24h | 7d | 30d

Overview

  • Red Hat
  • Red Hat build of Keycloak 26.4
  • rhbk/keycloak-operator-bundle

18 Aug 2026
Published
20 Aug 2026
Updated

CVSS
Pending
EPSS
0.52%

KEV

Description

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

Statistics

  • 6 Posts
  • 14 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Note the recently disclosed CVE-2026-18963 for #Keycloak OIDC: thehackernews.com/2026/08/crit . It allows unauthorized users to take over any account on your server.
On the #Slackware #Forgejo instance forge.slackware.nl/ I have upgraded Keycloak to 26.7.2 to address this vulnerability.

  • 5
  • 5
  • 0
  • 9h ago
Profile picture fallback

Geopolitical tensions rise as US-Iran dispute over Strait of Hormuz escalates; UK pledges long-range missile tech to Ukraine. Nvidia increases AI server prices over 15% due to memory costs. Critical Keycloak flaw (CVE-2026-18963) found allowing account takeovers, while Apple warns of mercenary spyware.

#AnonNews_irc #Cybersecurity #News

  • 1
  • 0
  • 0
  • 12h ago
Profile picture fallback

⚠️ Critical Keycloak flaw enables account takeover

CVE-2026-18963 lets unauthenticated attackers reset any user's password, bypassing email verification.

🔗 read more: thehackernews.com/2026/08/crit

#ransomNews #cyberthreats #Keycloak

  • 1
  • 0
  • 0
  • 11h ago
Profile picture fallback

📰 Critical Keycloak Flaw (CVE-2026-18963) Allows Account Takeover

🚨 CRITICAL FLAW: Keycloak is vulnerable to CVE-2026-18963 (CVSS 9.1), allowing unauthenticated remote attackers to take over any account. Patches are available—update immediately! #Keycloak #Cybersecurity #Vulnerability #CVE #IAM

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 1
  • 0
  • 14h ago
Profile picture fallback

⚠️ CRITICAL: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Critical flaw in Keycloak (CVE-2026-18963, CVSS 9.1) allows unauthenticated attackers to reset any user password and take over accounts due to improper state validation in the password recovery flow. Any organization running Keycloak without patches is immediately at risk of account takeover on all…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.
  • 0
  • 1
  • 0
  • 14h ago

Overview

  • Zimbra
  • Collaboration

13 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
1.51%

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Statistics

  • 5 Posts
  • 11 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: CISA orders urgent patching of actively exploited Zimbra flaw

Zimbra Collaboration Suite (ZCS) has a critical unauthenticated RCE vulnerability (CVE-2026-73570) that is actively exploited in the wild. Any organization running ZCS is at immediate risk of full system compromise. CISA has mandated U.S. government agencies patch within three days.

threatnoir.com/focus

🤖 AI generated summary

  • 1
  • 0
  • 0
  • 11h ago
Profile picture fallback

CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: radar.offseq.com/threat/cisa-o

  • 0
  • 0
  • 0
  • 17h ago

Bluesky

Profile picture fallback
Alert! Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22. Top: US (41 IPs). Detection in collaboration with @CERT_Polska_en Public Dashboard: dashboard.shadowserver.org/statistics/c...
  • 1
  • 6
  • 0
  • 18h ago
Profile picture fallback
We also see at least 8200 CVE-2026-73570 unpatched instances (this does not mean exploitable as the vuln is in a non default config) dashboard.shadowserver.org/statistics/c... Check for compromise & update: wiki.zimbra.com/wiki/Zimbra_... CVE-2026-73570 is on CISA KEV www.cisa.gov/known-exploi...
  • 0
  • 2
  • 0
  • 18h ago
Profile picture fallback
Data in Compromised Website reporting tagged 'zimbra-compromised' with detail set to 'Artifact from probable CVE-2026-73570 compromise' www.shadowserver.org/what-we-do/n... Compromised Zimbra tracker: dashboard.shadowserver.org/statistics/c...
  • 0
  • 1
  • 0
  • 18h ago

Overview

  • Oracle Corporation
  • Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in

20 Jan 2026
Published
25 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
43.23%

Description

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: Last hour

Fediverse

Profile picture fallback

CISA warned that the CVE-2026-21962 Oracle flaw with a CVSS 10 score is actively exploited in the wild. Patch Oracle Fusion Middleware systems now.

securityonline.info/cve-2026-2

  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback

Here's a summary of recent geopolitical, technology, and cybersecurity news:

Geopolitical: The US has launched "Operation Economic Outcast" against Iran (Aug 25) and plans 7.5% tariffs on Chinese goods over excess manufacturing capacity before a September summit (Aug 25).

