Description
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Statistics
- 3 Posts
- 1 Interaction
Last activity: 1 hour ago
Bluesky
Chrome security update released! 🚨 Addresses 12 vulns, incl. 1 critical flaw (CVE-2026-85046) in V8 JS engine that's being exploited. Update to v152.0.7977.82/.83 (Windows/Mac) or v152.0.7977.82 (Linux) ASAP!
#crypto #blockchain #news
Google、Chromeの脆弱性 CVE-2026-85046を修正、サイバー攻撃にも悪用、CISA KEVにも掲載
rocket-boys.co.jp/security-mea...
#セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
Description
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
Statistics
- 1 Post
- 1 Interaction
Last activity: 17 hours ago
Bluesky
Overview
- trycua
- cua-computer-server
05 Sep 2026
Published
05 Sep 2026
Updated
CVSS v4.0
CRITICAL (9.3)
EPSS
0.59%
KEV
Description
Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication.
Statistics
- 1 Post
- 1 Interaction
Last activity: 22 hours ago
Fediverse
CVE-2026-86121 - Critical RCE & auth bypass in Cua computer-server. Allows unauthenticated arbitrary command execution. CVSS 9.8. Update to 0.3.42 now. #CVE #infosec #cybersecurity
Overview
- F5
- NGINX JavaScript
02 Sep 2026
Published
03 Sep 2026
Updated
CVSS v3.1
HIGH (8.1)
EPSS
0.41%
KEV
Description
Description
NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engine, which is the engine used when the js_engine directive is absent, this corrupts adjacent objects and crashes the NGINX worker. With the QuickJS engine, the same call additionally leaks the prefix list on every invocation, causing worker memory to grow across requests. The official nginxinc/nginx-saml reference implementation is affected during SAML signature verification. It reads InclusiveNamespaces/@PrefixList from an untrusted SAML message and passes it to xml.exclusiveC14n() before the signature has been verified, so a valid SAML signature is not required. A crafted SAML Response, Assertion, LogoutRequest, or LogoutResponse is sufficient. Code execution has not been demonstrated and cannot be ruled out for all platforms, as the effect of the out-of-bounds write depends on conditions beyond the attacker's control.
Impact
This vulnerability allows remote attackers to cause a denial of service on the NGINX system, either through repeatable worker restarts or through worker memory growth or possibly trigger code execution. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Statistics
- 1 Post
Last activity: 9 hours ago
Overview
- HKUDS
- AutoAgent
05 Sep 2026
Published
05 Sep 2026
Updated
CVSS v4.0
CRITICAL (9.3)
EPSS
0.54%
KEV
Description
AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.
Statistics
- 1 Post
Last activity: 8 hours ago
Overview
- Mikrotik
- RouterOS
05 Sep 2026
Published
05 Sep 2026
Updated
CVSS v4.0
CRITICAL (9.2)
EPSS
0.25%
KEV
Description
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Statistics
- 1 Post
Last activity: 4 hours ago
Fediverse
The MikroTrick PoC is publicly disclosed. This MikroTrick RouterOS flaw is actively exploited in the wild, granting full administrative privileges.
#MikroTrick #RouterOS #CVE202667276 #CyberSecurity #Vulnerability
Overview
Description
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
Statistics
- 1 Post
Last activity: 18 hours ago
Fediverse
🚨 Critical Auth Bypass:
CVE-2026-82329 (CVSS 9.8) in JFrog Artifactory allows remote attackers to bypass authentication & mint admin tokens via blank join keys.
Read our full technical analysis & mitigation guide: https://denizhalil.com/2026/09/05/cve-2026-82329-jfrog-artifactory-authentication-bypass/
Overview
- N-able
- N-central
06 Sep 2026
Published
06 Sep 2026
Updated
CVSS v4.0
CRITICAL (10.0)
EPSS
0.41%
KEV
Description
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
Statistics
- 1 Post
Last activity: Last hour
Overview
- davidanderson
- UpdraftPlus: WP Backup & Migration Plugin
11 Jun 2026
Published
11 Jun 2026
Updated
CVSS v3.1
HIGH (8.1)
EPSS
3.58%
KEV
Description
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution.
Statistics
- 1 Post
Last activity: 13 hours ago
Overview
Description
An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value that is validated against that file's own TotalCount field but never against the actual size of RecItems. A crafted set of two or more .rev files can therefore write an attacker-controlled 32-bit value (the header's RevCRC field) to RecItems[RecNum] at an attacker-controlled offset up to 65534 * sizeof(RecVolItem) bytes past the allocation, corrupting adjacent heap objects. Triggering requires the victim to run a recovery/test operation on an attacker-supplied .rev set (for example 'unrar t x.part1.rev', WinRAR 'Repair archive', or auto-recovery when extracting a volume set with a missing .rar part). This is the RAR5-path sibling of CVE-2023-40477 (which was fixed in the RAR3 path only in WinRAR 6.23). Fixed in WinRAR / RAR 7.23.
Statistics
- 1 Post
Last activity: 17 hours ago