24h | 7d | 30d

Overview

  • Cisco
  • Cisco Secure Email

14 Sep 2026
Published
15 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.16%

Description

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Statistics

  • 17 Posts
  • 8 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

In einem aktuellen Sicherheitshinweis warnt Cisco vor der Ausnutzung einer Zero-Day-Schwachstelle in seiner Secure Email Gateway-Lösung. Angreifer nutzen diese, um aus der Ferne SQL-Befehle auf verwundbaren Systemen auszuführen und mit Root-Rechten zu operieren. Auch weil keine Authentifizierung erforderlich ist, wird CVE-2026-76461 mit 9.8 von 10 bewertet.
Betreiber sollten daher unverzüglich aktiv werden:
bsi.bund.de/SharedDocs/Cybersi

  • 4
  • 2
  • 0
  • 19h ago
Profile picture fallback

「Ciscoのセキュアメールゲートウェイの脆弱性が実際に悪用され、ルート権限でのコマンド実行が可能になる 」: #TheHackerNews

「スコは、Cisco Secure Email Gateway向けAsyncOSソフトウェアに影響を与える新たな重大な脆弱性が、実際に悪用されていると警告した。

CVE-2026-76461 として追跡されているこの脆弱性は 、CVSSスコアが10.0点満点中9.8点です。これは、メール解析ロジックにおける検証の不備が原因で、認証されていないリモート攻撃者が、基盤となるオペレーティングシステム上でroot権限で任意のコマンドを実行できる可能性があるとされています。

シスコは月曜日の勧告で、「攻撃者は、悪意のあるSQL文を含む細工された電子メールメッセージを影響を受けるデバイスに送信することで、この脆弱性を悪用する可能性がある」 と述べた 。」

thehackernews.com/2026/09/cisc

#prattohome

  • 1
  • 1
  • 0
  • 23h ago
Profile picture fallback

Actionable C-Suite threat intelligence and mitigation strategies for CVE-2026-76461, addressing active SQL injection exploitation vectors within enterprise Cisco Secure Email Gateway infrastructures. thecybermind.co/r5ry

  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

Geopolitical tensions: A Russian drone struck a Kyiv-Warsaw train near the Polish border (Sept 13), and Houthi forces secured Yemen's Red Sea coast (Sept 11), affecting maritime routes. Tech news: Apple's Siri AI, powered by Apple Intelligence, began its beta rollout (Sept 14). Cybersecurity: Cisco warned of active exploitation of a critical Secure Email Gateway flaw (CVE-2026-76461) (Sept 15), and Anthropic reported Russia-linked spies used its AI Claude for hacking campaigns.

#Cybersecurity #Geopolitics #TechNews

  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

📰 Cisco Patches Actively Exploited Zero-Day in Secure Email Gateways

Cisco patches critical, actively exploited zero-day (CVE-2026-76461) in Secure Email Gateways. Unauthenticated attackers can compromise devices via a crafted email. CISA has added it to the KEV catalog. #CyberSecurity #ZeroDay #Infosec #Cisco

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways

Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabili…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 1
  • 6h ago
Profile picture fallback

A critical Cisco Secure Email Gateway vulnerability allows unauthenticated attackers to gain root access via a single email. Learn about CVE-2026-76461.

meterpreter.org/cisco-secure-e

  • 0
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
Cisco Secure Email GatewayにおけるSQLインジェクションの脆弱性(CVE-2026-76461)に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260027.html
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
📢 [VULN] ⚠️Injection SQL exploitée dans Cisco Secure Email Gateway - CVE-2026-76461 Le 14 septembre 2026 à 16 h 00 UTC, Cisco a publié deux avis de sécurité sur sa passerelle de messagerie. #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
> 注意喚起: Cisco Secure Email GatewayにおけるSQLインジェクションの脆弱性(CVE-2026-76461)に関する注意喚起 (公開) https://www.jpcert.or.jp/at/2026/at260027.html
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Cisco patched CVE-2026-76461, a critical zero-day in Secure Email Gateway actively exploited to run root commands without auth. CISA added it to KEV, and Cisco disclosed more critical flaws. #Cisco #CISA #KEV
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) 🔗 Read more: www.helpnetsecurity.com/2026/09/15/c... #cybersecurity #cybersecuritynews #0day #emailsecurity #enterprise #SMBs @cisco.com
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
@sophossecurity.bsky.social Critical SQL injection is under active exploitation, enabling unauthenticated remote root command execution. - IOCs: CVE-2026-76461 - #CVE202676461 #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
CVE-2026-76461 in Cisco Secure Email Gateway enables unauthenticated remote attackers to execute arbitrary commands as root; patch immediately and check logs for SQL probes.
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
Cisco Secure Email GatewayにおけるSQLインジェクションの脆弱性(CVE-2026-76461)に関する注意喚起 #JPCERTCC (Sep 15) www.jpcert.or.jp/at/2026/at26...
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-76461) Cisco Secure Email Gateway Root RCE via Email Parsing". #cybersecurity #AttackSurfaceManagement #EASM https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • GitLab
  • GitLab

