24h | 7d | 30d

Overview

  • Microsoft
  • Copilot Web

18 Aug 2026
Published
19 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
1.63%

KEV

Description

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Statistics

  • 5 Posts
  • 11 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Von wegen KI: MS Copilot ist strunzdumm

Das Sicherheitsunternehmen Varonis hat eine Sicherheitslücke in Microsoft (MS) Copilot gefunden. Die hat inzwischen auch einen Namen bekommen und eine CVE-Nummer: CVE-2026-24301 oder CoSnitch. Sie ist mit 8,8 von 10 als kritisch eingestuft. Anscheinend gibt es noch keinen Flicken dagegen. Wer diese Lücke ausnutzt, kann Copilot von Ferne heimlich (ohne Interaktion des Opfers) dazu veranlassen, sensible geheime Daten zu senden. Zwar hat Copilot Schutzvorkehrungen gegen solchen Missbrauch, aber die sind unvollständig. Der Trick der Forscher/innen bestand darin, Copilot sich selbst hacken zu lassen! Immer wenn die KI einen ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#cybercrime #datenleck #KI #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump

  • 4
  • 7
  • 0
  • 20h ago
Profile picture fallback

Researchers got Microsoft Copilot to explain its own security bypass just by asking it the right follow-up questions

Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301), a critical flaw in Microsoft Copilot Personal made of three chained weaknesses that let an attacker exfiltrate data from a victim's connected accounts, Gmail, Google Drive,…

itnerd.blog/2026/08/19/researc

  • 0
  • 0
  • 1
  • 16h ago

Bluesky

Profile picture fallback
Microsoft Copilot Personalに脆弱性、連携アプリからワンクリックでデータを流出させる恐れ(CVE-2026-24301) | Codebook|Security News https://www.yayafa.com/2868613/ Microsoft Copilot …
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Elementor
  • Elementor Pro

19 Aug 2026
Published
19 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
Pending

KEV

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Statistics

  • 3 Posts
  • 8 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

WordPress admins running Elementor Pro:

CVSS 9.8 - CVE-2026-32475

WordPress Elementor Pro Plugin <= 4.2.1 is vulnerable to a high priority Arbitrary File Upload

patchstack.com/articles/critic

#wordpresss

  • 7
  • 1
  • 0
  • 16h ago

Bluesky

Profile picture fallback
CVE-2026-32475 in Elementor Pro Forms File Upload enables unauthenticated remote code execution by bypassing extension checks and writing a PHP file to a public directory.
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
Critical flaw in Elementor Pro, CVE-2026-32475, lets unauthenticated attackers upload PHP via the Forms module and run code on WordPress sites up to 4.2.1. #ElementorPro #WordPress #CVE202632475
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

14 Apr 2026
Published
19 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
77.90%

Description

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Statistics

  • 3 Posts
  • 4 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-33824: CRITICAL RCE in Windows IKE Extension is being actively exploited. All supported Windows 10, 11 & Server are impacted. Patch immediately or block UDP 500/4500 if IKE not used. More at radar.offseq.com/threat/critic

  • 0
  • 0
  • 0
  • 23h ago

Bluesky

Profile picture fallback
Critical RCE in Windows IKE Extension (CVE-2026-33824) is being actively exploited, affecting Windows 10, 11, and Server. Microsoft issued a patch, with temporary UDP 500/4500 restrictions noted. #CVE202633824 #Windows11 #Microsoft
  • 2
  • 2
  • 0
  • 18h ago
Profile picture fallback
Windows IKEにおけるRCE脆弱性が悪用される(CVE-2026-33824) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47275/
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • PTC
  • Windchill PDMLink

18 Jun 2026
Published
01 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
30.20%

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Statistics

  • 3 Posts

Last activity: 21 hours ago

Fediverse

Profile picture fallback

PTC Windchill/FlexPLM (CVE-2026-12569) exploited by Cl0p ransomware: CRITICAL severity, remote code execution, 40+ orgs hit. Patch ASAP to block active data theft & extortion. Full details: radar.offseq.com/threat/cl0p-r

  • 0
  • 0
  • 0
  • 22h ago

Bluesky

Profile picture fallback
Cl0p exploited CVE-2026-12569 in Windchill and FlexPLM to gain unauthenticated remote code execution, deploy web shells, and steal data from 40+ organizations.
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Cl0p has named 40+ alleged victims in a PTC Windchill and FlexPLM campaign tied to CVE-2026-12569, using web shells and a custom implant to steal databases, engineering files, and backups. #Cl0p #PTC #Windchill
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Red Hat
  • Red Hat build of Keycloak 26.4
  • rhbk/keycloak-operator-bundle

18 Aug 2026
Published
20 Aug 2026
Updated

CVSS
Pending
EPSS
0.39%

KEV

Description

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

Statistics

  • 2 Posts
  • 13 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

PSA: Critical unauthenticated account takeover vulnerability in - allows resetting arbitrary users‘ passwords. Update to 26.7.2 immediately or disable password reset. Tracked as CVE-2026-18963. github.com/keycloak/keycloak/i

  • 8
  • 4
  • 0
  • 17h ago
Profile picture fallback

Guten Morgen an @univention Kund*innen, die unsere #Keycloak App einsetzen! Wir werden demnächst Version 26.7.2 herausbringen. Von dem Account-Takeover-CVE ist unsere App nicht betroffen.

