24h | 7d | 30d

Overview

  • GitLab
  • GitLab

12 Sep 2026
Published
12 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
1.15%

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 9 hours ago

Fediverse

Profile picture fallback

๐Ÿ“ฐ GitLab Patches Critical CVSS 10.0 Path Traversal Vulnerability

GitLab releases emergency patches for a critical CVSS 10.0 path traversal flaw (CVE-2026-85706). Unauthenticated attackers can read arbitrary files. Active scanning detected. Upgrade self-managed instances NOW. #GitLab #CVE #CyberSecurity #PatchNow

๐Ÿ”— cyber.netsecops.io/articles/gi

  • 1
  • 0
  • 0
  • 9h ago
Profile picture fallback

๐Ÿšจ Detection for the actively exploited GitLab vulnerability tagged as CVE-2026-85706 (CVSS 10.0) available here:
github.com/projectdiscovery/nu

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
~Cisa~ CISA added actively exploited GitLab CE/EE path traversal CVE-2026-85706 to its KEV Catalog. - IOCs: CVE-2026-85706 - #CVE-2026-85706 #GitLab #ThreatIntel
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • checkpoint
  • Quantum Security Gateway

09 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.33%

KEV

Description

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Statistics

  • 4 Posts
  • 14 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

ncsc.nl/alerts/kritieke-kwetsb

Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en verwacht dat er snel pogingen tot misbruik zullen plaatsvinden, het advies is dan ook om de updates zo snel mogelijk te installeren.

Translated by LibreWolf:

There are 2 critical vulnerabilities in Check Point VPN products, with the characteristics CVE-2026-85102 and CVE-2026-85103. This concerns 2 serious vulnerabilities with a CVSS score of 9.8. The NCSC assesses the risk of abuse and possible damage as high and expects that attempts at abuse will take place quickly, so the advice is to install the updates as quickly as possible.

  • 3
  • 1
  • 0
  • 12h ago

Bluesky

Profile picture fallback
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
  • 3
  • 7
  • 0
  • 12h ago
Profile picture fallback
Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 #patchmanagement
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Dutch NCSC says exploitation of two critical Check Point VPN flaws is imminent. CVE-2026-85102 may enable code execution, while CVE-2026-85103 is a heap overflow risking full system control. #CheckPoint #NCSC #Netherlands
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • checkpoint
  • Quantum Security Gateway

09 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.36%

KEV

Description

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

Statistics

  • 3 Posts
  • 14 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

ncsc.nl/alerts/kritieke-kwetsb

Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en verwacht dat er snel pogingen tot misbruik zullen plaatsvinden, het advies is dan ook om de updates zo snel mogelijk te installeren.

Translated by LibreWolf:

There are 2 critical vulnerabilities in Check Point VPN products, with the characteristics CVE-2026-85102 and CVE-2026-85103. This concerns 2 serious vulnerabilities with a CVSS score of 9.8. The NCSC assesses the risk of abuse and possible damage as high and expects that attempts at abuse will take place quickly, so the advice is to install the updates as quickly as possible.

  • 3
  • 1
  • 0
  • 12h ago

Bluesky

Profile picture fallback
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
  • 3
  • 7
  • 0
  • 12h ago
Profile picture fallback
Dutch NCSC says exploitation of two critical Check Point VPN flaws is imminent. CVE-2026-85102 may enable code execution, while CVE-2026-85103 is a heap overflow risking full system control. #CheckPoint #NCSC #Netherlands
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • N-able
  • N-central

06 Sep 2026
Published
09 Sep 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.74%

Description

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Statistics

  • 3 Posts
  • 3 Interactions

Last activity: 7 hours ago

Bluesky

Profile picture fallback
Still 218 instances of N-able N-central seen unpatched to CVE-2026-86218 pre-auth RCE that is exploited in the wild & on US CISA KEV. Top: US (141) Stats - World Map view: dashboard.shadowserver.org/statistics/c... Tracker: dashboard.shadowserver.org/statistics/c...
  • 1
  • 2
  • 0
  • 7h ago
Profile picture fallback
IP data in Vulnerable HTTP reporting tagged 'cve-2026-86218': www.shadowserver.org/what-we-do/n... 218 out of 1399 seen in total. This is one week after exploitation activity was first reported publicly. Patch info: documentation.n-able.com/N-central/Re...
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
~Arcticwolf~ Active exploitation enables unauthenticated takeover of N-central servers; patch to 2026.3.1.14+. - IOCs: CVE-2026-86218, CVE-2026-86206, CVE-2026-86207 - #CVE202686218 #RCE #ThreatIntel
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

08 Sep 2026
Published
11 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.05%

KEV

Description

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback
  • 0
  • 3
  • 0
  • 5h ago

