24h | 7d | 30d

Overview

  • WordPress
  • WordPress

22 Sep 2026
Published
25 Sep 2026
Updated

CVSS
Pending
EPSS
2.88%

Description

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Statistics

  • 9 Posts
  • 2 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Ciberatacantes aprovechan la vulnerabilidad CVE-2026-87902 de WordPress pocas horas después de su publicación

blog.elhacker.net/2026/09/cibe

  • 0
  • 1
  • 1
  • 14h ago
Profile picture fallback

Seguridad: Vulnerabilidad CVE-2026-87902 en WordPress

Si tienes wordpress, te estás tardando en actualizar. Llévalo a la versión 7.1.2, pues es una situación crítica de seguridad.

interlan.ec/blog/2026/09/25/se

  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback

📰 Critical WordPress Path Traversal Flaw Actively Exploited (CVE-2026-87902)

🚨 CRITICAL VULNERABILITY: WordPress Core is being actively exploited via CVE-2026-87902 (CVSS 9.2). The unauthenticated path traversal flaw can lead to RCE. Affects versions 4.7.0-7.1.1. Update to 7.1.2 immediately! #WordPress #CVE #CyberSecurity #P...

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure(WordPressのCVE-2026-87902、公開から数時間で攻撃者が悪用) #TheHackerNews (Sep 24) thehackernews.com/2026/09/atta...
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
WordPressの重大な脆弱性、公開直後に悪用される(CVE-2026-87902) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47839/
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
~Cisa~ CISA added an actively exploited WordPress remote file inclusion flaw to its KEV Catalog; prioritize remediation. - IOCs: CVE-2026-87902 - #CVE-2026-87902 #ThreatIntel #WordPress
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • F5
  • BIG-IP

22 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.23%

Description

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 9 Posts
  • 5 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Love the energy 😅

>Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

labs.watchtowr.com/is-this-a-j

  • 1
  • 2
  • 1
  • 8h ago
Profile picture fallback

Discover the critical F5 BIG-IP zero-day vulnerability CVE-2026-94127. Learn why CISA demands immediate patching for this actively exploited APM flaw.

meterpreter.org/f5-big-ip-zero

  • 1
  • 0
  • 0
  • 8h ago
Profile picture fallback

An exploited F5 BIG-IP RCE vulnerability (CVE-2026-94127) is under active attack. Discover how the PoC works and patch your APM proxies immediately.

securityonline.info/exploited-

  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback

📰 F5 BIG-IP APM Zero-Day (CVE-2026-94127) Actively Exploited for RCE

F5 BIG-IP APM is being actively exploited via a critical RCE zero-day (CVE-2026-94127). CISA has added it to the KEV catalog, mandating an urgent patch. The flaw affects systems with a specific OAuth config. #F5 #BIGIP #CyberSecurity #RCE

🔗 cyber.netsecops.io/articles/f5

  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) labs.watchtowr.com/is-this-a-jo...
  • 0
  • 1
  • 0
  • 8h ago
Profile picture fallback
F5 BIG-IP Access Policy Managerにおけるヒープベースのバッファオーバーフローの脆弱性(CVE-2026-94127)に関する注意喚起 #JPCERTCC (Sep 24) www.jpcert.or.jp/at/2026/at26...
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
F5 BIG-IP Access Policy Managerにおけるヒープベースのバッファオーバーフローの脆弱性(CVE-2026-94127)に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260028.html
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
📢 F5 BIG-IP : heap overflow non authentifié menant à RCE via l'en-tête Authorization (CVE-2026-94127) Cet article présente une analyse technique complète de CVE-2026-94127, une vulnérabilité de type heap overflow non authentifié… 🟢 vérification factuelle haute #F5BIGIP #HeapOverflow #Cyberveille
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Roundcube
  • Webmail

25 May 2026
Published
25 Sep 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.89%

KEV

Description

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

Statistics

  • 7 Posts
  • 3 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Learn how hackers are exploiting the CVE-2026-48842 Roundcube SQL injection vulnerability. Understand the risk and how to patch your webmail server immediately.

meterpreter.org/roundcube-webm

  • 1
  • 0
  • 0
  • 11h ago
Profile picture fallback

🚨 Roundcube SQL injection flaw actively exploited months after patches were released

The Canadian Centre for Cyber Security has warned that CVE-2026-48842, a high-severity vulnerability in Roundcube Webmail, is being exploited in the wild.
⠀
Roundcube is an open-source webmail application that lets people access email through a browser.

