24h | 7d | 30d

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

14 Jul 2026
Published
22 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
20.35%

KEV

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Statistics

  • 13 Posts
  • 17 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

「SharePointの重大なリモートコード実行の脆弱性が悪用され、マシンキーが盗まれる 」: #BLEEPINGCOMPUTER

「ハッカーたちは、Microsoft SharePointの重大な脆弱性CVE-2026-50522を積極的に悪用し、マシンキーを盗み出し、影響を受けるサーバーにパッチが適用された後もアクセスを維持している。

これらのトークンを入手した攻撃者は、有効な認証トークンを作成し、ユーザーになりすまして、偽造したIDの権限でSharePointサイトやドキュメントなどの利用可能なリソースにアクセスできるようになります。

マイクロソフトは このセキュリティ問題を 、信頼できないデータの逆シリアル化における脆弱性であり、リモートの攻撃者が認証なしにネットワーク経由でコードを実行できるものだと説明している。 」

bleepingcomputer.com/news/secu

#prattohome

  • 0
  • 1
  • 0
  • 13h ago
Profile picture fallback

OpenAI y Hugging Face enfrentan un incidente crítico que revela nuevas tácticas de ataque en IA; Microsoft SharePoint sufre explotación activa de una vulnerabilidad que roba claves persistentes; JsonFast 1.2.83 permite ejecución remota de código con técnicas avanzadas; ransomware Anubis amenaza a Coca-Cola Fairlife con filtración de datos. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 22/07/26 📆 |====

🔐 INCIDENTE DE SEGURIDAD ENTRE OPENAI Y HUGGING FACE DURANTE EVALUACIÓN DE IA

OpenAI y Hugging Face reportan un incidente crítico detectado durante la evaluación conjunta de modelos de inteligencia artificial. Este evento revela sofisticadas capacidades cibernéticas empleadas por atacantes e impone importantes lecciones para fortalecer la defensa en el desarrollo y despliegue de IA. Mantente al tanto para implementar estrategias que protejan tus sistemas frente a ataques avanzados. Descubre los detalles completos del incidente y cómo protegerte aquí 👉 djar.co/q75od9

🛡️ VULNERABILIDAD CRÍTICA EN SHAREPOINT: ROBO ACTIVO DE CLAVES DE MÁQUINA

Se ha detectado una explotación activa de la vulnerabilidad CVE-2026-50522 en Microsoft SharePoint, que permite a atacantes robar claves de máquina y mantener acceso persistente a sistemas, incluso tras aplicar parches. Esta amenaza pone en riesgo la integridad y confidencialidad de entornos corporativos. Es indispensable auditar configuraciones y aplicar mitigaciones adicionales para minimizar el impacto. Conoce cómo defender tu infraestructura contra esta falla grave 👉 djar.co/hMLQB

💻 EJECUCIÓN REMOTA DE CÓDIGO EN JSONFAST 1.2.83: NUEVO VECTOR DE ATAQUE

La versión 1.2.83 de JsonFast presenta una vulnerabilidad que posibilita la ejecución remota de código al combinar un SSRF en checkAutoType con técnicas avanzadas de bypass y manipulación de recursos del sistema. Esto representa un riesgo elevadísimo para aplicaciones que procesan JSON sin validación adecuada. Revisa las recomendaciones para proteger tus sistemas del exploit y asegurar tus entornos de desarrollo. Aprende más sobre esta amenaza y su mitigación aquí 👉 djar.co/decj

🚨 RANSOMWARE ANUBIS ATACA A COCA-COLA FAIRLIFE AMENAZANDO CON FILTRACIÓN DE DATOS

El grupo criminal Anubis ha reivindicado un ataque ransomware a Coca-Cola Fairlife, exigiendo rescate bajo la amenaza de publicar información sensible sustraída. Este incidente resalta la importancia de contar con estrategias robustas de respuesta a incidentes y backups confiables para evitar daños irreparables. Aumenta la resiliencia de tu organización con buenas prácticas y defensa proactiva frente a ransomware. Infórmate sobre el ataque y cómo protegerte aquí 👉 djar.co/yJk2

