24h | 7d | 30d

Overview

  • Microsoft
  • Microsoft Entra

20 Aug 2026
Published
22 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
1.37%

KEV

Description

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Statistics

  • 3 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

「マイクロソフトが警鐘を鳴らす、Entra IDの完全な欠陥が攻撃を受けている
/マイクロソフトはクラウドIDのバグは既に修正済みだと述べているが、誰がどの程度悪用したのかは明らかにしていない。 」: #TheRegister

「マイクロソフトは、攻撃者が既に悪用していたEntra IDの深刻度が最大レベルの脆弱性を修正した。

CVE-2026-69836として追跡されているこの脆弱性は、CVSSスコアが最高値の10.0であり、認証されていない攻撃者がMicrosoftのクラウドIDサービス上でリモートからコードを実行できる可能性がある。Microsoft は木曜日にこの脆弱性を公表し 、既に悪用が確認されているという残念なニュースも同時に発表した。

Entra ID(旧称Azure Active Directory)は、マイクロソフトのお客様向けIDおよびアクセス管理の中核を担い、クラウドアプリケーションやその他の企業リソースへの認証とアクセスを管理します。」

theregister.com/cyber-crime/20

#prattohome

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant's cloud-based identity and access management service. It was previously called Azure Active Directory or Azure AD. thehackernews.com/2026/08/micr...
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
Microsoft disclosed a critical remote code execution vulnerability in its Entra ID cloud identity service. Tracked as CVE-2026-69836, the flaw […]
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • mlflow
  • mlflow

17 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.3)
EPSS
8.15%

Description

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

Statistics

  • 2 Posts
  • 4 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.

Listen/Read: hackread.com/attackers-exploit

#CyberSecurity #MLflow #AI #Vulnerability #CISA

  • 1
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog. Listen/Read: hackread.com/attackers-ex... #CyberSecurity #MLflow #AI #Vulnerability #CISA
  • 1
  • 2
  • 0
  • 9h ago

Overview

  • Grafana
  • Grafana OSS

19 Aug 2026
Published
19 Aug 2026
Updated

CVSS v3.1
HIGH (7.1)
EPSS
0.34%

KEV

Description

An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.

Statistics

  • 3 Posts

Last activity: 6 hours ago

Bluesky

Profile picture fallback
grafana: 13.1.3 -> 13.1.4, fix CVE-2026-17183 https://github.com/NixOS/nixpkgs/pull/555114 #security
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
#555115 intel-compute-runtime: 26.27.39122.11 -> 26.31.39395.13 #555114 grafana: 13.1.3 -> 13.1.4, fix CVE-2026-17183
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
[26.05] grafana: 13.0.6 -> 13.0.7, fix CVE-2026-17183 https://github.com/NixOS/nixpkgs/pull/555366 #security
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • NetScaler
  • ADC

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.33%

KEV

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Statistics

  • 2 Posts

Last activity: 8 hours ago

Fediverse

Profile picture fallback

Citrix NetScaler (CVE-2026-19490) : cette faille critique permet de contourner l’authentification it-connect.fr/citrix-netscaler #ActuCybersécurité #Cybersécurité #Vulnérabilité

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
📢 [VULN] Citrix NetScaler (CVE-2026-19490) : cette faille permet de contourner l'authentification Le 19 août 2026, Citrix a publié un nouveau bulletin de sécurité pour NetScaler ADC et NetScaler Gateway. #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • TRENDnet
  • TEW-821DAP

22 Aug 2026
Published
22 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
Pending

KEV

Description

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument system.ntp.server/system.ntp.enable_server/cameo.time.time_zone/cameo.cameo.syslog_server can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-77946: Stack-based buffer overflow in TRENDnet TEW-821DAP v2.2.01b05 (CRITICAL, CVSS 10). Remote code execution possible via NTP config. No patch — limit exposure & monitor traffic. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

CVE-2026-77946 - Critical stack buffer overflow in TRENDnet TEW-821DAP NTP handler. Remote exploit public, unpatched. CVSS 10. Isolate/disable affected devices until patch. #CVE #TRENDnet #infosec

valtersit.com/cve/CVE-2026-779

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Cisco
  • Cisco IOS XE Software

16 Oct 2023
Published
21 Oct 2025
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
99.57%

Description

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 12 hours ago

Bluesky

Profile picture fallback
Interesting Git repos of the week: Detection: * https://github.com/thewhiteninja/ntfstool - parse NTFS for forensic artefacts Exploitation: * https://github.com/shaan3000/GhostGateway - attack MQTT and MODBUS * https://github.com/ZephrFish/CVE-2023-20198-Checker - @zephrfish's tool to hunt […]
  • 1
  • 0
  • 0
  • 12h ago

Overview

  • Zimbra
  • Collaboration

13 Aug 2026
Published
22 Aug 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
1.04%

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Geopolitical tensions rise as the US escalates economic pressure on Iran, which labels new sanctions as a "declaration of war". Ukraine faces critical missile shortages amid intensified Russian strikes. In technology, major investments continue in AI infrastructure, with Google backing Marvell's custom AI chips. Cybersecurity sees CISA adding a critical Zimbra vulnerability (CVE-2026-73570) to its KEV catalog and new banking Trojans actively exploited globally.

#AnonNews_irc #Cybersecurity #News

  • 1
  • 0
  • 0
  • 11h ago

Overview

  • Cisco
  • Cisco Secure Workload

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.41%

KEV

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.   The vulnerabilities tracked by CVE-2026-20231 are related to improper neutralization of special elements issues that are grouped under the Common Weakness Enumeration (CWE) CWE-74.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Fuck it, CVE dumpster diving.

CVE-2026-20231 - this is one of a batch of Cisco CVEs that stood out to me because they have multiple descriptions: One by the CNA, one by an ADP, "CVE" itself. The ADP one is just "please please please dont do this (bundling multiple vulns into a single cve) :neobot_angel_pleading: ". Cisco dont care, they put out 9 of those over the last 7 days.

  • 0
  • 3
  • 0
  • 1h ago

Overview

  • Metabase
  • Metabase

10 Aug 2026
Published
12 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
10.40%

Description

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

🚨🇫🇷 iMapper allegedly breached through critical Metabase vulnerability, account data and database access leaked on a cybercrime forum

A forum actor claims to have compromised iMapper, a French web-connected 2D laser measurement platform for building professionals, using a vulnerability identified in the listing as CVE-2026-72898 with a claimed CVSS score of 10.0.

The exposed account dataset reportedly contains 2,463 records and includes:

• User IDs and usernames
• Password hashes
• Account roles
• Email addresses
• Phone numbers
• Professions
• MFA status and related metadata
• Language preferences
• Stripe customer IDs
• Stripe tax-related identifiers
• Measurement and display configuration fields

The data is being distributed in XLSX format. The listing also claims the compromised environment contains additional database tables and offers credentials that could provide access to those systems.

The claims, exploitation method and authenticity, availability and scope of the allegedly exposed data and database access have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

  • 0
  • 1
  • 0
  • 3h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 2 hours ago

Fediverse

Profile picture fallback

‼️ CVE-2026-39113: Heap Buffer Overflow in SQLite's Optional SQLAR Extension

GitHub: github.com/20000419/CVE-2026-3

  • 0
  • 1
  • 0
  • 2h ago
Showing 1 to 10 of 41 CVEs