24h | 7d | 30d

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

14 Jul 2026
Published
13 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
2.96%

KEV

Description

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Statistics

  • 8 Posts
  • 1 Interaction

Last activity: Last hour

Fediverse

Profile picture fallback

🛑 Attackers are exploiting a SharePoint authentication bypass.

CVE-2026-55040 lets unauthenticated attackers forge JWTs and impersonate any SharePoint site user, including administrators. Eight of 12 recorded exploit attempts occurred on August 12 and 13, after Rapid7 published a PoC.

See how the exploit works: thehackernews.com/2026/08/atta

  • 0
  • 1
  • 0
  • 9h ago
Profile picture fallback

「公開された概念実証(PoC)リリース後、攻撃者がSharePointの認証バイパスを悪用 」: #TheHackerNews

「攻撃者は、概念実証(PoC)コードの公開を受けて、新たに明らかになったMicrosoft SharePointの脆弱性を悪用し始めている。

問題となっている脆弱性は CVE-2026-55040 (CVSSスコア:9.1)で、認証の脆弱性に起因する重大なセキュリティ機能のバイパスに関するものです。この脆弱性は、マイクロソフトが2026年7月のパッチチューズデーアップデートの一環として修正しました。

マイクロソフトは先月、この脆弱性に関する勧告の中で、「この脆弱性によりなりすましが可能になるため、認証機能が回避される可能性がある」と述べた。「この脆弱性を悪用すると、攻撃者はファイルを漏洩させたりデータを改ざんしたりできる可能性があるが、システムの可用性に影響を与えることはできない」としている。 」

thehackernews.com/2026/08/atta

#prattohome

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

Attackers are actively exploiting CVE-2026-55040, a critical remote code execution vulnerability in Microsoft SharePoint, after a proof-of-concept exploit was released by Rapid7. This flaw affects Sha
helpnetsecurity.com/2026/08/13
#cybersecurity #Microsoft #SharePoint

  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
Threat actors are exploiting CVE-2026-55040 in Microsoft SharePoint using a PoC to bypass authentication and impersonate users, enabling file disclosure and data modification.
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040, CVSS 9.1) after a proof-of-concept code was released by […]
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) 🔗 Read more: www.helpnetsecurity.com/2026/08/13/m... #vulnerability #cyberattack ##cybersecurity @rapid7.com
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
Servidores Microsoft SharePoint estão a ser alvo de ataques devido a falha crítica. A vulnerabilidade CVE-2026-55040 permite contornar a autenticação do sistema sem credenciais válidas. 🚨 #falha #microsoft #vaga
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
SharePoint CVE-2026-55040 is being exploited in the wild soon after Rapid7 published a PoC. Microsoft also patched CVE-2026-63520, which may chain to enable unauthenticated RCE on SharePoint servers. #SharePoint #Microsoft #Rapid7
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

11 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
HIGH (7.0)
EPSS
0.33%

Description

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Statistics

  • 8 Posts
  • 4 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

(CISA TS-SOC) CVE-2026-68820 – Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Severity: HIGH Impact Summary: Allows an authorized attacker to elevate privileges locally via a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock....