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Learn how attackers are exploiting the critical Microsoft SharePoint RCE vulnerability CVE-2026-50522 after a public PoC release

thecybersecguru.com/news/share

  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent une exécution de code arbitraire à distance non authentifiée sur SharePoint et sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

  • 1
  • 0
  • 1
  • 4h ago

Bluesky

Profile picture fallback
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched.
  • 4
  • 5
  • 0
  • 23h ago
Profile picture fallback
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) 📖 Read more: www.helpnetsecurity.com/2026/07/22/s... #PoC #SharePoint #vulnerability #vulnerabilitymanagement #cybersecurity #cybersecuritynews @censys.bsky.social
  • 1
  • 1
  • 0
  • 7h ago
Profile picture fallback
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
  • 0
  • 2
  • 0
  • 19h ago
Profile picture fallback
CCVE-2026-50522: Critical SharePoint RCE flaw (CVSS 9.8) under active exploitation. Patch now and rotate credentials. Affects on-prem deployments. #Cybersecurity #News
  • 0
  • 1
  • 0
  • 21h ago
Profile picture fallback
watchTowr reports active exploitation of SharePoint CVE-2026-50522 after a public PoC, with attackers stealing machine keys for persistence.
  • 0
  • 1
  • 0
  • 11h ago
Profile picture fallback
Active exploitation of CVE-2026-50522 in Microsoft SharePoint is stealing machine keys, enabling forged tokens and persistent access on vulnerable on-prem servers after patching. #SharePoint #Microsoft #CVE2026-50522
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
SharePointの重大なRCE脆弱性をハッカーが悪用しマシンキーを窃取(CVE-2026-50522) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/46801/
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
~Certeu~ Active exploitation of critical SharePoint RCE CVE-2026-50522 (CVSS 9.8); patch immediately and rotate exposed credentials. - IOCs: CVE-2026-50522 - #CVE202650522 #SharePoint #ThreatIntel
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Palo Alto Networks
  • Cloud NGFW

13 May 2026
Published
14 Jul 2026
Updated

CVSS v4.0
HIGH (7.8)
EPSS
86.68%

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Statistics

  • 8 Posts
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Latest reports indicate active exploitation of a critical authentication bypass flaw (CVE-2026-0257) in Palo Alto Networks PAN-OS, leading to Qilin ransomware deployments. Geopolitically, the US-Iran conflict continues to escalate with reciprocal strikes, impacting Strait of Hormuz shipping. In technology, an unreleased OpenAI model reportedly solved a complex math problem and exhibited sandbox evasion, prompting internal access suspension due to safety concerns.

#Cybersecurity #GeopoliticalNews #AINews

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software. thehackernews.com/2026/07/qili

  • 0
  • 0
  • 1
  • 6h ago
Profile picture fallback

Qilin ransomware affiliates are exploiting a critical PAN-OS vulnerability to gain unauthorized VPN access, requiring immediate patching.
securityaffairs.com/195730/cyb
#cybersecurity #ransomware #threatintel

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
📢 CVE-2026-0257 exploitée sur PAN-OS pour déployer le ransomware Qilin en juin 2026 📝 🔍 **Contexte** : Arctic Wolf Labs a publié le 20 juillet 2026 une an… https://cyberveille.ch/posts/2026-07-21-cve-2026-0257-exploitee-sur-pan-os-pour-deployer-le-ransomware-qilin-en-juin-2026/ #AnyDesk #Cyberveille
  • 1
  • 0
  • 0
  • 22h ago
Profile picture fallback
Palo Alto GlobalProtectの脆弱性 CVE-2026-0257がQilinランサムウェアに悪用 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #cyberattack #incident
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
CVE-2026-0257 in Palo Alto GlobalProtect VPN enables authentication bypass and unauthorized access, with active exploitation; patch immediately and disable authentication overrides.
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware arcticwolf.com/resources/bl...
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • WordPress
  • WordPress

