. - IOCs: CVE-2026-83548, CVE-2026-83549, CVE-2026-82329 - #CVE #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Sangoma
  • Switchvox SMB Edition

17 Jul 2026
Published
02 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
1.09%

Description

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Statistics

  • 5 Posts
  • 1 Interaction

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Angreifer nutzen aktiv eine kritische SQL-Injection-Schwachstelle (CVE-2026-9586) in der VoIP-Plattform Sangoma Switchvox aus. Die Lücke ermöglicht unauthentifizierten Akteuren die Remotecodeausführung sowie das Einrichten von Reverse Shells auf den Zielsystemen. Verantwortliche Administratoren müssen umgehend die bereitgestellten Sicherheitsupdates einspielen, um Kompromittierungen zu verhindern.

#InfoSec #CyberSecurity #ITSecurity #VoIP #Vulnerability

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
CVE-2026-9586 enables unauthenticated remote code execution in Sangoma Switchvox SMB Edition 8.3 via SQL injection, patched in 8.4.0.2.
  • 0
  • 1
  • 0
  • 19h ago
Profile picture fallback
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) 🔗 Read more: www.helpnetsecurity.com/2026/09/02/e... #vulnerability #exploit #Cybersecurity @horizon3ai.bsky.social
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 https://packetstorm.news/news/view/43034 #news
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
Hackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox, to trigger remote code execution via the /pa endpoint and deploy reverse shells. #Switchvox #Sangoma #Horizon3
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • SonicWall
  • SMA1000

01 Sep 2026
Published
02 Sep 2026
Updated

CVSS
Pending
EPSS
0.92%

Description

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

Statistics

  • 10 Posts
  • 10 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

SonicWall weist aktuell auf 2 Schwachstellen in seiner SMA1000-Serie hin.
Während die nach CVSS mit 10 von 10 bewertete CVE-2026-83548 für sich alleine bereits ein erhebliches Bedrohungspotenzial für Betreiber mitbringt, ist auch eine Kombination mit der zweiten Sicherheitslücke - CVE-2026-83549 (7.8) - denkbar.
Der Hersteller berichtet von beobachteten Angriffen. IT-Sicherheitsverantwortliche sollten daher schnellstmöglich handeln: bsi.bund.de/SharedDocs/Cybersi

  • 3
  • 2
  • 0
  • 12h ago
Profile picture fallback

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

  • 2
  • 1
  • 1
  • 14h ago
Profile picture fallback

Tiens, encore du SMA1000 ...

Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.

La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.

Sont concernés les SMA1000 6210, 7210 et 8200v.

Pas de workaround : hotfix à appliquer au plus vite. ☹️

Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.

À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.

Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃

Advisory 🩹
👇
psirt.global.sonicwall.com/vul

  • 1
  • 0
  • 0
  • 20h ago
Profile picture fallback

Warning about two #vulnerabilities (CVE-2026-83548, CVE-2026-83549) in the #SMA1000 series from #SonicWall. These are already being exploited in attacks, so apply the patches.

borncity.com/win/2026/09/02/so

  • 0
  • 1
  • 0
  • 6h ago
Profile picture fallback

📰 SonicWall Warns of Two Actively Exploited Zero-Days in SMA1000

🚨 BREAKING: SonicWall warns of two actively exploited zero-days (CVE-2026-83548, CVE-2026-83549) in SMA 1000 appliances. Attackers chain the flaws for unauthenticated RCE. Patches are available and must be applied immediately. #ZeroDay #SonicWall #C...

🔗 cyber.netsecops.io/articles/so

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
SonicWall says attackers are chaining two actively exploited SMA1000 zero-days, CVE-2026-83548 and CVE-2026-83549, for remote code execution on 6210, 7210, and 8200v appliances. #SonicWall #SMA1000 #CVE202683548
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
Warnung vor zwei #Schwachstellen (CVE-2026-83548, CVE-2026-83549) in der #SMA1000-Series des Herstellers #SonicWall. Diese werden bereits bei Angriffen ausgenutzt, also patchen. borncity.com/blog/2026/09...
  • 0
  • 0
  • 1
  • 6h ago
Profile picture fallback
~Cybergcca~ SonicWall CVE-2026-83548/83549 and JFrog CVE-2026-82329 are being exploited and added to CISA KEV. - IOCs: CVE-2026-83548, CVE-2026-83549, CVE-2026-82329 - #CVE #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • servmask
  • All-in-One WP Migration and Backup

25 Aug 2026
Published
27 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.54%

KEV

Description

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This can be leveraged to obtain the ai1wm_secret_key when a site administrator performs an archive restore and achieve remote code execution once able to leverage the ai1wm_secret_key value.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 5 hours ago

Bluesky

Profile picture fallback
High-severity SQL injection in All-in-One WP Migration and Backup can let unauthenticated attackers gain remote code execution and take over WordPress sites. Fixed in 7.110 after disclosure. #WordPress #SQLInjection #CVE202619949
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Cleo
  • Harmony

01 Sep 2026
Published
01 Sep 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.28%

KEV

Description

A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 is sufficient to fix this issue. It is recommended to upgrade the affected component.