thecybermind.co/join

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
이번 Microsoft 8월 Patch Tuesday 업데이트는 미루지 않는 것이 좋겠습니다. 특히 Windows 11의 CVE-2026-68820은 CVSS가 7.0이라 숫자만 보면 덜 심각해 보이지만, Microsoft Defender는 공개된 익스플로잇이 존재하는 취약점으로 별도 경고하고 있습니다. 취약점은 CVSS 점수만 보고 우선순위를 정하면 안 됩니다. Windows Update를 확인하고 이번 보안 업데이트는 가급적 신속하게 적용하시길 권합니다.
  • 0
  • 1
  • 0
  • 23h ago
Profile picture fallback
Microsoft、2026年8月定例パッチで421件の脆弱性を修正 悪用確認済みゼロデイ1件(CVE-2026-68820)、公開済み未パッチ2件も rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 1
  • 0
  • 16h ago
Profile picture fallback
Lazarus-linked attacks exploit Windows CVE-2026-68820 as a zero-day to gain SYSTEM access and deploy Troy against defense and aerospace firms.
  • 0
  • 1
  • 0
  • 13h ago
Profile picture fallback
CVE-2026-68820: Windows AFD.sys Zero-Day socprime.com/blog/cve-202...
  • 0
  • 1
  • 0
  • Last hour
Profile picture fallback
Lazarus-linked hackers are exploiting Windows zero-day CVE-2026-68820 in Operation Dream Job to gain SYSTEM access, targeting defense, aerospace, and aviation firms with FudModule, Troy, and RelayShell. #Lazarus #NorthKorea #Windows0day
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Microsoft's record Patch Tuesday fixed 419 vulnerabilities, including 3 zero-days. AI-assisted flaw discovery is driving bug counts higher, and CVE-2026-68820 was exploited in the wild, linked to Lazarus Group. #PatchTuesday #AI #LazarusGroup
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
📢 Lazarus Group exploite un zero-day Windows (CVE-2026-68820) via de fausses offres d'emploi Cet article documente une nouvelle vague de la campagne Operation Dream Job, attribuée au groupe nord-coréen Lazarus, ciblant les… 🟢 vérification factuelle haute #LazarusGroup #ZeroDay #Cyberveille
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Microsoft
  • Microsoft Malware Protection Engine

16 Jun 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
10.75%

KEV

Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Statistics

  • 5 Posts
  • 5 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

“Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.”

theregister.com/cyber-crime/20

  • 1
  • 2
  • 0
  • 11h ago
Profile picture fallback

「Microsoftに恨みを持つハッカーが、完全にパッチが適用されたWindows上でシステム権限を取得できる新たなゼロデイ脆弱性を発見した。
/水曜日の裏技を使おうぜ、ベイビー 」: #TheRegister

「マイクロソフトに恨みを持つ、ゼロデイ攻撃を専門とするNightmare Eclipseは、マイクロソフトのRoguePlanetパッチ(CVE-2026-50656)を回避すると思われる、Defenderの新たなゼロデイ脆弱性「ShieldBreak」を公開した。これにより、攻撃者は完全にパッチが適用されたWindows 10、Windows 11、およびWindows Serverシステム上でSYSTEM権限を取得できる。

少なくとも他の研究者の一人によると、このエクスプロイトは有効だという。「試してみたところ、最新のWindows 11でも動作しました」と、元マイクロソフト社員でセキュリティ専門家のケビン・ボーモント氏 は述べている 。 」

theregister.com/cyber-crime/20

#prattohome

  • 1
  • 1
  • 0
  • 9h ago

Bluesky

Profile picture fallback
ShieldBreak enables attackers with any initial access to obtain system-level privileges by bypassing a Microsoft Defender patch for CVE-2026-50656.
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
Novo exploit ShieldBreak é capaz de ultrapassar as proteções do Microsoft Defender com 100% de eficácia, afetando sistemas com Windows 11 25H2 e Windows Server 2025. A ferramenta, criada por NightmareEclipse, contorna a correção lançada para a vulnerabilidade CVE-2026-50656. 🚨 #exploit #microsoft
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
Microsoft Defender: Critical Patch Bypass for CVE-2026-50656 RoguePlanet https://blackhatnews.tokyo/archives/129964 https://flagthis.com/tldr/6146 ##Microsoft ##ZeroDay ##PrivilegeEscalation ##RoguePlanet ##ShieldBreak
  • 0
  • 0
  • 0
  • Last hour

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
13 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.14%

