24h | 7d | 30d

Overview

  • TryGhost
  • Ghost

20 Feb 2026
Published
20 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
63.49%

KEV

Description

Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.

Statistics

  • 5 Posts
  • 2 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

"A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.

The campaign was discovered by XLab threat intelligence researchers at Chinese cybersecurity company Qianxin, who confirmed impact on more than 700 domains, including university portals, AI/SaaS companies, media outlets, fintech firms, security sites, and personal blogs.

According to the researchers, threat actors planted malicious code on the websites of Harvard University, Oxford University, Auburn University, and DuckDuckGo."

bleepingcomputer.com/news/secu

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
Ghost CMS flaw CVE-2026-26980 enabled attacks on 700+ sites, injecting ClickFix malware through fake CAPTCHA pages.
  • 0
  • 1
  • 0
  • 3h ago
Profile picture fallback
CVE-2026-26980 SQL injection in Ghost has been exploited at scale to steal Admin API keys and inject malicious JavaScript into unpatched sites.
  • 0
  • 1
  • 0
  • 3h ago
Profile picture fallback
A critical SQL injection flaw (CVE-2026-26980) in Ghost CMS is being actively exploited to hijack website articles. Attackers have compromised […]
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
Ghost CMS CVE-2026-26980 was mass-exploited in a SQL injection campaign that hit 700+ sites. Attackers stole Admin API keys and planted JavaScript loaders for ClickFix attacks, impacting Harvard, Oxford, and DuckDuckGo. #GhostCMS #CVE2026 #ClickFix
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Drupal
  • Drupal core

20 May 2026
Published
23 May 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
12.57%

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

Statistics

  • 5 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Drupal Critical SQL Injection Vulnerability Under Active Exploitation as CISA Issues Urgent Warning + Video

Introduction A newly disclosed security flaw in Drupal Core has rapidly escalated into a major cybersecurity concern after active exploitation attempts were detected worldwide only days after disclosure. The vulnerability, tracked as CVE-2026-9082, has now been officially added to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited…

undercodenews.com/drupal-criti

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
🚨 In this week’s newsletter, we cover CVE-2026-9082, a Drupal JSON: API SQL injection vulnerability now under active exploitation. We break down how attackers are targeting exposed /jsonapi/ endpoints and what defenders should do next. 👉 www.crowdsec.net/vulntracking...
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
CVE-2026-9082: Drupal's Highly Critical SQL Injection Flaw Is Already Under Active Attack https://securityaffairs.com/192557/security/cve-2026-9082-drupals-highly-critical-sql-injection-flaw-is-already-under-active-attack.html
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
CISAが既知の悪用された脆弱性を1件カタログに追加 CISA Adds One Known Exploited Vulnerability to Catalog #CISA (May 22) CVE-2026-9082 DrupalコアのSQLインジェクション脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
~Checkpoint~ Highlights include actively exploited Defender & Drupal flaws, major breaches at GitHub & 7-Eleven, and new AI-driven threats. - IOCs: CVE-2026-41091, CVE-2026-9082, Showboat - #CVE #Malware #ThreatIntel
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Rust
  • Cargo
  • cargo

25 May 2026
Published
25 May 2026
Updated

CVSS v4.0
LOW (2.3)
EPSS
Pending

KEV

Description

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.

Statistics

  • 3 Posts
  • 6 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

JUST IN: Security Advisory for Cargo (CVE-2026-5222)

>> Cargo CVE-2026-5222: Sparse registry URL normalization flaw lets attackers steal credentials from third-party registries under niche conditions. Fixed in Rust 1.96.

#rustlang #rustlang

  • 2
  • 1
  • 0
  • 1h ago

Bluesky

Profile picture fallback
Security Advisory for Cargo (CVE-2026-5222) | Rust Blog
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Palo Alto Networks
  • Cloud NGFW

13 May 2026
Published
14 May 2026
Updated

CVSS v4.0
HIGH (7.2)
EPSS
0.03%

KEV

Description

An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used. The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

I thought Palo was part of the Mythos seekrit cabal platform and also had their own advanced AI BS that protected enterprises from everything.