Statistics

  • 2 Posts

Last activity: 13 hours ago

Bluesky

Profile picture fallback
Patch Cleo Harmony immediately for CVE-2026-84115, a JWT refresh token authentication bypass enabling remote privilege escalation and persistent access.
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
Exploit published for a fresh Cleo Harmony flaw, CVE-2026-84115, enabling auth bypass via JWT refresh token manipulation in /api/connections. Attackers may gain elevated access and persistence. #CleoHarmony #CVE-2026-84115 #WatchTowr
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • fast-uri
  • fast-uri

02 Sep 2026
Published
02 Sep 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
Pending

KEV

Description

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.

Statistics

  • 3 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

🚨 High-severity security fix in fast-uri (4.1.4, 3.1.7, 2.4.6) just released!

Patches CVE-2026-84292: fast-uri vulnerable to authority injection via an unvalidated port in serialize

github.com/fastify/fast-uri/se

  • 0
  • 0
  • 1
  • 7h ago
Profile picture fallback

CVE-2026-84292 - Host Injection in fast-uri. Unvalidated port input allows redirection to attacker-controlled hosts. CVSS 7.5. Audit your dependencies now. #CVE #NodeJS #infosec

valtersit.com/cve/CVE-2026-842

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Langflow
  • Langflow

23 Jan 2026
Published
26 Feb 2026
Updated

CVSS v3.0
CRITICAL (9.8)
EPSS
2.26%

KEV

Description

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-27322.

Statistics

  • 3 Posts

Last activity: 13 hours ago

Fediverse

Profile picture fallback

Langflow RCE now under active exploitation

Attackers are actively exploiting CVE-2026-0768, a critical unauthenticated RCE flaw in Langflow's code validator, running credential-harvesting operations that pull OpenAI API keys and AWS access straight out of compromised agentic AI infrastructure, with exploitation clocked within roughly 20 hours of disclosure....

itnerd.blog/2026/09/02/langflo

  • 0
  • 0
  • 1
  • 15h ago

Bluesky

Profile picture fallback
Attackers Turn Langflow and Rails Flaws Into Entry Points for Credential Probing #AISecurity #CredentialTheft #CVE20260768
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • F5
  • NGINX JavaScript

02 Sep 2026
Published
02 Sep 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
Pending

KEV

Description

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engine, which is the engine used when the js_engine directive is absent, this corrupts adjacent objects and crashes the NGINX worker. With the QuickJS engine, the same call additionally leaks the prefix list on every invocation, causing worker memory to grow across requests. The official nginxinc/nginx-saml reference implementation is affected during SAML signature verification. It reads InclusiveNamespaces/@PrefixList from an untrusted SAML message and passes it to xml.exclusiveC14n() before the signature has been verified, so a valid SAML signature is not required. A crafted SAML Response, Assertion, LogoutRequest, or LogoutResponse is sufficient. Code execution has not been demonstrated and cannot be ruled out for all platforms, as the effect of the out-of-bounds write depends on conditions beyond the attacker's control.   Impact This vulnerability allows remote attackers to cause a denial of service on the NGINX system, either through repeatable worker restarts or through worker memory growth or possibly trigger code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 1 Post
  • 7 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

I am fortunate enough to not know anything about NGINX JavaScript ( hashtag blessed ) but if you do, this might be of interest.

nvd.nist.gov/vuln/detail/cve-2

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engine, which is the engine used when the js_engine directive is absent, this corrupts adjacent objects and crashes the NGINX worker. With the QuickJS engine, the same call additionally leaks the prefix list on every invocation, causing worker memory to grow across requests. The official nginxinc/nginx-saml reference implementation is affected during SAML signature verification. It reads InclusiveNamespaces/@PrefixList from an untrusted SAML message and passes it to xml.exclusiveC14n() before the signature has been verified, so a valid SAML signature is not required. A crafted SAML Response, Assertion, LogoutRequest, or LogoutResponse is sufficient. Code execution has not been demonstrated and cannot be ruled out for all platforms, as the effect of the out-of-bounds write depends on conditions beyond the attacker's control. Impact This vulnerability allows remote attackers to cause a denial of service on the NGINX system, either through repeatable worker restarts or through worker memory growth or possibly trigger code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • 3
  • 4
  • 0
  • 8h ago
Showing 1 to 10 of 37 CVEs