Bluesky

Profile picture fallback
~Arcticwolf~ Two actively exploited Windows zero-days require urgent patching. - IOCs: CVE-2026-85880, CVE-2026-81963, CVE-2026-69730 - #CVE-2026-81963 #CVE-2026-85880 #ThreatIntel
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • jfrog
  • artifactory

12 Aug 2026
Published
12 Sep 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.92%

Description

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Statistics

  • 3 Posts

Last activity: 13 hours ago

Fediverse

Profile picture fallback

CRITICAL CISA KEV ALERT: CVE-2026-42018 targets JFrog Artifactory via improper auth and token leakage. Active exploitation verified. Access our CSUITE Brief for technical execution vectors, asset integrity rules, and endpoint hardening steps to protect your enterprise perimeter. thecybermind.co/22sa

  • 0
  • 0
  • 1
  • 13h ago

Bluesky

Profile picture fallback
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 #appsec
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Linux
  • Linux

11 Sep 2026
Published
11 Sep 2026
Updated

CVSS
Pending
EPSS
0.16%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: net: mctp: hold a reference to the route device in mctp_route_lookup() mctp_route_lookup() uses rt->dev without holding a reference on it. mctp_route_lookup_single() returns the route under RCU only, so the route's device can be torn down concurrently: mctp_dev_put() drops the last reference and synchronously kfree()s mdev->addrs. mctp_dev_saddr() then reads rt->dev->addrs[0], giving a use-after-free reachable by an unprivileged local AF_MCTP user on the receive/forwarding path (no CAP_NET_RAW required): BUG: KASAN: slab-use-after-free in mctp_route_lookup Read of size 1 at addr ... by task mctp_uaf/... mctp_route_lookup mctp_pkttype_receive Freed by task ...: kfree mctp_dev_put mctp_dev_notify In the same window mctp_dst_from_route() -> mctp_dev_hold() also increments a refcount that has already reached zero ("refcount_t: addition on 0 ... mctp_dev_hold"). This reintroduces the use-after-free class of CVE-2023-3439: the source address lookup was moved ahead of the point where the destination takes its device reference. Take a reference with refcount_inc_not_zero() before touching rt->dev, skip a device that is already dead, and drop the reference once the destination has taken its own.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 22 hours ago

Fediverse

Profile picture fallback

CVE-2026-80995: HIGH severity use-after-free in Linux kernel MCTP code lets unprivileged users trigger memory corruption or DoS. Fix: update to patched kernel when released. Details: radar.offseq.com/threat/in-the

