24h | 7d | 30d

Overview

  • Zyxel
  • GS1900-48HPv2 firmware

16 Jun 2026
Published
22 Sep 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
1.99%

Description

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Statistics

  • 9 Posts
  • 7 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

CISA warned of an exploited Zyxel switch vulnerability in GS1900 devices. Patch the Zyxel switch vulnerability now to prevent network compromise.

securityonline.info/exploited-

  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a stack-based buffer overflow that could allow attackers […]
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
  • 0
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating system (OS) command execution. thehackernews.com/2026/09/zyxe...
  • 1
  • 1
  • 1
  • 9h ago
Profile picture fallback
~Cisa~ CISA confirms active exploitation of a Zyxel GS1900 switch buffer overflow; prioritize remediation. - IOCs: CVE-2026-7273 - #CVE20267273 #KEV #ThreatIntel
  • 1
  • 0
  • 0
  • 17h ago
Profile picture fallback
CISA added a patched Zyxel GS1900 stack-based buffer overflow (CVE-2026-7273) to KEV due to evidence of active exploitation.
  • 1
  • 0
  • 0
  • 14h ago
Profile picture fallback
Zyxel GS1900 Switches Targeted in Active Attacks, CISA Warns Attackers are actively exploiting CVE-2026-7273 in Zyxel GS1900 switches, with CISA urging organizations to patch affected devices.
  • 1
  • 0
  • 0
  • 10h ago
Profile picture fallback
Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) 📖 Read more: www.helpnetsecurity.com/2026/09/22/z... #cybersecurity #cybersecuritynews #exploit #government #SMBs @greynoise.io @greynoise.infosec.exchange.ap.brid.gy @veeam.com
  • 1
  • 0
  • 0
  • 10h ago
Profile picture fallback
CISA says CVE-2026-7273 in Zyxel GS1900 switches is actively exploited for data theft. The stack overflow lets unauthenticated LAN users run OS commands. #Zyxel #CISA #US
  • 1
  • 0
  • 0
  • 10h ago

Overview

  • checkpoint
  • Quantum Security Management

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

Description

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

Statistics

  • 9 Posts
  • 4 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

🚨 Check Point patches Management Server zero-day exploited in attacks

Check Point has released fixes for CVE-2026-93616, a vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts on affected management servers.

The company says a small number of customers have already been attacked.

Affected products include:

• Security Management Server
• Multi-Domain Security Management Server
• Log Server
• Multi-Domain Log Server
• SmartEvent

The vulnerability carries a CVSS score of 9.8.

Check Point advises installing the applicable fixes, restricting management access to trusted IP addresses, and checking for signs of exploitation.

LivePatch Take 28/29 does not fix this vulnerability.

Source: bleepingcomputer.com/news/secu

  • 0
  • 1
  • 0
  • 2h ago
Profile picture fallback

Check Point Quantum Security Management is affected by CVE-2026-93616 (CRITICAL, CVSS 9.8): unauthenticated attackers can upload & execute scripts via path traversal. Restrict access & monitor activity until patch info is released. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

A critical exploited Check Point Management vulnerability (CVE-2026-93616) allows attackers to execute arbitrary scripts. Secure your servers now.

securityonline.info/exploited-

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. The security firm bug is already being exploited. Attackers can abuse the flaw without logging in to […]
Check Point Fixes a New Actively Exploited Critical Security Flaw
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback

Check Point has disclosed a zero-day (in Security Management Server) and marked an older bug also as exploited in the wild (in Site-to-Site VPN)

blog.checkpoint.com/security/s

  • 3
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
sk1000171 - CVE-2026-93616: Directory Traversal and File upload allows execution of arbitrary script on the Management Server support.checkpoint.com/results/sk/s... CVSS: 9.8 - Actively exploited
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
Check Point released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in Security Management Server products being exploited in the wild, enabling unauthenticated script execution. #CheckPoint #CVE202693616 #SmartConsole
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
Check Point disclosed CVE-2026-93616, a path traversal zero-day in Security Management Server web services used in targeted attacks, and released fixes plus hunting guidance. #CheckPoint #ZeroDay #VPN
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
CVE-2026-93616 enables unauthenticated script execution via path traversal in Check Point Security Management Server, fixed September 22, while separate VPN attempts target CVE-2026-85102.
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • D-Link
  • DIR-822A

07 Sep 2026
Published
08 Sep 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
1.35%

KEV

Description

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

Statistics

  • 6 Posts
  • 26 Interactions

Last activity: 6 hours ago

Bluesky

Profile picture fallback
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
  • 3
  • 3
  • 0
  • 8h ago
Profile picture fallback
lol CVE-2026-86296
  • 0
  • 6
  • 0
  • 6h ago
Profile picture fallback
D-Link flags a max-severity zero-day in legacy DIR-822A routers. CVE-2026-86296 is an unauthenticated stack-based buffer overflow in the DHCP server; public PoC exists. #DLink #DIR822A #CVE202686296
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
D-Link warns of two major bugs with public POCs CVE-2026-86296: supportannouncement.us.dlink.com/security/pub... POC: tzh00203.notion.site/D-Link-DIR-8... CVE-2026-93958: supportannouncement.us.dlink.com/security/pub... POC: github.com/FoundTL/D-Li...
  • 1
  • 3
  • 0
  • 7h ago

Overview

  • F5
  • BIG-IP

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

Description

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 4 Posts
  • 15 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

EITW 0day in F5 APM.

my.f5.com/manage/s/article/K00

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). (CVE-2026-94127)

This vulnerability allows an unauthenticated attacker to perform RCE. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.

