24h | 7d | 30d

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

14 Jul 2026
Published
13 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
2.96%

KEV

Description

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Statistics

  • 8 Posts
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

🛑 Attackers are exploiting a SharePoint authentication bypass.

CVE-2026-55040 lets unauthenticated attackers forge JWTs and impersonate any SharePoint site user, including administrators. Eight of 12 recorded exploit attempts occurred on August 12 and 13, after Rapid7 published a PoC.

See how the exploit works: thehackernews.com/2026/08/atta

  • 0
  • 1
  • 0
  • 13h ago
Profile picture fallback

「公開された概念実証(PoC)リリース後、攻撃者がSharePointの認証バイパスを悪用 」: #TheHackerNews

「攻撃者は、概念実証(PoC)コードの公開を受けて、新たに明らかになったMicrosoft SharePointの脆弱性を悪用し始めている。

問題となっている脆弱性は CVE-2026-55040 (CVSSスコア:9.1)で、認証の脆弱性に起因する重大なセキュリティ機能のバイパスに関するものです。この脆弱性は、マイクロソフトが2026年7月のパッチチューズデーアップデートの一環として修正しました。

マイクロソフトは先月、この脆弱性に関する勧告の中で、「この脆弱性によりなりすましが可能になるため、認証機能が回避される可能性がある」と述べた。「この脆弱性を悪用すると、攻撃者はファイルを漏洩させたりデータを改ざんしたりできる可能性があるが、システムの可用性に影響を与えることはできない」としている。 」

thehackernews.com/2026/08/atta

#prattohome

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

Attackers are actively exploiting CVE-2026-55040, a critical remote code execution vulnerability in Microsoft SharePoint, after a proof-of-concept exploit was released by Rapid7. This flaw affects Sha
helpnetsecurity.com/2026/08/13
#cybersecurity #Microsoft #SharePoint

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
Threat actors are exploiting CVE-2026-55040 in Microsoft SharePoint using a PoC to bypass authentication and impersonate users, enabling file disclosure and data modification.
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040, CVSS 9.1) after a proof-of-concept code was released by […]
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) 🔗 Read more: www.helpnetsecurity.com/2026/08/13/m... #vulnerability #cyberattack ##cybersecurity @rapid7.com
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
Servidores Microsoft SharePoint estão a ser alvo de ataques devido a falha crítica. A vulnerabilidade CVE-2026-55040 permite contornar a autenticação do sistema sem credenciais válidas. 🚨 #falha #microsoft #vaga
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
📢 CVE-2026-55040 : vulnérabilité SharePoint exploitée dans la nature après publication d'un PoC Il rapporte l'exploitation active en conditions réelles de CVE-2026-55040, une vulnérabilité affectant Microsoft SharePoint, corrigée lors… 🟢 vérification factuelle haute #PoC #SharePoint #Cyberveille
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
13 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.14%

KEV

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Statistics

  • 6 Posts
  • 7 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

「攻撃者がVMware vCenterの脆弱性を悪用し、永続的なリモートアクセスを取得する 」: #TheHackerNews

「QUIRSOの 新たな調査結果 によると、攻撃者は、最近パッチが適用されたBroadcom VMware vCenterの重大なセキュリティ脆弱性を積極的に悪用し始めている。

問題となっている脆弱性は CVE-2026-59310 (CVSSスコア:9.8)で、VMware vCenterサーバーのディレクトリトラバーサル脆弱性であり、ネットワークアクセス権を持つ悪意のある攻撃者がこれを悪用して任意のコードを実行できる可能性がある。この脆弱性に対するパッチは、ブロードコム社が先月末にリリースした。

ドイツのサイバーセキュリティ企業は、インシデント対応活動中にこの活動を発見したと発表した。 」

thehackernews.com/2026/08/atta

#prattohome

  • 1
  • 0
  • 0
  • 13h ago
Profile picture fallback

📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310.