12 Sep 2026
Published
12 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
11.96%

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Statistics

  • 8 Posts
  • 86 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Aktuell sind uns in Deutschland rund 3.150 offen aus dem Internet erreichbare GitLab-Instanzen bekannt, die noch für die kritische Schwachstelle CVE-2026-85706 verwundbar sind. Diese werden ab heute an die zuständigen Netzbetreiber gemeldet.

1.640 GitLab-Instanzen sind noch für die ältere kritische Schwachstelle CVE-2026-19478 verwundbar. Diese melden wir bereits seit dem 31.08. an die zuständigen Netzbetreiber.

Beide Schwachstellen werden bereits aktiv ausgenutzt.
🚨 Patch NOW! 🚨

  • 43
  • 35
  • 0
  • 21h ago
Profile picture fallback

Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.

meterpreter.org/gitlab-cve-202

  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback

Actionable C-Suite threat intelligence for CVE-2026-85706, covering active path traversal exploitation vectors, endpoint hardening, and patch automation across GitLab environments. thecybermind.co/uzke

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
🚨 GitLab CVE-2026-85706 is a CVSS 10.0 vulnerability under active exploitation. Censys sees 86K+ GitLab hosts on the Internet. If your instance was exposed while vulnerable: patch, rotate credentials, and investigate for compromise. https://bit.ly/4A690c6
  • 1
  • 2
  • 1
  • 16h ago
Profile picture fallback
Dropped some research and detection/hunt content on CVE-2026-85706 🤓
  • 0
  • 4
  • 0
  • 6h ago
Profile picture fallback
GitLab has patched CVE-2026-85706, a CVSSv3.1 10.0 path traversal vulnerability in the repository commits API that allows an unauthenticated user to read arbitrary files from GitLab CE and EE servers. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September ..
  • 0
  • 1
  • 0
  • 14h ago

Overview

  • vitejs
  • vite

07 Apr 2026
Published
17 Aug 2026
Updated

CVSS v4.0
HIGH (8.2)
EPSS
2.00%

KEV

Description

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.

Statistics

  • 4 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

「大規模スキャンキャンペーンがViteの脆弱性を悪用し、公開された開発サーバーからクラウド認証情報を抽出 」: #TheHackerNews

「サイバーセキュリティ研究者らは、Viteの導入事例を標的とした大規模なスキャンキャンペーンの詳細を明らかにし、機密データの窃盗を企てていたことを明らかにした。

F5 Labs によると、1つ目はインターネットに公開されているVite開発サーバーを標的とした自動化された攻撃で、クラウド認証情報、Amazon Web Services(AWS)およびMicrosoft Azureインスタンスからの構成情報、インフラストラクチャの状態ファイルを盗むように設計されている 。

2026年8月に観測された認証情報収集活動は、Viteの深刻なセキュリティ脆弱性であるCVE-2026-39364(CVSSスコア:8.2)の脆弱性を悪用していることが判明しました。」

thehackernews.com/2026/09/mass

#prattohome

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
Cloud Takeover: Mass Scanning for Exposed Vite Endpoints (CVE-2026-39364) #appsec
  • 0
  • 0
  • 1
  • 21h ago
Profile picture fallback
Attackers scan internet-exposed Vite servers to steal environment files, cloud credentials, and infrastructure configuration using CVE-2026-39364 file-access bypasses.
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Rymera Web Co Pty Ltd.
  • Woocommerce Wholesale Lead Capture
  • woocommerce-wholesale-lead-capture

19 Mar 2026
Published
29 Apr 2026
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
1.73%

KEV

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

Statistics

  • 3 Posts

Last activity: 1 hour ago

Bluesky

Profile picture fallback
Hackers are exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP backdoors and take over WordPress sites. Wordfence blocked 100,000+ attempts. #WooCommerce #WordPress #Wordfence
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
Threat actors are actively exploiting CVE-2026-27540, a critical arbitrary file upload flaw in the WooCommerce Wholesale Lead Capture plugin with […]
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
Unauthenticated attackers exploit CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload arbitrary files, including PHP web shells, enabling remote code execution.
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • GitLab
  • GitLab