  • 2
  • 5
  • 0
  • 6h ago
Profile picture fallback

An exploited BIG-IP APM vulnerability tracked as CVE-2026-94127 allows RCE attacks. Secure your BIG-IP APM vulnerability deployments with new F5 hotfixes.

securityonline.info/big-ip-apm

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
BIG-IP APM vulnerability CVE-2026-94127 #critical #9.8 my.f5.com/manage/s/art...
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Arista Networks
  • VeloCloud Orchestrator (VCO) On-Prem

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.42%

Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

Statistics

  • 4 Posts
  • 5 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-93952 (CRITICAL, CVSS 10) impacts Arista VeloCloud Orchestrator (On-Prem) via improper input validation. Remote, unauthenticated access may lead to full system compromise. Patch urgently. radar.offseq.com/threat/cve-20

  • 2
  • 0
  • 0
  • 12h ago
Profile picture fallback

An exploited VeloCloud vulnerability with a 10.0 CVSS score hits Arista appliances. Patch the critical VeloCloud vulnerability to stop active attacks.

securityonline.info/velocloud-

  • 1
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
CVE-2026-93952 enables unauthenticated remote attackers to gain internal privileges on on-premises VeloCloud Orchestrator, potentially compromising orchestrator and managed Edge devices.
  • 1
  • 0
  • 0
  • 7h ago
Profile picture fallback
Arista disclosed a critical flaw (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) actively exploited as of September 22. The vulnerability, with […]
  • 1
  • 0
  • 0
  • 7h ago

Overview

  • checkpoint
  • Quantum Security Gateway

09 Sep 2026
Published
22 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.33%

Description

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Statistics

  • 4 Posts
  • 7 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

An exploited Check Point VPN vulnerability allows remote code execution. Patch this Check Point VPN vulnerability now to block active in-the-wild attacks.

securityonline.info/checkpoint

  • 0
  • 1
  • 0
  • 5h ago
Profile picture fallback

Check Point has disclosed a zero-day (in Security Management Server) and marked an older bug also as exploited in the wild (in Site-to-Site VPN)

blog.checkpoint.com/security/s

  • 3
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
CVE-2026-93616 enables unauthenticated script execution via path traversal in Check Point Security Management Server, fixed September 22, while separate VPN attempts target CVE-2026-85102.
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • WordPress
  • WordPress

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Statistics

  • 3 Posts
  • 3 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Service notice: all hosted/maintained WP websites have been updated to the latest minor version of your current major branch (security release, CVE-2026-87902). No action needed from you!

I don't host or maintain your website? Be sure to update your WordPress ASAP. This one is critical.

Release notes → wordpress.org/news/2026/09/wor

#WordPress #Security #Critical #Cyberia

  • 1
  • 1
  • 0
  • 5h ago
Profile picture fallback

WordPress 7.1.2 patches a critical WordPress RCE vulnerability (CVE-2026-87902). Update your site to prevent conditional remote code execution.

securityonline.info/wordpress-

  • 1
  • 0
  • 0
  • 5h ago

Bluesky

Profile picture fallback
WordPress patched CVE-2026-87902, a critical core flaw in versions 4.7.0-7.1.1 that could let unauthenticated attackers load a PHP file and, on some servers, trigger code execution. #WordPress #CVE202687902 #PatchUpdate
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts
  • 6 Interactions

Last activity: 7 hours ago

Fediverse

Bluesky

Profile picture fallback
[RSS] CVE-2026-78902: XSS to RCE in pfSense with one DNS request www.netspi.com -> Original->
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

11 Aug 2026
Published
16 Sep 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.81%

KEV

Description

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 7 hours ago

Fediverse

Profile picture fallback

Microsoft Called CVE-2026-65660 a Spoofing Bug. It’s an Authenticated SharePoint RCE

CVE-2026-65660 is an authenticated SharePoint RCE, not just spoofing. Learn about the ToolPane flaw, XAML exploit chain, affected versions, and fixes

thecybersecguru.com/news/cve-2

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
CVE-2026-65660 in SharePoint Server enables authenticated remote code execution via unescaped quotes in SafeControls-related directive reconstruction.
  • 1
  • 0
  • 0
  • 8h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
7.94%

KEV

Description

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 9 hours ago

Bluesky

Profile picture fallback
vCenter pre-auth RCE: CVE-2026-59309/59310
  • 0
  • 0
  • 1
  • 13h ago
Profile picture fallback
Woops: * https://mobeta.fr/blog/vcenter-cve-2026-59309-cve-2026-59310/ #threatintel, #vmware
  • 1
  • 0
  • 0
  • 11h ago
Showing 1 to 10 of 75 CVEs