The flaw affects its virtuser_query plugin and allows SQL injection before authentication.
⠀
Key details:

• CVSS score: 8.1
• No attacker credentials required
• No user interaction required
• Affects Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1
⠀
Roundcube released the original fixes on May 24, 2026. Canada added the exploitation warning to its advisory on September 21, citing open-source reporting.

The advisory does not identify the attackers, victims or scale of exploitation.
⠀
Administrators should update affected installations promptly. Newer security releases, 1.6.19 and 1.7.4, also address additional vulnerabilities.

Source: cyber.gc.ca/en/alerts-advisori

  • 0
  • 1
  • 0
  • 2h ago

Bluesky

Profile picture fallback
Roundcube Webmail is affected by CVE-2026-48842, a high-severity unauthenticated SQL injection in virtuser_query. Exploitation can expose messages, address books, and user identities. #Roundcube #SQLInjection #CVE202648842
  • 0
  • 1
  • 0
  • 12h ago
Profile picture fallback
Exploited Roundcube Webmail Vulnerability CVE-2026-48842(Roundcube Webmailの認証前SQLインジェクション脆弱性、実攻撃での悪用を確認) #SecurityOnline (Sep 24) securityonline.info/exploited-ro...
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Roundcube Webmail Vulnerability CVE-2026-48842 Actively Exploited A high-severity security vulnerability in Roundcube Webmail that was patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
CVE-2026-48842 enables unauthenticated SQL injection in Roundcube’s virtuser_query plugin, bypassing escaping and allowing database tampering and data access.
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Roundcubeの重大な脆弱性、攻撃で悪用されるように:CVE-2026-48842 | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47835/
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • WSO2
  • WSO2 Universal Gateway

06 Aug 2026
Published
25 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.58%

Description

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

Statistics

  • 5 Posts
  • 3 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products […]
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-5430 – WSO2 Multiple Products Path Traversal Vulnerability

Analyze the technical mechanics of CVE-2026-5430 with our WSO2 TSUITE brief, covering directory traversal vectors, unrestricted file uploads, and endpoint hardening....

thecybermind.co/bg2r

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

"CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks"

"[...] The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2."

bleepingcomputer.com/news/secu

  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback

CISA added two exploited CISA KEV vulnerabilities to its catalog. Patch WSO2 and Adobe Commerce to secure systems against active attacks.

securityonline.info/cisa-kev-v

  • 0
  • 0
  • 0
  • 19h ago

Bluesky

Profile picture fallback
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2.
  • 0
  • 3
  • 0
  • 4h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

11 Aug 2026
Published
25 Sep 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
1.22%

Description

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Statistics

  • 5 Posts
  • 11 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Go hunt on your SharePoint shit.

blog.previdian.com/cve-2026-65

Update September 25th, 2026: The exploitation creates a webshell backdoor named: "/_layouts/15/sphealth.aspx"

  • 2
  • 4
  • 0
  • 7h ago
Profile picture fallback

An exploited SharePoint RCE vulnerability is under attack. Technical details for this SharePoint RCE vulnerability are public. Patch CVE-2026-65660 now.

