24h | 7d | 30d

Overview

  • Gitea
  • Gitea

26 Aug 2026
Published
26 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

Description

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Statistics

  • 8 Posts
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

📰 CISA Warns of Actively Exploited Gitea RCE Flaw (CVE-2026-60004)

🚨 CISA KEV ALERT: A critical RCE flaw in Gitea (CVE-2026-60004, CVSS 9.8) is actively exploited. Attackers can gain RCE on self-hosted Git servers. Patch to version 1.27.1 or later NOW. #Gitea #RCE #CISA #KEV #CVE202660004

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

⚠️ CRITICAL: Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Gitea instances are under active attack for CVE-2026-60004, a critical RCE flaw (CVSS 9.8) that allows unauthenticated account creation to trigger arbitrary command execution. Attackers are deploying miner-like payloads. Any organization running Gitea with default open registration is at immediate…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) 🔗 Read more: www.helpnetsecurity.com/2026/08/26/g... #exploit #opensource #cybersecurity
  • 0
  • 1
  • 0
  • 18h ago
Profile picture fallback
CVE-2026-60004 in Gitea enables remote code execution via diffpatch injection and is being exploited, prompting CISA to require rapid patching.
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
CVE-2026-60004 enables remote code execution in Gitea via diffpatch, letting attackers run arbitrary shell commands as the Gitea OS user.
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
CISA says CVE-2026-60004 is actively exploited in Gitea, letting authenticated users run shell commands via the diffpatch API. Open registration can expose default installs. #Gitea #CISA #CodeInjection
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
CISA is warning of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. CVE-2026-60004 is a remote code execution vulnerability that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the Gitea OS user.
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
Giteaの重大な脆弱性が実際に悪用される(CVE-2026-60004) Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) #HelpNetSecurity (Aug 26) www.helpnetsecurity.com/2026/08/26/g...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Veeam
  • One

26 Aug 2026
Published
26 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

Statistics

  • 6 Posts
  • 6 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

A critical Veeam ONE vulnerability (CVE-2026-65641, CVSS 9.3) lets an unauthenticated attacker coerce SMB authentication. Patch Veeam now.

securityonline.info/veeam-cve-

  • 2
  • 1
  • 0
  • 20h ago
Profile picture fallback

Kritische Veeam ONE-Schwachstelle CVE-2026-65641 (CVSS 9.3) - patchen

borncity.com/blog/2026/08/27/v

  • 1
  • 1
  • 1
  • 6h ago
Profile picture fallback
  • 1
  • 0
  • 1
  • 6h ago

Bluesky

Profile picture fallback
CVE-2026-65641 (CVSS 9.3): Veeam ONEの脆弱性により、認証されていない攻撃者がSMB認証を強制的に実行できる CVE-2026-65641 (CVSS 9.3): Veeam ONE Flaw Lets Unauthenticated Attacker Coerce SMB Authentication #DailyCyberSecurity (Aug 26) securityonline.info/veeam-cve-20...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Red Hat
  • Enterprise Linux 9
  • OpenSSH

01 Jul 2024
Published
14 Jul 2026
Updated

CVSS
Pending
EPSS
99.51%

KEV

Description

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

regreSSHion (CVE-2024-6387) shows ALESCo in action: we built the fix, then shared it upstream with CentOS Stream so the whole ecosystem benefits, not just us.

@benny and @neal explain. youtube.com/shorts/c8gw1pueHgg

  • 1
  • 2
  • 0
  • 7h ago

Bluesky

Profile picture fallback
regreSSHion (CVE-2024-6387) shows ALESCo in action: we built the fix, then shared it upstream with CentOS Stream so the whole ecosystem benefits, not just us. @bennyvasquez.bsky.social and @conan-kudo.bsky.social explain. www.youtube.com/shorts/c8gw1...
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • NetScaler
  • ADC

30 Jun 2026
Published
27 Aug 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
1.04%

Description

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

CISA adds six exploited vulnerabilities to its KEV Catalog, including a Citrix NetScaler flaw and CVE-2026-8452, with active exploitation confirmed.

securityonline.info/cisa-kev-s

  • 1
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
CISA urges immediate remediation of CVE-2026-8452 in Citrix NetScaler due to active exploitation, including unauthenticated remote code execution and web shell deployment.
  • 0
  • 1
  • 0
  • Last hour

