24h | 7d | 30d

Overview

  • Zimbra
  • Collaboration

13 Aug 2026
Published
14 Aug 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
0.54%

KEV

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Statistics

  • 6 Posts
  • 1 Interaction

Last activity: 2 hours ago

Fediverse

Profile picture fallback

CVE-2026-73570 is exploited in the wild. This unauthenticated RCE hits Zimbra Collaboration via SNMP notifications. Patch to 10.1.20 now.

securityonline.info/zimbra-cve

  • 1
  • 0
  • 0
  • 17h ago
Profile picture fallback

CRITICAL: CVE-2026-73570 in Zimbra Collaboration Suite is under active exploit. RCE via SNMP notifications lets unauth attackers run OS commands as Zimbra user. Patch to 10.1.20 now & monitor for abnormal files/restarts. Details: radar.offseq.com/threat/critic

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
CVE-2026-73570 in Zimbra Collaboration enables unauthenticated command injection leading to remote code execution when zimbra-snmp is installed and SNMP notifications are enabled.
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
CVE-2026-73570 in Zimbra Collaboration Suite is being exploited in the wild, enabling unauthenticated arbitrary OS command execution as the Zimbra user when zimbra-snmp is installed and SNMP notifications are enabled.
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
Actively exploited vulnerability in Zimbra Collaboration Suite CVE-2026-73570
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
CERT Polska reports active exploitation of CVE-2026-73570 in Zimbra Collaboration. The flaw affects systems with zimbra-snmp and SNMP notifications enabled, allowing unauthenticated OS command execution as the Zimbra user. #Zimbra #CERTPolska #Poland
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • mlflow
  • mlflow

17 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.3)
EPSS
8.15%

Description

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

CVE-2026-64849 exposes unauthenticated MLflow tracking servers to critical server-side request forgery (SSRF) threats via redirect bypasses. Discover immediate mitigation strategies, CISA KEV compliance guidelines, and SOC detection playbooks to secure your AI infrastructure. thecybermind.co/jily

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
CISA says attackers are actively exploiting CVE-2026-64849 in MLflow, using a DNS-rebinding SSRF bypass to reach internal services and cloud metadata, risking AWS IAM credential theft on unpatched systems. #MLflow #CISA #AWS
  • 0
  • 1
  • 0
  • 7h ago
Profile picture fallback
CISAが既知の悪用された脆弱性を1件カタログに追加 CISA Adds One Known Exploited Vulnerability to Catalog #CISA (Aug 19) CVE-2026-64849 MLflowサーバーサイドリクエストフォージェリの脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
🚨 CVE-2026-64849 is a critical unauthenticated SSRF discovered in MLflow. It lets attackers reach internal services and potentially steal sensitive data. Upgrade to version 3.15.0 as it also fixes two additional flaws affecting MLflow, CVE-2026-69148 and CVE-2026-69146. Details: buff.ly/Gjg9jor
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • PTC
  • Windchill PDMLink

18 Jun 2026
Published
01 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
30.20%

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 1 hour ago

Fediverse

Profile picture fallback

ReliaQuest found Clop deploying a purpose-built JSP web shell that abuses Windchill's internal APIs to decrypt secrets and steal files after exploiting CVE-2026-12569.

meterpreter.org/clop-windchill

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

⚠️ CRITICAL: Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Clop ransomware operators deployed a custom JSP web shell targeting PTC Windchill and FlexPLM servers, exploiting CVE-2026-12569 to decrypt stored credentials and exfiltrate engineering data. Any organization running vulnerable Windchill instances is at immediate risk of credential compromise, late…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
📢 Clop exploite CVE-2026-12569 dans PTC Windchill avec un web shell personnalisé pour extorsion massive 📅 Source : ReliaQuest Threat Research Team, publié le 18 août 2026. Cette analyse technique décrit une campagne d'extorsion de… 🟢 vérification factuelle haute #Clop #PTCWindchill #Cyberveille
  • 1
  • 0
  • 0
  • 1h ago

Overview

  • Elementor
  • Elementor Pro

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
0.42%

KEV

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Statistics

  • 4 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2026-32475 in Elementor Pro Forms File Upload enables unauthenticated remote code execution by bypassing extension checks and writing a PHP file to a public directory.
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
Critical flaw in Elementor Pro, CVE-2026-32475, lets unauthenticated attackers upload PHP via the Forms module and run code on WordPress sites up to 4.2.1. #ElementorPro #WordPress #CVE202632475
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0.
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
Critical Elementor Pro bug, CVE-2026-32475, may let attackers upload a malicious PHP file and trigger RCE on vulnerable WordPress sites using published forms with File Upload enabled. #ElementorPro #WordPress #Patchstack
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Red Hat
  • Red Hat build of Keycloak 26.4
  • rhbk/keycloak-operator-bundle