KEV

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Statistics

  • 5 Posts
  • 3 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

「攻撃者がVMware vCenterの脆弱性を悪用し、永続的なリモートアクセスを取得する 」: #TheHackerNews

「QUIRSOの 新たな調査結果 によると、攻撃者は、最近パッチが適用されたBroadcom VMware vCenterの重大なセキュリティ脆弱性を積極的に悪用し始めている。

問題となっている脆弱性は CVE-2026-59310 (CVSSスコア:9.8)で、VMware vCenterサーバーのディレクトリトラバーサル脆弱性であり、ネットワークアクセス権を持つ悪意のある攻撃者がこれを悪用して任意のコードを実行できる可能性がある。この脆弱性に対するパッチは、ブロードコム社が先月末にリリースした。

ドイツのサイバーセキュリティ企業は、インシデント対応活動中にこの活動を発見したと発表した。 」

thehackernews.com/2026/08/atta

#prattohome

  • 1
  • 0
  • 0
  • 9h ago
Profile picture fallback

📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310.

Listen/Read: hackread.com/apt-exploits-crit

#CyberSecurity #VMware #vCenter #APT #Vulnerability

  • 0
  • 0
  • 0
  • 5h ago

Bluesky

Profile picture fallback
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access.
  • 0
  • 2
  • 0
  • Last hour
Profile picture fallback
Threat actors exploit CVE-2026-59310 in VMware vCenter to achieve remote code execution and maintain persistent access via reverse_ssh.
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310. Listen/Read: hackread.com/apt-exploits... #CyberSecurity #VMware #vCenter #APT #Vulnerability
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 6 Posts
  • 2 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

…et encore une vulnérabilité critique dans , trouvée une nouvelle fois par pwn.ai, qui a nécessité la publication en urgence de la mise à jour 7.0.4

La CVE-2026-65640 est une RCE assez intéressante côté traitement d’images. (ImageMagick)

Un utilisateur avec le rôle Author peut envoyer un fichier nommé comme une innocente image .png, alors que son contenu est en réalité du PostScript/EPS.
WordPress se fiait trop à l’extension ; ImageMagick, lui, regarde le contenu et peut transmettre le fichier à Ghostscript… avec à la clé une exécution de code.

Ce n’est donc pas une RCE pré-auth : il faut déjà disposer d’un compte Author. Mais sur un site multi-auteurs, communautaire ou avec des comptes peu maîtrisés, le risque devient nettement plus concret.
👇
wordpress.org/news/2026/08/wor
⬇️
github.com/WordPress/wordpress

  • 1
  • 1
  • 0
  • 2h ago
Profile picture fallback

WordPress 7.0.4 Fixes Critical Imagick RCE: How a Malicious PNG Could Become Server-Side Code Execution

WordPress 7.0.4 fixes CVE-2026-65640, an authenticated RCE affecting sites using Imagick and Ghostscript. Learn how malicious PNG reach code execution

thecybersecguru.com/news/wordp

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

WordPress 7.0.4 patches CVE-2026-65640, an Author-level remote code execution bug on sites using Imagick and Ghostscript. Update now.

securityonline.info/wordpress-

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
#WordPress: Yet another AI-discovered(@pwn_ai) Critical WordPress #RCE #Vulnerability CVE-2026-65640 Allows Authors to Execute Code via Malicious PNG File (via Imagemagick). Patched WordPress version 7.0.4 is now available, older versions backported: 👇 cybersecuritynews.com/wordpress-im...
  • 0
  • 0
  • 1
  • 9h ago
Profile picture fallback
WordPress released patches for CVE-2026-65640, a high-severity authenticated remote code execution flaw exploitable via PostScript-in-image uploads when Imagick and Ghostscript are enabled.
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Adobe
  • Adobe Commerce

