24h | 7d | 30d

Overview

  • IBM
  • MQ Appliance

18 Sep 2026
Published
21 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.52%

KEV

Description

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

🚨 RAPID RESPONSE: IBM MQ Pre-Authentication RCE [CVE-2026-10747]

A critical heap buffer overflow in IBM MQ could allow remote code execution before authentication. CVSS: 10.0.

Censys ARC observes IBM MQ web consoles on 120 hosts and 149 web properties Internet-wide. These numbers indicate IBM MQ presence, not confirmed vulnerable systems.

IBM has released fixes for affected MQ Server and MQ Appliance versions. No public PoC or reported active exploitation is known at this time.

Read the full analysis for affected versions, Internet observations, and remediation guidance. censys.com/advisory/cve-2026-1

  • 1
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
🚨 CVE-2026-10747: A critical pre-auth RCE in IBM MQ carries a CVSS 10.0. Censys ARC observes IBM MQ consoles on 120 hosts Internet-wide. IBM has released fixes; no active exploitation is currently known. https://bit.ly/4jh5qWx
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Linux
  • Linux

25 Jun 2026
Published
19 Sep 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.28%

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 2 hours ago

Fediverse

Profile picture fallback

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53266 – Linux Kernel Out-of-Bounds Write Vulnerability

Analyze the executive impact of CVE-2026-53266 with our strategic Linux CSUITE brief, covering kernel out-of-bounds write risks, compliance assurance, and board-level risk communication....

thecybermind.co/n7ln

  • 0
  • 1
  • 0
  • 2h ago

Bluesky

Profile picture fallback
CISA added 3 exploited Linux kernel flaws to its KEV catalog: CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266. Risks include DoS, memory disclosure, crashes, and corruption. #LinuxKernel #CISA #CVEs
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Linux
  • Linux

13 Oct 2025
Published
19 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.79%

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

Statistics

  • 2 Posts

Last activity: 9 hours ago

Fediverse

Profile picture fallback

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2025-39964 – Linux Kernel Race Condition Vulnerability

Analyze the mechanics of CVE-2025-39964 with our technical Linux TSUITE brief, covering AF_ALG race conditions, CrowdStrike CQL queries, and endpoint hardening....

thecybermind.co/dxag

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
CISA added 3 exploited Linux kernel flaws to its KEV catalog: CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266. Risks include DoS, memory disclosure, crashes, and corruption. #LinuxKernel #CISA #CVEs
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Cisco
  • Cisco Secure Email

14 Sep 2026
Published
18 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.01%

Description

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Statistics

  • 1 Post
  • 8 Interactions

Last activity: 14 hours ago

Fediverse

Profile picture fallback

🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and…

Also tracked this week: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping · Check Point, Kaspersky, Tanium…

nexus8.8bitsecurity.com/entity

  • 2
  • 6
  • 0
  • 14h ago

Overview

  • Fortra
  • GoAnywhere MFT

18 Sep 2025
Published
04 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
99.80%

Description

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 6 hours ago

Bluesky

Profile picture fallback
Is This Bad? This Feels Bad. (GoAnywhere CVE-2025-10035) - watchTowr Labs
  • 0
  • 1
  • 0
  • 6h ago
Profile picture fallback
It Is Bad (Exploitation of Fortra GoAnywhere MFT CVE-2025-10035) - Part 2 - watchTowr Labs
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Microsoft
  • Azure AI Foundry

17 Sep 2026
Published
21 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.49%

KEV

Description

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 20 hours ago

Bluesky

Profile picture fallback
Microsoft、Azure・Copilotなど18件の脆弱性を修正 7件がCVSS 10.0、顧客側の更新作業は不要(CVE-2026-85889)他 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 1
  • 1
  • 20h ago

Overview

  • GNU
  • inetutils

13 Mar 2026
Published
23 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
23.67%

KEV

Description

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

Statistics

  • 1 Post

Last activity: 3 hours ago

Fediverse

Profile picture fallback

We preserved a 1994 Telnet bug for thirty years because industrial downtime costs money, only to discover clean exploitation is too tedious to bother weaponizing.
labs.watchtowr.com/a-32-year-o

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Ivanti
  • Endpoint Manager Mobile

13 May 2025
Published
26 Feb 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
86.52%

Description

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

Statistics

  • 2 Posts

Last activity: 6 hours ago

Fediverse

Profile picture fallback

🚨 In this week’s Threat Alert, we cover CVE-2025-4427, an authentication bypass in Ivanti Endpoint Manager Mobile (EPMM) that can be chained with CVE-2025-4428 for unauthenticated remote code execution. CrowdSec has observed 865 unique IP addresses sending requests matching the exploitation pattern since May 2025.

Read our latest article for the full analysis, protection recommendations, and more: crowdsec.net/vulntracking-repo

Keep your network informed. Like and share this post!

  • 0
  • 0
  • 0
  • 6h ago

Bluesky

Profile picture fallback
🚨 This week’s Threat Alert covers CVE-2025-4427, an Ivanti EPMM authentication bypass that can lead to unauthenticated RCE when chained with CVE-2025-4428. CrowdSec has observed 865 unique IPs matching the exploitation pattern since May 2025. Read more: www.crowdsec.net/vulntracking...
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Thinking Software Technology
  • EFence

14 Sep 2026
Published
14 Sep 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.34%

KEV

Description

EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

Statistics

  • 1 Post

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CVE-2026-89180: SQLi in Thinking Software EFence lets unauthenticated attackers read database contents. CVSS 7.5, no patch yet. Apply mitigations now. valtersit.com/cve/CVE-2026-891 #CVE #infosec #SQLi

  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Exim
  • Exim

19 Sep 2026
Published
19 Sep 2026
Updated

CVSS v3.1
HIGH (7.0)
EPSS
0.27%

KEV

Description

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

Statistics

  • 1 Post

Last activity: 20 hours ago

Fediverse

Profile picture fallback

Exim 4.100.1 patches a serious Exim vulnerability set: Proxy Protocol heap flaws, a GnuTLS use-after-free, and SMTP smuggling (CVE-2026-94054). Upgrade now.

securityonline.info/exim-4-100

  • 0
  • 0
  • 0
  • 20h ago
Showing 1 to 10 of 42 CVEs