Overview

  • Ubiquiti Inc
  • UniFi Protect Application

26 Aug 2026
Published
26 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
Pending

KEV

Description

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 12 hours ago

Fediverse

Profile picture fallback

Ubiquiti patched 22 UniFi flaws. Three hit CVSS 10.0, including command injection CVE-2026-77537. Update UniFi Protect, OS, and Talk now.

securityonline.info/unifi-comm

  • 1
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
Ubiquiti patches 3 max-severity flaws in UniFi Protect, UniFi OS, and UniFi Talk, fixing auth bypass and command injection risks plus 18 more critical issues across its product line. #Ubiquiti #UniFi #CVE202677537
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

11 Aug 2026
Published
26 Aug 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
2.93%

KEV

Description

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 5 hours ago

Bluesky

Profile picture fallback
CVE-2026-63520: SharePointのリモートコード実行(RCE)チェーンが実環境で調査され、概念実証(PoC)が公開されました CVE-2026-63520: SharePoint RCE Chain Probed in the Wild, PoC Public #DailyCyberSecurity (Aug 25) securityonline.info/sharepoint-c...
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Attackers are chaining CVE-2026-55040 and CVE-2026-63520 to hit unpatched Microsoft SharePoint servers with remote code execution. Public PoC exploits are available, and active probing has been seen. #SharePoint #CISA #Defused
  • 1
  • 1
  • 0
  • 11h ago
Profile picture fallback
Microsoft SharePointの脆弱性を狙う活動-CVE-2026-55040はKEV掲載、CVE-2026-63520の技術詳細も公開 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Zimbra
  • Collaboration

13 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
1.51%

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Statistics

  • 2 Posts

Last activity: 8 hours ago

Fediverse

Bluesky

Profile picture fallback
Unauthenticated attackers exploited CVE-2026-73570 in Zimbra SNMP monitoring to achieve remote code execution, compromising hundreds of internet-facing servers despite a patch.
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Microsoft
  • Microsoft Malware Protection Engine

16 Jun 2026
Published
25 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
11.36%

KEV

Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Statistics

  • 2 Posts

Last activity: 14 hours ago

Fediverse

Profile picture fallback

📰 New 'ShieldBreak' Exploit Bypasses Microsoft Defender Patch

A new zero-day exploit, 'ShieldBreak,' bypasses Microsoft's patch for the 'RoguePlanet' Defender flaw (CVE-2026-50656). The PoC allows SYSTEM-level access on patched Windows systems. No fix is currently available. #ZeroDay #MicrosoftDefender #CyberSe...

🔗 cyber.netsecops.io/articles/sh

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
🛡️ Mitigación y Gestión de la Vulnerabilidad "RoguePlanet" (CVE-2026-50656) en Microsoft Defender www.newstecnicas.com/2026/07/miti...
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Google
  • Chrome

25 Aug 2026
Published
27 Aug 2026
Updated

CVSS
Pending
EPSS
0.35%

KEV

Description

Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Statistics

  • 3 Posts

Last activity: 6 hours ago

Bluesky

Profile picture fallback
Chrome 152 patches 327 vulnerabilities, including 10 critical and 61 high-severity flaws. Google says 299 fixes were found internally, with researcher Goodluck earning $25,000 for CVE-2026-79282. #Chrome152 #Google #Goodluck
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
Google、Chromeの定例パッチを公開 327件のセキュリティ修正、Criticalは10件(CVE-2026-79282 他) rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 1
  • 6h ago

Overview

  • kubernetes
  • ingress-nginx

24 Mar 2025
Published
26 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
99.52%

KEV

Description

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Statistics

  • 1 Post
  • 6 Interactions

Last activity: 20 hours ago

Fediverse

Profile picture fallback

82% of container teams run Kubernetes in production (CNCF Annual Survey 2025). Most underestimate what happens after launch.

Cluster upgrades, observability tuning, secret management, and network policies never stop. IngressNightmare (CVE-2025-1974, CVSS 9.8) showed why: a full cluster takeover via delayed patches, affecting 40%+ of prod environments.

We broke down the four biggest Day-2 blind spots: nine.ch/en/blog/kubernetes-day

#kubernetes #devops #nine

  • 3
  • 3
  • 0
  • 20h ago
Showing 1 to 10 of 78 CVEs