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.48%

KEV

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Statistics

  • 5 Posts
  • 4 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

「ハッカーがAdobe Commerceの重大な脆弱性を悪用し、顧客アカウントを乗っ取る 」: #BLEEPINGCOMPUTER

「AdobeのeコマースプラットフォームであるCommerceとMagentoにおける重大な脆弱性(CVE-2026-71362)を悪用しようとする試みが検出されました。この脆弱性により、攻撃者が顧客アカウントを乗っ取る可能性があります。

この脆弱性は、認証なしに「機密性の高いリソースへの上位アクセス権を取得する」ために悪用される可能性のある、誤った認証の脆弱性と説明されており、Adobeが昨日のセキュリティアップデートで対処した7つの問題のうちの1つです。

ソフトウェアベンダーは 勧告 の中で、修正された脆弱性に対する実際の攻撃事例は把握していないと述べているが、eコマースセキュリティ企業のSansecは、同社のShieldウェブアプリケーションファイアウォール(WAF)が既にCVE-2026-71362の悪用を阻止していると述べている。 」

bleepingcomputer.com/news/secu

#prattohome

  • 1
  • 0
  • 0
  • 9h ago
Profile picture fallback

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

  • 1
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.
  • 1
  • 1
  • 0
  • 19h ago
Profile picture fallback
Adobe Commerce and Magento are facing CVE-2026-71362, a critical auth flaw that can hijack customer sessions and expose account data. Sansec says its Shield WAF is already blocking exploit attempts. #AdobeCommerce #Magento #CVE2026-71362
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
CVE-2026-71362 enables unauthenticated privilege escalation in Adobe Commerce, letting attackers hijack customer sessions and access private data; apply August 2026 patches immediately.
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Cisco
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (8.6)
EPSS
0.87%

Description

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: Last hour

Bluesky

Profile picture fallback
Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) 📖 Read more: www.helpnetsecurity.com/2026/08/13/c... #exploit #firewall #secureaccess #vulnerability #cybersecurity #cybersecuritynews @cisco.com
  • 0
  • 1
  • 0
  • 9h ago
Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-20349) Cisco ASA and FTD Denial of Service via Remote Access SSL VPN". #cybersecurity #AttackSurfaceManagement #EASM https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) www.helpnetsecurity.com/2026/08/13/c...
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
~Cybergcca~ Active exploitation of Cisco ASA/FTD SSL VPN DoS vuln (CVE-2026-20349); AMD, GitLab, Plesk patches also released. - IOCs: CVE-2026-20349 - #CVE202620349 #Cisco #ThreatIntel
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Palo Alto Networks
  • Prisma Access Agent

13 Aug 2026
Published
13 Aug 2026
Updated

CVSS v4.0
LOW (2.1)
EPSS
0.14%

KEV

Description

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.

Statistics

  • 2 Posts

Last activity: 11 hours ago

Bluesky

Profile picture fallback
Paloaltoの脆弱性情報 「CVE-2026-0292 Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows (Severity: LOW)」が公開されました。 → https://security.paloaltonetworks.com/CVE-2026-0292
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
Vulnerabilities in Palo Alto products URL: security.paloaltonetworks.com/CVE-2026-0292 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.2
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Foxit Software Inc.
  • Foxit PDF Editor

13 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
MEDIUM (4.7)
EPSS
0.12%

KEV

Description

Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Foxit PDF Reader und Editor 2026.1.3.36551 korrigiert eine Sicherheitslücke (CVE-2026-18622)

deskmodder.de/blog/2026/08/13/

  • 3
  • 0
  • 1
  • 9h ago

Overview

  • Unknown
  • KiviCare

13 Aug 2026
Published
13 Aug 2026
Updated

CVSS
Pending
EPSS
0.15%

KEV

Description

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 9 hours ago

Fediverse

Profile picture fallback

CVE-2026-13610 | CRITICAL privilege flaw in KiviCare <4.5.2 lets unauthenticated attackers create privileged staff accounts, risking patient data exposure 🏥. Restrict registration endpoint & monitor user creation. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 9h ago
Showing 1 to 10 of 66 CVEs