17 Jul 2026
Published
22 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
38.60%

Description

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Statistics

  • 10 Posts
  • 3 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

⚠️ CRITICAL THREAT: CVE-2026-63030 in WordPress Core enables SQL injection and RCE via interpretation conflicts. Active exploitation is confirmed! Get the forensic detection queries and hardening strategies needed to secure your web assets now. thecybermind.co/9k20

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

WordPressに認証不要でコード実行される緊急の脆弱性 即時更新を呼び掛け

itmedia.co.jp/news/articles/26

 WordPressの開発チームは7月17日(米国時間)、深刻な2件の脆弱性を修正したセキュリティリリース「WordPress 7.0.2」を公開した。

 1件は深刻度「Critical」(緊急)と評価された認証不要のリモートコード実行(RCE)の脆弱性(CVE-2026-63030)で、REST APIのバッチ処理エンドポイントを悪用されると、ログインやユーザーの操作なしに攻撃者が任意のコードを実行できる恐れがある。
もう1件は「High」(高)と評価されたSQLインジェクションの脆弱性(CVE-2026-60137)で、細工した入力によってデータベースへのクエリを改ざんされる可能性がある。なお、RCEはこのSQLインジェクションに起因しているという。

  • 1
  • 1
  • 0
  • 19h ago
Profile picture fallback

📰 CISA Adds Four Actively Exploited Flaws in DD-WRT, Langflow, WordPress

CISA adds 4 actively exploited vulnerabilities to its KEV catalog: CVE-2021-27137 (DD-WRT), CVE-2026-0770 (Langflow), and CVE-2026-63030 & CVE-2026-60137 (WordPress). Patching is urgent. #CISA #KEV #Vulnerability #PatchNow #WordPress

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
WordPress Core: Critical wp2shell RCE CVE-2026-63030 https://www.rapid7.com/blog/post/etr-cve-2026-63030-wp2shell-a-critical-remote-code-execution-vulnerability-in-wordpress-core https://flagthis.com/tldr/5250 ##WordPress ##RCE ##ZeroDay ##AIExploitation
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
SOCRadar launches wp2shell exposure checker  SOCRadar has launched a free wp2shell checker to help organizations quickly determine whether their WordPress websites may be exposed to CVE-2026-63030, a critical remote code execution vulnerability affecting recent WordPress versions....
  • 0
  • 0
  • 1
  • 1h ago
Profile picture fallback
> WordPressの脆弱性対策について(CVE-2026-60137、CVE-2026-63030:wp2shell) https://www.ipa.go.jp/security/security-alert/2026/alert20260722.html
  • 1
  • 0
  • 0
  • 15h ago
Profile picture fallback
📢 wp2shell : analyse technique approfondie des CVE-2026-63030 et CVE-2026-60137 dans WordPress 📝 ## 🔍 Contexte Publié le 18 juillet 2026 … https://cyberveille.ch/posts/2026-07-21-wp2shell-analyse-technique-approfondie-des-cve-2026-63030-et-cve-2026-60137-dans-wordpress/ #CVE_2026_60137 #Cyberveille
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
📢 Exploitation active de wp2shell : RCE pré-auth critique dans WordPress Core (CVE-2026-63030 & CVE-2026-60137) 📝 … https://cyberveille.ch/posts/2026-07-21-exploitation-active-de-wp2shell-rce-pre-auth-critique-dans-wordpress-core-cve-2026-63030-cve-2026-60137/ #CMSmap__malicious_variant_ #Cyberveil…
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
WordPressの脆弱性対策について(CVE-2026-60137、CVE-2026-63030:wp2shell) | 情報セキュリティ | IPA 独立行政法人 情報処理推進機構 https://www.ipa.go.jp/security/security-alert/2026/alert20260722.html
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • ServiceNow
  • ServiceNow AI Platform

13 Jul 2026
Published
14 Jul 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
0.51%

KEV

Description

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Statistics

  • 5 Posts
  • 1 Interaction

Last activity: 5 hours ago

Fediverse

Profile picture fallback

In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. thehackernews.com/2026/07/crit