Listen/Read: hackread.com/apt-exploits-crit

#CyberSecurity #VMware #vCenter #APT #Vulnerability

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access.
  • 1
  • 5
  • 0
  • 4h ago
Profile picture fallback
Threat actors exploit CVE-2026-59310 in VMware vCenter to achieve remote code execution and maintain persistent access via reverse_ssh.
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310. Listen/Read: hackread.com/apt-exploits... #CyberSecurity #VMware #vCenter #APT #Vulnerability
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
Critical VMware vCenter Syslog Server flaw CVE-2026-59310 is being actively exploited to deploy reverse_ssh for persistence and remote access, with 361 IPs hit across 47 countries. #VMware #Broadcom #Countries
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Microsoft
  • Microsoft Malware Protection Engine

16 Jun 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
10.75%

KEV

Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Statistics

  • 6 Posts
  • 5 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

“Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.”

theregister.com/cyber-crime/20

  • 1
  • 2
  • 0
  • 15h ago
Profile picture fallback

「Microsoftに恨みを持つハッカーが、完全にパッチが適用されたWindows上でシステム権限を取得できる新たなゼロデイ脆弱性を発見した。
/水曜日の裏技を使おうぜ、ベイビー 」: #TheRegister

「マイクロソフトに恨みを持つ、ゼロデイ攻撃を専門とするNightmare Eclipseは、マイクロソフトのRoguePlanetパッチ(CVE-2026-50656)を回避すると思われる、Defenderの新たなゼロデイ脆弱性「ShieldBreak」を公開した。これにより、攻撃者は完全にパッチが適用されたWindows 10、Windows 11、およびWindows Serverシステム上でSYSTEM権限を取得できる。

少なくとも他の研究者の一人によると、このエクスプロイトは有効だという。「試してみたところ、最新のWindows 11でも動作しました」と、元マイクロソフト社員でセキュリティ専門家のケビン・ボーモント氏 は述べている 。 」

theregister.com/cyber-crime/20

#prattohome

  • 1
  • 1
  • 0
  • 13h ago
Profile picture fallback

📰 New 'ShieldBreak' Exploit Bypasses Microsoft Defender Patch

A new zero-day exploit, 'ShieldBreak,' bypasses Microsoft's patch for the 'RoguePlanet' Defender flaw (CVE-2026-50656). The PoC allows SYSTEM-level access on patched Windows systems. No fix is currently available. #ZeroDay #MicrosoftDefender #CyberSe...

🔗 cyber.netsecops.io/articles/sh

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
ShieldBreak enables attackers with any initial access to obtain system-level privileges by bypassing a Microsoft Defender patch for CVE-2026-50656.
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Novo exploit ShieldBreak é capaz de ultrapassar as proteções do Microsoft Defender com 100% de eficácia, afetando sistemas com Windows 11 25H2 e Windows Server 2025. A ferramenta, criada por NightmareEclipse, contorna a correção lançada para a vulnerabilidade CVE-2026-50656. 🚨 #exploit #microsoft
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
Microsoft Defender: Critical Patch Bypass for CVE-2026-50656 RoguePlanet https://blackhatnews.tokyo/archives/129964 https://flagthis.com/tldr/6146 ##Microsoft ##ZeroDay ##PrivilegeEscalation ##RoguePlanet ##ShieldBreak
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 7 Posts
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

…et encore une vulnérabilité critique dans , trouvée une nouvelle fois par pwn.ai, qui a nécessité la publication en urgence de la mise à jour 7.0.4

La CVE-2026-65640 est une RCE assez intéressante côté traitement d’images. (ImageMagick)

Un utilisateur avec le rôle Author peut envoyer un fichier nommé comme une innocente image .png, alors que son contenu est en réalité du PostScript/EPS.
WordPress se fiait trop à l’extension ; ImageMagick, lui, regarde le contenu et peut transmettre le fichier à Ghostscript… avec à la clé une exécution de code.