Given that, how does CVE-2026-0265 — an at-scale PAN-OS CAS Authentication Bypass — happen now?

Seems like Mythos isn't all its cracked up to be?

  • 0
  • 2
  • 0
  • 2h ago

Bluesky

Profile picture fallback
Palo Alto Networks製PAN-OSにおける認証回避の脆弱性(CVE-2026-0265)に関する注意喚起 #JPCERTCC (May 22) www.jpcert.or.jp/at/2026/at26...
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • F5
  • NGINX Plus

22 May 2026
Published
23 May 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.15%

KEV

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 2 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

NGINX “Poolslip” Vulnerability Exposes Critical Remote Code Execution Risk Across F5 Ecosystem

Introduction A newly disclosed security vulnerability affecting NGINX has raised major concerns across the cybersecurity industry after researchers demonstrated a sophisticated attack capable of bypassing modern memory protections and potentially achieving remote code execution. The flaw, tracked as CVE-2026-9256 and internally identified as F5 ID 161 (NGINX), impacts both…

undercodenews.com/nginx-poolsl

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
~Cybergcca~ CCCS released 7 advisories for IBM, Roundcube, Dell, Ubuntu, CISA ICS, Red Hat, and cPanel. - IOCs: CVE-2026-9256 - #Patch #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Rust Project
  • Cargo
  • cargo

25 May 2026
Published
25 May 2026
Updated

CVSS v4.0
MEDIUM (6.5)
EPSS
Pending

KEV

Description

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

Statistics

  • 3 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

JUST IN: Security Advisory for Cargo (CVE-2026-5223)

>> Cargo CVE-2026-5223: Malicious crates with symlinks can override other crates from the same third-party registry. Fixed in Rust 1.96.0.

#rustlang #rust

  • 0
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
Security Advisory for Cargo (CVE-2026-5223) | Rust Blog
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • F5
  • NGINX Plus

13 May 2026
Published
21 May 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
1.00%

KEV

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 2 Posts

Last activity: 21 hours ago

Fediverse

Profile picture fallback

📰 Critical 18-Year-Old 'NGINX Rift' Vulnerability (CVE-2026-42945) Under Active Attack

🚨 CRITICAL NGINX FLAW! An 18-year-old bug 'NGINX Rift' (CVE-2026-42945) is actively exploited for DoS & RCE. Affects millions of web servers. Patch immediately! #NGINX #CVE #Infosec #PatchNow

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ng

  • 0
  • 0
  • 0
  • 23h ago

Bluesky

Profile picture fallback
~Checkpoint~ Highlights include active exploitation of Cisco SD-WAN, Windows zero-days, and major ransomware breaches. - IOCs: CVE-2026-20182, CVE-2026-42945, YellowKey - #Ransomware #ThreatIntel #ZeroDay
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Krajowa Izba Rozliczeniowa
  • Szafir SDK

25 May 2026
Published
25 May 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

Szafir SDK returns a success status code from the cryptographic digital signature verification process (i.e. /VerifyingTaskItem/Signature/VerificationResult/Result/@code == 0, "Positively verified") even when the trust status of the signer's certificate could not be established (i.e. /VerifyingTaskItem/Signature/VerificationResult/SigningCertificate/@certificateType == "nondetermined"). This causes consuming applications to incorrectly treat the signature as valid despite an unverified certificate chain, enabling authentication bypass and user impersonation. This issue was fixed in version 463.