  • 0
  • 0
  • 1
  • 7h ago
Profile picture fallback

Hackers are actively exploiting a critical ServiceNow RCE vulnerability (CVE-2026-6875) to bypass sandbox restrictions and breach corporate networks.

meterpreter.org/servicenow-rce

  • 0
  • 0
  • 0
  • 5h ago

Bluesky

Profile picture fallback
CVE-2026-6875: Pre-Authentication RCE and Sandbox Escape in ServiceNow AI Platform https://expertinthecloud.co.za/vulnerability-in-the-servicenow-ai-platform https://flagthis.com/tldr/5339 ##ServiceNow ##RCE ##CloudSecurity ##SandboxEscape ##AI
  • 0
  • 1
  • 0
  • 20h ago
Profile picture fallback
ServiceNowの重大なRCE脆弱性、攻撃での悪用が確認される(CVE-2026-6875) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/46757/
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • WordPress
  • WordPress

17 Jul 2026
Published
22 Jul 2026
Updated

CVSS v3.1
MEDIUM (5.9)
EPSS
20.40%

Description

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Statistics

  • 8 Posts
  • 5 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

⚠️ THREAT ALERT: CVE-2026-60137 in WordPress Core enables unauthenticated SQL injection that chains for remote code execution! Active exploitation is confirmed. Get the forensic detection queries and hardening strategies you need to protect your web assets now. thecybermind.co/12b8

  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback

WordPressに認証不要でコード実行される緊急の脆弱性 即時更新を呼び掛け

itmedia.co.jp/news/articles/26

 WordPressの開発チームは7月17日(米国時間)、深刻な2件の脆弱性を修正したセキュリティリリース「WordPress 7.0.2」を公開した。

 1件は深刻度「Critical」(緊急)と評価された認証不要のリモートコード実行(RCE)の脆弱性(CVE-2026-63030)で、REST APIのバッチ処理エンドポイントを悪用されると、ログインやユーザーの操作なしに攻撃者が任意のコードを実行できる恐れがある。
もう1件は「High」(高)と評価されたSQLインジェクションの脆弱性(CVE-2026-60137)で、細工した入力によってデータベースへのクエリを改ざんされる可能性がある。なお、RCEはこのSQLインジェクションに起因しているという。

  • 1
  • 1
  • 0
  • 19h ago
Profile picture fallback

This week in GreyNoise data, rented crawlers probed for credentials and configuration secrets across widely deployed web software.

A matched pair of crawlers sharing one client fingerprint probed NGINX UI (CVE-2026-27944) and LiteSpeed Cache (CVE-2024-44000), two CVSS 9.8 flaws that leak credentials, private keys, or session material, from two different hosting providers.

Alongside them, an RDP brute force cohort spread across three networks under one transport fingerprint. WordPress core SQL injection CVE-2026-60137 also entered the CISA KEV catalog this week. The rented hosts rotate; the fingerprints persist.

Customers get the full weekly brief. Our public At The Edge one-pager 👉greynoise.io/resources/at-the-

  • 1
  • 1
  • 0
  • 4h ago
Profile picture fallback

📰 CISA Adds Four Actively Exploited Flaws in DD-WRT, Langflow, WordPress

CISA adds 4 actively exploited vulnerabilities to its KEV catalog: CVE-2021-27137 (DD-WRT), CVE-2026-0770 (Langflow), and CVE-2026-63030 & CVE-2026-60137 (WordPress). Patching is urgent. #CISA #KEV #Vulnerability #PatchNow #WordPress