Details findet Ihr hier: help.univention.com/t/keycloak

  • 0
  • 1
  • 0
  • 3h ago

Overview

  • NetScaler
  • ADC

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Statistics

  • 3 Posts
  • 3 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback

CVE-2026-19490 (CVSS 9.3) is a critical NetScaler authentication bypass in NetScaler Gateway and ADC. Patch now to block unauthenticated access.

securityonline.info/netscaler-

  • 1
  • 0
  • 0
  • 19h ago
Profile picture fallback
  • 1
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 #CRITICAL support.citrix.com/support-home...
  • 1
  • 0
  • 0
  • 20h ago

Overview

  • GitLab
  • GitLab

17 Aug 2026
Published
17 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
0.72%

KEV

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Statistics

  • 3 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback
  • 0
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
CVE-2026-19478 enables unauthenticated remote code injection in GitLab, allowing deletion and modification of public projects; attackers began exploiting within two days.
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-60702) Oracle WebLogic Server Takeover via T3 and IIOP" and "Emerging Threat: (CVE-2026-19478) GitLab Unauthenticated Project Deletion via #GraphQL Directive". #cybersecurity #AttackSurfaceManagement https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Google
  • Android

01 Jun 2026
Published
03 Jun 2026
Updated

CVSS
Pending
EPSS
0.09%

KEV

Description

In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Statistics

  • 2 Posts
  • 4 Interactions

Last activity: 15 hours ago

Fediverse

Profile picture fallback

🚨 Public PoC available for high-severity Android ContactsProvider flaw

github.com/qm4rs/cve-2026-0075

CVE-2026-0075 affects Android 14, 15, 16, and 16 QPR2 and can allow access to information from the contacts database through a SQL-related side channel without user interaction.

Researcher QM4RS has now released a controlled Android PoC that intentionally requests neither READ_CONTACTS nor WRITE_CONTACTS.

The issue involves ContactsProvider2 returning detailed SQLite errors to callers that lack contacts permission. Those errors could potentially be abused as an information side channel.

Google's fix strips sensitive JSON-related SQLite exception details from unauthorized callers.

The researcher cautions that the PoC is build-specific and does not demonstrate a universal exploitation path across every Android device.

Devices with the June 5, 2026 Android security patch level or later address the issue.

  • 3
  • 1
  • 0
  • 15h ago
Profile picture fallback

A public PoC for CVE-2026-0075 shows an Android elevation of privilege in ContactsProvider2 that needs no user interaction.

securityonline.info/cve-2026-0

  • 0
  • 0
  • 0
  • 20h ago

Overview

  • Red Hat
  • Multicluster Global Hub
  • multicluster-globalhub/multicluster-globalhub-agent-rhel9

17 Aug 2026
Published
19 Aug 2026
Updated

CVSS
Pending
EPSS
0.30%

KEV

Description

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.

Statistics

  • 2 Posts

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Three critical Red Hat ACM/MCE flaws, led by CVE-2026-66792 (CVSS 9.9), allow full compromise of the managed cluster.

securityonline.info/red-hat-ac

  • 0
  • 0
  • 0
  • 20h ago

Bluesky

Profile picture fallback
CVE-2026-66792 (CVSS 9.9): Red Hat ACMの脆弱性により、管理対象クラスタが完全に侵害される可能性がある CVE-2026-66792 (CVSS 9.9): Red Hat ACM Flaw Allows Full Compromise of the Managed Cluster #DailyCyberSecurity (Aug 19) securityonline.info/red-hat-acm-...
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Splunk
  • Splunk MCP Server app

19 Aug 2026
Published
19 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
Pending

KEV

Description

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Splunk MCP Server app v1.2 is impacted by CVE-2026-76404 (CRITICAL, CVSS 9.1) — insecure deserialization lets admin users run arbitrary OS commands. Limit admin access & monitor for misuse until a patch is released. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

Splunk patches CVE-2026-76404, a critical remote code execution flaw in the MCP Server app, plus 16 more bugs across its apps and add-ons.

securityonline.info/splunk-app

  • 0
  • 0
  • 0
  • 4h ago
Showing 1 to 10 of 60 CVEs