18 Aug 2026
Published
20 Aug 2026
Updated

CVSS
Pending
EPSS
0.39%

KEV

Description

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

Statistics

  • 2 Posts
  • 7 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

Guten Morgen an @univention Kund*innen, die unsere #Keycloak App einsetzen! Wir werden demnächst Version 26.7.2 herausbringen. Von dem Account-Takeover-CVE ist unsere App nicht betroffen.

Details findet Ihr hier: help.univention.com/t/keycloak

  • 3
  • 4
  • 0
  • 12h ago

Bluesky

Profile picture fallback
🚨 Dutch NCSC warns about CVE-2026-18963, a critical Keycloak password-reset vulnerability. 🔐 Affected systems may be exposed to unauthenticated account takeover. What to check and how to fix it: basefortify.eu/posts/2026/0... #Keycloak #CyberSecurity
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Splunk
  • Splunk MCP Server app

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.56%

KEV

Description

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 14 hours ago

Fediverse

Profile picture fallback

Splunk MCP Server app v1.2 is impacted by CVE-2026-76404 (CRITICAL, CVSS 9.1) — insecure deserialization lets admin users run arbitrary OS commands. Limit admin access & monitor for misuse until a patch is released. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 17h ago
Profile picture fallback

Splunk patches CVE-2026-76404, a critical remote code execution flaw in the MCP Server app, plus 16 more bugs across its apps and add-ons.

securityonline.info/splunk-app

  • 1
  • 0
  • 0
  • 14h ago

Overview

  • NetScaler
  • ADC

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.34%

KEV

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback
  • 1
  • 0
  • 0
  • 22h ago

Bluesky

Profile picture fallback
Citrix flags urgent NetScaler patching for CVE-2026-19490 and CVE-2026-19489, which can enable auth bypass and denial of service on specific setups. CISA still tracks prior Citrix flaws in KEV. #Citrix #NetScaler #CISA
  • 1
  • 0
  • 0
  • 1h ago
Profile picture fallback
Citrix released updates for NetScaler ADC/Gateway to fix CVE-2026-19489 and CVE-2026-19490, including a critical authentication bypass under specific SIP ALG and SAML conditions.
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Frauscher Sensortechnik
  • FDS 102

20 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.55%

KEV

Description

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.

Statistics

  • 3 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Frauscher FDS 102 v2.1.0 hit by CRITICAL vuln (CVE-2026-14950): insufficient session expiration lets remote attackers keep using stolen session tokens. No patch yet — monitor sessions, restrict access. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

Frauscher FDS102 vulnerabilities include CVE-2026-14950 (CVSS 9.8), a session flaw enabling unauthorized continued access. Update to v2.14.0.

securityonline.info/frauscher-

  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Microsoft
  • Microsoft Configuration Manager

14 Jul 2026
Published
20 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.68%

KEV

Description

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 6 hours ago

Fediverse

Profile picture fallback

CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM

securityonline.info/cve-2026-4

  • 0
  • 0
  • 0
  • 6h ago

Bluesky

Profile picture fallback
PoC exploit chain (CVE-2026-47301) for SCCM, combining a broken access, CAB arbitrary-write path traversal, certificate verification bypass, and DLL hijacking to achieve SYSTEM-level code execution. github.com/OmriBaso/SCC... #infosec #cybersecurity #pentest #cve #redteam
  • 0
  • 1
  • 0
  • 13h ago

Overview

  • GitLab
  • GitLab

17 Aug 2026
Published
17 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
1.51%

KEV

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Statistics

  • 2 Posts

Last activity: 12 hours ago

Bluesky

Profile picture fallback
CVE-2026-19478 enables unauthenticated remote code injection in GitLab, allowing deletion and modification of public projects; attackers began exploiting within two days.
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-60702) Oracle WebLogic Server Takeover via T3 and IIOP" and "Emerging Threat: (CVE-2026-19478) GitLab Unauthenticated Project Deletion via #GraphQL Directive". #cybersecurity #AttackSurfaceManagement https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 16h ago
Showing 1 to 10 of 68 CVEs