Ce n’est donc pas une RCE pré-auth : il faut déjà disposer d’un compte Author. Mais sur un site multi-auteurs, communautaire ou avec des comptes peu maîtrisés, le risque devient nettement plus concret.
👇
wordpress.org/news/2026/08/wor
⬇️
github.com/WordPress/wordpress

  • 1
  • 1
  • 0
  • 6h ago
Profile picture fallback

WordPress 7.0.4 Fixes Critical Imagick RCE: How a Malicious PNG Could Become Server-Side Code Execution

WordPress 7.0.4 fixes CVE-2026-65640, an authenticated RCE affecting sites using Imagick and Ghostscript. Learn how malicious PNG reach code execution

thecybersecguru.com/news/wordp

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

WordPress 7.0.4 patches CVE-2026-65640, an Author-level remote code execution bug on sites using Imagick and Ghostscript. Update now.

securityonline.info/wordpress-

  • 0
  • 0
  • 0
  • 13h ago

Bluesky

Profile picture fallback
#WordPress: Yet another AI-discovered(@pwn_ai) Critical WordPress #RCE #Vulnerability CVE-2026-65640 Allows Authors to Execute Code via Malicious PNG File (via Imagemagick). Patched WordPress version 7.0.4 is now available, older versions backported: 👇 cybersecuritynews.com/wordpress-im...
  • 0
  • 0
  • 1
  • 13h ago
Profile picture fallback
WordPress released patches for CVE-2026-65640, a high-severity authenticated remote code execution flaw exploitable via PostScript-in-image uploads when Imagick and Ghostscript are enabled.
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
WordPress 7.0.4 patches CVE-2026-65640, an 8.8 flaw that could let Author-level attackers trigger remote code execution via crafted PostScript uploads on sites using Imagick and Ghostscript. #WordPress #CVE-2026-65640 #Imagick
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

11 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
HIGH (7.0)
EPSS
0.33%

Description

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Statistics

  • 6 Posts
  • 3 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

(CISA TS-SOC) CVE-2026-68820 – Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Severity: HIGH Impact Summary: Allows an authorized attacker to elevate privileges locally via a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock....

thecybermind.co/join

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
Microsoft、2026年8月定例パッチで421件の脆弱性を修正 悪用確認済みゼロデイ1件(CVE-2026-68820)、公開済み未パッチ2件も rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 1
  • 0
  • 20h ago
Profile picture fallback
Lazarus-linked attacks exploit Windows CVE-2026-68820 as a zero-day to gain SYSTEM access and deploy Troy against defense and aerospace firms.
  • 0
  • 1
  • 0
  • 17h ago
Profile picture fallback
CVE-2026-68820: Windows AFD.sys Zero-Day socprime.com/blog/cve-202...
  • 0
  • 1
  • 0
  • 4h ago
Profile picture fallback
Microsoft's record Patch Tuesday fixed 419 vulnerabilities, including 3 zero-days. AI-assisted flaw discovery is driving bug counts higher, and CVE-2026-68820 was exploited in the wild, linked to Lazarus Group. #PatchTuesday #AI #LazarusGroup
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
📢 Lazarus Group exploite un zero-day Windows (CVE-2026-68820) via de fausses offres d'emploi Cet article documente une nouvelle vague de la campagne Operation Dream Job, attribuée au groupe nord-coréen Lazarus, ciblant les… 🟢 vérification factuelle haute #LazarusGroup #ZeroDay #Cyberveille
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Adobe
  • Adobe Commerce

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.48%

KEV

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Statistics

  • 6 Posts
  • 5 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

「ハッカーがAdobe Commerceの重大な脆弱性を悪用し、顧客アカウントを乗っ取る 」: #BLEEPINGCOMPUTER

「AdobeのeコマースプラットフォームであるCommerceとMagentoにおける重大な脆弱性(CVE-2026-71362)を悪用しようとする試みが検出されました。この脆弱性により、攻撃者が顧客アカウントを乗っ取る可能性があります。

この脆弱性は、認証なしに「機密性の高いリソースへの上位アクセス権を取得する」ために悪用される可能性のある、誤った認証の脆弱性と説明されており、Adobeが昨日のセキュリティアップデートで対処した7つの問題のうちの1つです。

ソフトウェアベンダーは 勧告 の中で、修正された脆弱性に対する実際の攻撃事例は把握していないと述べているが、eコマースセキュリティ企業のSansecは、同社のShieldウェブアプリケーションファイアウォール(WAF)が既にCVE-2026-71362の悪用を阻止していると述べている。 」

bleepingcomputer.com/news/secu

#prattohome

  • 1
  • 0
  • 0
  • 13h ago
Profile picture fallback

「AdobeがColdFusionとCampaign ClassicのCVSS 10.0違反3件を修正 」: #TheHackerNews

「Adobeは 、ColdFusion、Commerce、およびCampaign Classicに影響を与える複数の重大なセキュリティ脆弱性に対処するためのアップデートをリリース