Statistics

  • 2 Posts
  • 15 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Na CONFidence 2026 Michał kończy właśnie opowieść o krytycznych lukach, które umożliwiały zalogowanie się na konto dowolnego obywatela w wielu kluczowych systemach administracji publicznej, a @zaufanatrzeciastrona opublikowała przed chwilą cykl artykułów jego autorstwa, dokładnie wyjaśniający problem. Zdecydowanie polecam (zarwałam noc, żeby je na czas skorygować ;-))

👉 Zdalne wykonanie kodu w SzafirHost – [CVE-2026-26928] [Badanie e-podpisów, cz. 1] – zaufanatrzeciastrona.pl/post/z
👉 Hakowanie e-Sądu YubiKeyem – [Badanie e-podpisów, cz. 2] – zaufanatrzeciastrona.pl/post/h
👉 Ominięcie uwierzytelniania w ZUS-ie i systemach e-Zdrowia, czyli o krok od cyberchaosu – [CVE-2026-9058] [Badanie e-podpisów, cz. 3] – zaufanatrzeciastrona.pl/post/o
👉 Podsumowanie: Krytyczna podatność umożliwiająca całkowite ominięcie logowania w ZUS-ie, e-Sądzie i systemach e-Zdrowia – zaufanatrzeciastrona.pl/post/p

  • 2
  • 4
  • 0
  • 3h ago

Overview

  • Krajowa Izba Rozliczeniowa
  • SzafirHost

02 Apr 2026
Published
02 Apr 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.02%

KEV

Description

SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dynamic library. JAR files are correctly verified based on a list of trusted file hashes, and if a file was not on that list, it was checked to see if it had been digitally signed by the vendor. The application doesn't verify hash or vendor's digital signature of uploaded DLL, SO, JNILIB or DYLIB file. The attacker can provide malicious file which will be saved in users /temp folder and executed by the application. This issue was fixed in version 1.1.0.

Statistics

  • 2 Posts
  • 15 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Na CONFidence 2026 Michał kończy właśnie opowieść o krytycznych lukach, które umożliwiały zalogowanie się na konto dowolnego obywatela w wielu kluczowych systemach administracji publicznej, a @zaufanatrzeciastrona opublikowała przed chwilą cykl artykułów jego autorstwa, dokładnie wyjaśniający problem. Zdecydowanie polecam (zarwałam noc, żeby je na czas skorygować ;-))

👉 Zdalne wykonanie kodu w SzafirHost – [CVE-2026-26928] [Badanie e-podpisów, cz. 1] – zaufanatrzeciastrona.pl/post/z
👉 Hakowanie e-Sądu YubiKeyem – [Badanie e-podpisów, cz. 2] – zaufanatrzeciastrona.pl/post/h
👉 Ominięcie uwierzytelniania w ZUS-ie i systemach e-Zdrowia, czyli o krok od cyberchaosu – [CVE-2026-9058] [Badanie e-podpisów, cz. 3] – zaufanatrzeciastrona.pl/post/o
👉 Podsumowanie: Krytyczna podatność umożliwiająca całkowite ominięcie logowania w ZUS-ie, e-Sądzie i systemach e-Zdrowia – zaufanatrzeciastrona.pl/post/p

  • 2
  • 4
  • 0
  • 3h ago

Overview

  • VMware
  • bitnamicharts/appsmith
  • bitnamicharts/appsmith

24 Jul 2025
Published
26 Feb 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.18%

KEV

Description

Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A remote attacker could retrieve these secrets by accessing specific URLs if the application is exposed externally. The issue affects deployments using the default value of usePasswordFiles=true, which mounts secrets as files into the container filesystem.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback

CVE-2025-41240 - Critical Supply Chain Attack in Bitnami Helm charts. Kubernetes secrets exposed at predictable path /opt/bitnami/*/secrets within web root. CVSS 10. Unauthenticated access to sensitive credentials via HTTP/S. Patch unknown but immediate action required. #CVE #Kubernetes #infosec

valtersit.com/cve/CVE-2025-412

  • 2
  • 1
  • 0
  • 12h ago
Showing 1 to 10 of 50 CVEs