  • 2
  • 0
  • 0
  • 22h ago

Overview

  • Linux
  • Linux

11 Sep 2026
Published
11 Sep 2026
Updated

CVSS
Pending
EPSS
0.20%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() smc_llc_srv_add_link() keeps add_llc pointing into the queue entry: add_llc = &qentry->msg.add_link; smc_llc.c:1482 ... smc_llc_save_add_link_info(link_new, add_llc); smc_llc.c:1494 smc_llc_flow_qentry_del(&lgr->llc_flow_lcl); smc_llc.c:1495 ... u8 *llc_msg = smc_link_shared_v2_rxbuf(link) ? (u8 *)lgr->wr_rx_buf_v2 : (u8 *)add_llc; smc_llc.c:1504 smc_llc_save_add_link_rkeys(link, link_new, llc_msg); smc_llc.c:1506 smc_llc_flow_qentry_del() kfree()s the entry, so on a link without a shared v2 receive buffer the pointer handed to smc_llc_save_add_link_rkeys() is already freed. Before the Fixes: commit that branch always used lgr->wr_rx_buf_v2 and add_llc was not used after the free. Reproduced on an unpatched tree over rxe, with KASAN, kasan_multi_shot and a link forced to max_recv_sge == 1: the entry is freed and read by the same call, and the freeing frame is smc_llc_srv_add_link() itself. [ 2.523161] BUG: KASAN: slab-use-after-free in smc_llc_save_add_link_rkeys+0x333/0x350 [ 2.523499] Read of size 2 at addr ffff8880052194de by task kworker/0:1/11 [ 2.523789] [ 2.523862] CPU: 0 UID: 0 PID: 11 Comm: kworker/0:1 Not tainted 7.2.0-rc5-p0-g2c9dd296545d #35 PREEMPT(lazy) [ 2.523865] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 2.523866] Workqueue: smc_hs_wq smc_listen_work [ 2.523869] Call Trace: [ 2.523870] <TASK> [ 2.523871] dump_stack_lvl+0x53/0x70 [ 2.523872] print_report+0xd0/0x630 [ 2.523874] ? __pfx__raw_spin_lock_irqsave+0x10/0x10 [ 2.523876] ? smc_llc_save_add_link_rkeys+0x333/0x350 [ 2.523878] kasan_report+0xce/0x100 [ 2.523879] ? smc_llc_save_add_link_rkeys+0x333/0x350 [ 2.523881] smc_llc_save_add_link_rkeys+0x333/0x350 [ 2.523883] ? smcr_buf_reg_lgr+0x2a4/0x660 [ 2.523885] smc_llc_srv_add_link+0xaa2/0x1e50 [ 2.523888] ? _printk+0xba/0xf0 [ 2.523897] ? __pfx_smc_llc_srv_add_link+0x10/0x10 [ 2.523899] ? down_write+0xb0/0x130 [ 2.523903] ? __pfx_down_write+0x10/0x10 [ 2.523905] smc_listen_work+0x489e/0x4d00 [ 2.523907] ? kmem_cache_free+0x1c6/0x3a0 [ 2.523911] ? __pfx_smc_listen_work+0x10/0x10 [ 2.523913] ? release_sock+0x148/0x1d0 [ 2.523915] ? smc_tcp_listen_work+0xb4f/0xfc0 [ 2.523917] ? _raw_spin_lock_irq+0x80/0xe0 [ 2.523918] ? __pfx__raw_spin_lock_irq+0x10/0x10 [ 2.523920] process_one_work+0x633/0x1030 [ 2.523922] ? assign_work+0x11d/0x370 [ 2.523924] worker_thread+0x45b/0xd10 [ 2.523926] ? __pfx_worker_thread+0x10/0x10 [ 2.523928] ? __pfx_worker_thread+0x10/0x10 [ 2.523929] kthread+0x2c6/0x3b0 [ 2.523931] ? recalc_sigpending+0x15c/0x1e0 [ 2.523934] ? __pfx_kthread+0x10/0x10 [ 2.523935] ret_from_fork+0x36e/0x5a0 [ 2.523937] ? __pfx_ret_from_fork+0x10/0x10 [ 2.523938] ? __switch_to+0x572/0xdd0 [ 2.523943] ? __pfx_kthread+0x10/0x10 [ 2.523944] ret_from_fork_asm+0x1a/0x30 [ 2.523947] </TASK> [ 2.523948] [ 2.531253] Allocated by task 48: [ 2.531399] kasan_save_stack+0x33/0x60 [ 2.531570] kasan_save_track+0x14/0x30 [ 2.531737] __kasan_kmalloc+0x8f/0xa0 [ 2.531905] __kmalloc_cache_noprof+0x158/0x370 [ 2.532100] smc_llc_enqueue+0x72/0x560 [ 2.532268] smc_wr_rx_tasklet_fn+0x474/0xa80 [ 2.532491] tasklet_action_common+0x20f/0x8a0 [ 2.532714] handle_softirqs+0x18e/0x590 [ 2.532886] do_softirq+0x3b/0x60 [ 2.533036] __local_bh_enable_ip+0x61/0x70 [ 2.533221] __alloc_skb+0x732/0x890 [ 2.533384] rxe_init_packet+0x16b/0x4f0 [ 2.533567] prepare_ack_packet+0xb8/0x830 [ 2.533760] rxe_receiver+0x495/0x96e0 [ 2.533933] do_work+0x144/0x470 [ 2 ---truncated---

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 20 hours ago

Fediverse

Profile picture fallback

CVE-2026-80981: Linux kernel net/smc HIGH severity use-after-free in smc_llc_srv_add_link(). Risk of memory corruption & escalation. Patch when available! Details: radar.offseq.com/threat/in-the

  • 1
  • 1
  • 0
  • 20h ago

Overview

  • Pending

04 Sep 2026
Published
04 Sep 2026
Updated

CVSS
Pending
EPSS
0.26%

KEV

Description

Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

CVE-2026-78849 - XSS in Netgate pfSense (Plus <=26.03 & CE <=2.8.1). Remote code execution via captive_portal_status.widget.php. Unpatched. CVSS N/A. Isolate exposed firewalls & monitor logs. Details: valtersit.com/cve/CVE-2026-788 #CVE #pfSense #infosec

  • 1
  • 1
  • 0
  • 11h ago

Overview

  • irontec
  • sngrep

12 Sep 2026
Published
12 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CVE-2026-90558: CRITICAL stack buffer overflow in irontec sngrep (<=1.8.4). Malicious SIP headers can crash or allow code execution. Patch status pending โ€” filter untrusted SIP traffic. radar.offseq.com/threat/cve-20

  • 0
  • 1
  • 0
  • 1h ago
Showing 1 to 10 of 52 CVEs