最も深刻な欠陥は以下のとおりです。

CVE-2026-48362 (CVSSスコア: 10.0)
CVE-2026-48273 (CVSSスコア: 9.9)
CVE-2026-71384 (CVSSスコア: 9.6))
CVE-2026-71362 (CVSSスコア:9.1)
CVE-2026-71398 (CVSSスコア: 10.0)
CVE-2026-27302 (CVSSスコア: 10.0)
CVE-2026-48381 (CVSSスコア:9.0)

thehackernews.com/2026/08/adob

#prattohome

  • 1
  • 0
  • 0
  • 13h ago

Bluesky

Profile picture fallback
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.
  • 2
  • 1
  • 0
  • 23h ago
Profile picture fallback
Adobe Commerce and Magento are facing CVE-2026-71362, a critical auth flaw that can hijack customer sessions and expose account data. Sansec says its Shield WAF is already blocking exploit attempts. #AdobeCommerce #Magento #CVE2026-71362
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
CVE-2026-71362 enables unauthenticated privilege escalation in Adobe Commerce, letting attackers hijack customer sessions and access private data; apply August 2026 patches immediately.
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
Adobe Commerce CVE-2026-71362 was exploited soon after disclosure. The critical 9.1 flaw can let unauthenticated attackers hijack customer sessions and access private account data. #AdobeCommerce #Magento #CVE202671362
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Cisco
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (8.6)
EPSS
0.87%

Description

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 4 hours ago

Bluesky

Profile picture fallback
Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) 📖 Read more: www.helpnetsecurity.com/2026/08/13/c... #exploit #firewall #secureaccess #vulnerability #cybersecurity #cybersecuritynews @cisco.com
  • 0
  • 1
  • 0
  • 13h ago
Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-20349) Cisco ASA and FTD Denial of Service via Remote Access SSL VPN". #cybersecurity #AttackSurfaceManagement #EASM https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) www.helpnetsecurity.com/2026/08/13/c...
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
~Cybergcca~ Active exploitation of Cisco ASA/FTD SSL VPN DoS vuln (CVE-2026-20349); AMD, GitLab, Plesk patches also released. - IOCs: CVE-2026-20349 - #CVE202620349 #Cisco #ThreatIntel
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Metabase
  • Metabase

10 Aug 2026
Published
12 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
10.40%

Description

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Statistics

  • 2 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

(CISA TS-SOC) CVE-2026-72898 – Metabase SQL Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to gain administrator access, modify configuration, steal credentials, and exfiltrate data from connected databases via SQL injection....

thecybermind.co/join

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

🚨 CRITICAL ALERT: CVE-2026-72898 (CVSS 10.0)

Unauthenticated SQL Injection in Metabase allows remote attackers to execute arbitrary SQL, hijack admin accounts & exfiltrate enterprise DB credentials. Patch immediately!

Read full analysis: denizhalil.com/2026/08/13/cve-

#CyberSecurity #Metabase #SQLi

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Foxit Software Inc.
  • Foxit PDF Editor

13 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
MEDIUM (4.7)
EPSS
0.12%

KEV

Description

Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 13 hours ago

Fediverse

Profile picture fallback

Foxit PDF Reader und Editor 2026.1.3.36551 korrigiert eine Sicherheitslücke (CVE-2026-18622)

deskmodder.de/blog/2026/08/13/

  • 3
  • 0
  • 1
  • 13h ago

Overview

  • Unknown
  • KiviCare

13 Aug 2026
Published
13 Aug 2026
Updated

CVSS
Pending
EPSS
0.15%

KEV

Description

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 13 hours ago

Fediverse

Profile picture fallback

CVE-2026-13610 | CRITICAL privilege flaw in KiviCare <4.5.2 lets unauthenticated attackers create privileged staff accounts, risking patient data exposure 🏥. Restrict registration endpoint & monitor user creation. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 13h ago
Showing 1 to 10 of 68 CVEs