securityonline.info/exploited-

  • 1
  • 0
  • 0
  • 13h ago
Profile picture fallback

cisa.gov/news-events/alerts/20

  • CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability

  • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

  • 1
  • 2
  • 0
  • 5h ago

Bluesky

Profile picture fallback
📢 SharePoint CVE-2026-65660 : Bypass SafeControls via EditingPageParser menant à un RCE pré-authentification Cet article présente une analyse technique approfondie de CVE-2026-65660, une vulnérabilité affectant toutes… 🟡 vérification factuelle moyenne #SharePoint #InMemoryWebshell #Cyberveille
  • 1
  • 0
  • 0
  • 8h ago
Profile picture fallback
~Cybergcca~ MikroTik and Microsoft flaws are actively exploited; patch affected systems. - IOCs: CVE-2026-67277, CVE-2026-86060, CVE-2026-65660 - #CyberSecurity #ThreatIntel #Vulnerabilities
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Avast
  • (Free/Premiium/Ultimeat) Antivirus

11 Nov 2025
Published
14 Nov 2025
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.25%

KEV

Description

Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow.

Statistics

  • 9 Posts

Last activity: 13 hours ago

Bluesky

Profile picture fallback
CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2 | Discussion
  • 0
  • 0
  • 2
  • 14h ago
Profile picture fallback
CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2 https://www.safateam.com/intelligence-hub/research/technical-articles/cve-2025-13032-entering-and-breaking-the-avast-antivirus-sandbox-part-2 (https://news.ycombinator.com/item?id=49841115)
  • 0
  • 0
  • 5
  • 13h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 31 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

"the kernel.org CNA has CVE-2026-100000 reserved"

🍾

/ @gregkh

  • 6
  • 25
  • 0
  • 7h ago

Overview

  • Eufy
  • Omni C20

24 Sep 2026
Published
24 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.24%

KEV

Description

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 18 hours ago

Fediverse

Profile picture fallback

CVE-2026-93291 (CRITICAL): Eufy Omni C20 (<1.6.4) fails certificate validation, exposing devices to MITM and arbitrary code execution. Patch status unknown — use strong network protections. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

Critical Eufy robot vacuum vulnerabilities expose the Omni C20 and X10 Pro to OS command injection. Patch CVE-2026-93289 and CVE-2026-93291 immediately.

securityonline.info/eufy-robot

  • 1
  • 0
  • 0
  • 18h ago

Overview

  • pgpartman
  • pg_partman

18 Sep 2026
Published
19 Sep 2026
Updated

CVSS v3.1
HIGH (8.5)
EPSS
0.38%

KEV

Description

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept any nonempty schema name. A role with partman_user access can select a target schema where the role lacks the normal CREATE privilege, and the background worker performs the relocation with pg_partman_bgw.role privileges, which default to PostgreSQL superuser, bypassing the authorization check that a normal ALTER TABLE SET SCHEMA operation would enforce. This permits unauthorized relocation of retained child tables between schemas. This issue is fixed in version 5.5.0.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 23 hours ago

Fediverse

Profile picture fallback

CVE-2026-61821 pg_partman: drop_partition_id/time allow privilege escalation to superuser via retention_schema. CVSS 8.5, unpatched. patch to 5.5.0 now valtersit.com/cve/CVE-2026-618 #CVE #infosec #PostgreSQL

  • 1
  • 1
  • 0
  • 23h ago

Overview

  • Palo Alto Networks
  • Cloud NGFW

13 May 2026
Published
14 Jul 2026
Updated

CVSS v4.0
HIGH (7.8)
EPSS
96.38%

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Japan's Digital Agency was breached through a VPN flaw that was public before the attack. Data on ~246,000 officials and contractors may be exposed.

The agency won't name the product. Japanese researcher piyolog points to CVE-2026-0257 (PAN-OS GlobalProtect), added to CISA KEV on May 29. Detection to disclosure: eleven weeks, with no CVE or IOCs in the notice.

Our take on patching by CVSS, "zero trust" as a label, and Japan's disclosure culture:
japancyberwatch.com/articles/j

  • 1
  • 0
  • 0
  • 11h ago
Showing 1 to 10 of 100 CVEs