Technology: Google is reorganizing DeepMind and acquired Spirit Airlines' data for AI model development (Aug 24). Fujitsu is trialing AI for construction process and risk management (Aug 25).

Cybersecurity: CISA added an Oracle HTTP Server vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities Catalog (Aug 24). Critical GitLab (CVE-2026-19478) and Cisco vulnerabilities (CVSS 10.0) are under active exploitation (Aug 24).

#AnonNews_irc #Cybersecurity #News

  • 1
  • 0
  • 0
  • Last hour

Overview

  • Zscaler
  • Client Connector

24 Aug 2026
Published
25 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
Pending

KEV

Description

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

Statistics

  • 1 Post
  • 6 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

nvd.nist.gov/vuln/detail/CVE-2

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

  • 2
  • 4
  • 0
  • 11h ago

Overview

  • PostgreSQL

13 Aug 2026
Published
14 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.53%

KEV

Description

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 16 hours ago

Fediverse

Profile picture fallback

A PostgreSQL vulnerability (CVE-2026-14669, CVSS 8.8) with public PoC exploit code allows remote code execution via to_char. Update now.

securityonline.info/postgresql

  • 2
  • 0
  • 0
  • 16h ago

Overview

  • nltk
  • nltk

22 Aug 2026
Published
24 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.49%

KEV

Description

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 17 hours ago

Fediverse

Profile picture fallback

CVE-2026-63312 - Arbitrary local file read in NLTK StreamBackedCorpusView bypasses pathsec. CVSS 7.5. Exposes sensitive system files. Update to NLTK 3.10.0+. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-633

  • 1
  • 1
  • 0
  • 17h ago

Overview

  • nltk
  • nltk

22 Aug 2026
Published
24 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.11%

KEV

Description

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 18 hours ago

Fediverse

Profile picture fallback

CVE-2026-63310 - MITM package injection flaw in NLTK downloader module. CVSS 7.1. Update NLTK to 3.9.3+ immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-633

  • 1
  • 1
  • 0
  • 18h ago

Overview

  • phoca.cz
  • Phoca Cart extension for Joomla

20 Aug 2026
Published
21 Aug 2026
Updated

CVSS v4.0
MEDIUM (5.3)
EPSS
0.32%

KEV

Description

Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart

GitHub: github.com/toanln-cov/CVE-2026

A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≤ 6.1.7 for Joomla.

The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.

The PoC demonstrates:

• Reflected XSS through crafted GET parameters
• Exploitation of vulnerable price filter inputs
• Attribute-context injection caused by missing htmlspecialchars() encoding
• No authentication requirement for exploitation
• Affected versions: PhocaCart ≤ 6.1.7
• Fixed version: PhocaCart 6.1.8

💥 No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.

  • 1
  • 1
  • 0
  • 10h ago

Overview

  • wedevs
  • Dokan Pro

25 Jun 2026
Published
29 Jun 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.46%

KEV

Description

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

دليل شامل لثغرة SQL Injection في إضافة Dokan Pro

ثغرة حقن SQL في إضافة Dokan Pro (CVE-2026-12077)1. الملخص التنفيذي ثغرة من نوع SQL Injection تعتمد على التأخير الزمني (Time-Based Blind SQL Injection) تم اكتشافها في إضافة Dokan Pro لأنظمة ووردبريس، والتي تُستخدم لإنشاء متاجر متعددة البائعين (Multi-Vendor Marketplaces). تؤثر على جميع الإصدارات حتى 5.0.4، وتسمح لمهاجم غير […]

cybercases8.wordpress.com/2026

  • 1
  • 0
  • 0
  • 4h ago

Overview

  • PixelYourSite Professional
  • Boost
  • boost

24 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
HIGH (7.1)
EPSS
Pending

KEV

Description

Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-32556 - Unauthenticated XSS in Boost <= 2.0.4. CVSS 7.1. Currently unpatched. Audit systems and mitigate risk immediately. #CVE #XSS #infosec

valtersit.com/cve/CVE-2026-325

  • 1
  • 0
  • 0
  • 4h ago
Showing 1 to 10 of 49 CVEs