17 Aug 2026
Published
17 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
5.81%

KEV

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Statistics

  • 1 Post
  • 78 Interactions

Last activity: 21 hours ago

Fediverse

Profile picture fallback

Aktuell sind uns in Deutschland rund 3.150 offen aus dem Internet erreichbare GitLab-Instanzen bekannt, die noch für die kritische Schwachstelle CVE-2026-85706 verwundbar sind. Diese werden ab heute an die zuständigen Netzbetreiber gemeldet.

1.640 GitLab-Instanzen sind noch für die ältere kritische Schwachstelle CVE-2026-19478 verwundbar. Diese melden wir bereits seit dem 31.08. an die zuständigen Netzbetreiber.

Beide Schwachstellen werden bereits aktiv ausgenutzt.
🚨 Patch NOW! 🚨

  • 43
  • 35
  • 0
  • 21h ago

Overview

  • mySCADA Technologies
  • mySCADA myPRO

15 Sep 2026
Published
15 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.

Statistics

  • 3 Posts

Last activity: 6 hours ago

Fediverse

Profile picture fallback

CVE-2026-73807 | CRITICAL: mySCADA myPRO (v0 – 2.1) API flaw allows unauthenticated access to privileged functions. No patch yet — restrict API network access & monitor logs. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

Discover the latest mySCADA myPRO Manager vulnerabilities, including CVE-2026-73807, and learn how to patch your systems to prevent remote attacks.

securityonline.info/myscada-my

  • 0
  • 0
  • 0
  • 6h ago

Bluesky

Profile picture fallback
~Cisa~ Unauthenticated flaws enable privileged access and arbitrary SMS; update to 2.2. - IOCs: CVE-2026-73807, CVE-2026-82567 - #CVE-2026-73807 #CVE-2026-82567 #ThreatIntel
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • marimo-team
  • marimo

09 Apr 2026
Published
24 Apr 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
98.94%

Description

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Bluesky

Profile picture fallback
Skilled attackers can pivot from Marimo to SSH bastion and AWS secrets in seconds, exploiting CVE-2026-39987 with credential pivoting and evasion beyond AI-assisted expectations.
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
A skilled human attacker exploited a critical Marimo vulnerability (CVE-2026-39987) to pivot from a vulnerable notebook to an SSH bastion […]
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Logitech
  • Logi Options+

14 Sep 2026
Published
14 Sep 2026
Updated

CVSS v4.0
HIGH (8.5)
EPSS
0.11%

KEV

Description

A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Fediverse

Profile picture fallback

Logitech Options+ : une faille donne les privilèges SYSTEM à n’importe quel utilisateur Windows it-connect.fr/logitech-options #ActuCybersécurité #Cybersécurité #Vulnérabilité

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
📢 [VULN] Logitech Options+ : une faille donne les privilèges SYSTEM à n’importe quel utilisateur Windows - CVE-2026-12518 C'est un simple logiciel destiné à configurer une souris ou un clavier, et pourtant Logitech Options+ contient une faille de sécurité permett… #Vulnérabilité #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Fortinet
  • FortiProxy

09 Feb 2024
Published
04 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
84.28%

Description

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

Statistics

  • 2 Posts

Last activity: 1 hour ago

Bluesky

Profile picture fallback
Thai broadband provider 3BB was hit via Fortinet flaw CVE-2024-21762, with attackers using exploit tools, credential harvesters, and a MeshCentral backdoor to move laterally and hide tracks. #Thailand #Fortinet #MeshCentral
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
タイの大手ブロードバンド事業者、Fortinet製品の脆弱性通じて侵害される(CVE-2024-21762) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47732/
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
Acronis Warns of Actively Exploited Linux Privilege Escalation Flaw Acronis has warned of CVE-2026-87886, a high-severity Linux privilege escalation vulnerability affecting its cPanel, WHM, and Plesk backup integrations.
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
Acronis disclosed CVE-2026-87886 in its cPanel, WHM, and Plesk backup plugins: a Linux local privilege escalation flaw (CVSS 7.8) already used in limited targeted attacks. #Acronis #cPanel #Plesk
  • 0
  • 0
  • 0
  • 4h ago
Showing 1 to 10 of 84 CVEs