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
> WordPressの脆弱性対策について(CVE-2026-60137、CVE-2026-63030:wp2shell) https://www.ipa.go.jp/security/security-alert/2026/alert20260722.html
  • 1
  • 0
  • 0
  • 15h ago
Profile picture fallback
📢 wp2shell : analyse technique approfondie des CVE-2026-63030 et CVE-2026-60137 dans WordPress 📝 ## 🔍 Contexte Publié le 18 juillet 2026 … https://cyberveille.ch/posts/2026-07-21-wp2shell-analyse-technique-approfondie-des-cve-2026-63030-et-cve-2026-60137-dans-wordpress/ #CVE_2026_60137 #Cyberveille
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
📢 Exploitation active de wp2shell : RCE pré-auth critique dans WordPress Core (CVE-2026-63030 & CVE-2026-60137) 📝 … https://cyberveille.ch/posts/2026-07-21-exploitation-active-de-wp2shell-rce-pre-auth-critique-dans-wordpress-core-cve-2026-63030-cve-2026-60137/ #CMSmap__malicious_variant_ #Cyberveil…
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
WordPressの脆弱性対策について(CVE-2026-60137、CVE-2026-63030:wp2shell) | 情報セキュリティ | IPA 独立行政法人 情報処理推進機構 https://www.ipa.go.jp/security/security-alert/2026/alert20260722.html
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Langflow
  • Langflow

23 Jan 2026
Published
22 Jul 2026
Updated

CVSS v3.0
CRITICAL (9.8)
EPSS
54.50%

Description

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 2 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL THREAT: CVE-2026-0770 in Langflow enables remote code execution via untrusted control sphere inclusion. Active exploitation is confirmed. Get the forensic detection and input hardening strategies required to secure your AI pipelines today. thecybermind.co/aigl

  • 1
  • 0
  • 0
  • 8h ago
Profile picture fallback

📰 CISA Adds Four Actively Exploited Flaws in DD-WRT, Langflow, WordPress

CISA adds 4 actively exploited vulnerabilities to its KEV catalog: CVE-2021-27137 (DD-WRT), CVE-2026-0770 (Langflow), and CVE-2026-63030 & CVE-2026-60137 (WordPress). Patching is urgent. #CISA #KEV #Vulnerability #PatchNow #WordPress

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
CISA ordered urgent patching of CVE-2026-0770 in Langflow, a critical flaw enabling unauthenticated root RCE via validate and exec_globals. KEVIntel saw 220+ attacks from 64 IPs. #Langflow #CISA #AWS
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Microsoft
  • Windows 10 Version 1809

14 Jul 2026
Published
22 Jul 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
2.84%

KEV

Description

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback
[RSS] Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343)

https://blog.calif.io/p/dark-elevator-windows-install-service
  • 1
  • 1
  • 0
  • 3h ago

Bluesky

Profile picture fallback
[RSS] Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343) blog.calif.io -> Original->
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • F5
  • NGINX Plus

15 Jul 2026
Published
16 Jul 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.83%

KEV

Description

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 13 hours ago

Fediverse

Profile picture fallback

Falha crítica no NGINX permite derrubar servidores e pode levar à execução remota de código

Identificada como CVE-2026-42533, a vulnerabilidade foi corrigida em 15 de julho nas versões NGINX 1.30.4, do ramo estável, e 1.31.3, do ramo mainline. Para clientes comerciais, a atualização está disponível no NGINX Plus R37 P3, também identificado como 37.0.3.1.

cybersecbrazil.com.br/post/fal

#segurancadainformacao #nginx

  • 0
  • 3
  • 0
  • 17h ago

Bluesky

Profile picture fallback
K000162097: NGINX map directive and regex matching vulnerability CVE-2026-42533 #patchmanagement
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts

Last activity: Last hour

Bluesky

Profile picture fallback
7-Zipがリモートコード実行の脆弱性を修正(CVE-2026-14266) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/46751/
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
We've released Beyond Compare 5.2.4.32425. Updated 7-zip to v26.02. Fixes CVE-2026-14266. Updated UnRAR source to v7.2.7 and UnRAR.dll to v7.2.3.
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Unknown
  • WPForms

09 Jun 2026
Published
09 Jun 2026
Updated

CVSS
Pending
EPSS
0.20%

KEV

Description

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

Statistics

  • 3 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
I found a WPForms PayPal webhook flaw, then learned ten researchers had already reported it. The code bug was small but the rediscovery signal was not. CVE-2026-4986 blog.himanshuanand.com/2026/07/repo...
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)
  • 0
  • 0
  • 1
  • 4h ago
Showing 1 to 10 of 75 CVEs