24h | 7d | 30d

Overview

  • Cisco
  • Cisco Secure Email

14 Sep 2026
Published
15 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.01%

Description

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Statistics

  • 10 Posts
  • 1 Interaction

Last activity: 2 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways

Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabili…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 1
  • 16h ago
Profile picture fallback

A critical Cisco Secure Email Gateway vulnerability allows unauthenticated attackers to gain root access via a single email. Learn about CVE-2026-76461.

meterpreter.org/cisco-secure-e

  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

Global cybersecurity agencies, including CISA & NSA, issued guidance to mitigate 17 Active Directory compromise techniques (Sept 16). Cisco patched an actively exploited email gateway zero-day (CVE-2026-76461). Geopolitically, the US confirmed deploying space weapons, drawing warnings from China about an arms race (Sept 15). AI is now the leading driver for new cybersecurity spending.

#Cybersecurity #Geopolitics #TechNews

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution esecurityplanet.com/threats/ne

  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback

Recent developments include Cisco patching a critical zero-day (CVE-2026-76461) in its Secure Email Gateway, which was actively exploited for root command execution. Geopolitically, China warned against weaponizing space after the US confirmed orbital weapon deployments. In technology, debates continue on AI safety versus national competitive advantage, with US Speaker Johnson rejecting development pauses.

#Cybersecurity #Geopolitics #AnonNews_irc

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) - Help Net Security www.helpnetsecurity.com/2026/09/15/c...
  • 0
  • 1
  • 0
  • 6h ago
Profile picture fallback
CVE-2026-76461 in Cisco Secure Email Gateway enables unauthenticated remote attackers to execute arbitrary commands as root; patch immediately and check logs for SQL probes.
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Cisco Secure Email GatewayにおけるSQLインジェクションの脆弱性(CVE-2026-76461)に関する注意喚起 #JPCERTCC (Sep 15) www.jpcert.or.jp/at/2026/at26...
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-76461) Cisco Secure Email Gateway Root RCE via Email Parsing". #cybersecurity #AttackSurfaceManagement #EASM https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Google
  • Android

15 Sep 2026
Published
16 Sep 2026
Updated

CVSS
Pending
EPSS
0.11%

Description

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Statistics

  • 10 Posts
  • 8 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

@skyblitz CVE-2026-58704 is a modem firmware vulnerability with a patch released today and it will be included in our upcoming release.

  • 0
  • 6
  • 0
  • 6h ago
Profile picture fallback

A Google Pixel vulnerability exploited in targeted attacks allows privilege escalation. Update your device to patch this Google Pixel vulnerability now.

securityonline.info/google-pix

  • 0
  • 1
  • 0
  • 14h ago
Profile picture fallback

If you've got a Google Pixel cell phone, do a system patch immediately. There is an active vulnerability that allows the hacker to take control of your device with no user interaction. It is being actively used in the wild.

cve.org/CVERecord?id=CVE-2026-

  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback

📰 Google Patches Actively Exploited Zero-Day Flaw in Pixel Modems

Google patches high-severity zero-day (CVE-2026-58704) in Pixel modems. The flaw allows for remote privilege escalation and is under limited, targeted exploitation. CISA added to KEV. Update your Pixel now! #Pixel #Android #ZeroDay

🔗 cyber.netsecops.io/articles/go

  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback

@GrapheneOS funny to see google fixing : CVE-2025-48595 that was fixed looooooong ago in your.

i don't see CVE-2026-58704, is it already fixed ?

bleepingcomputer.com/news/secu

  • 1
  • 0
  • 0
  • 6h ago

Bluesky

Profile picture fallback
CVE-2026-58704 in Pixel Cellular Modem enables privilege escalation via permission bypass, with limited targeted exploitation indicated and no user interaction required.
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
Google patched a high-severity Pixel modem zero-day (CVE-2026-58704) with limited targeted exploitation, enabling remote privilege escalation without user interaction.
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
Pixel, Google chiude una falla zero-day nel modem già sfruttata in attacchi Google corregge sui Pixel CVE-2026-58704, falla nel modem cellulare già associata ad attacchi mirati. La pat... https://www.ilsoftware.it/google-pixel-zero-day-modem-attacchi/
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
A Pixel modem software bug (CVE-2026-58704) enabled zero-click privilege escalation in targeted attacks and has been patched by Google.
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
~Cisa~ CISA added CVE-2026-58704 to its KEV Catalog after evidence of active exploitation. - IOCs: CVE-2026-58704 - #CVE-2026-58704 #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • GitLab
  • GitLab

12 Sep 2026
Published
12 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
11.96%

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Statistics

  • 4 Posts
  • 6 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

GitLab CVE-2026-85706: unauth arbitrary file read, exploited in the wild, now on CISA KEV. Patch
19.3.2 / 19.2.6 / 19.1.8.
The 10.0 is about the read. The damage is the credentials inside the files, and a commits API
reads history, so secrets you deleted are still there.
Patch, hunt, THEN rotate. Rotating on a readable server hands over the new keys.
blog.relayshield.net/a-file-read-bug-is-a-credential-theft-bug

  • 1
  • 1
  • 0
  • Last hour
Profile picture fallback

Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.

meterpreter.org/gitlab-cve-202

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

Actionable C-Suite threat intelligence for CVE-2026-85706, covering active path traversal exploitation vectors, endpoint hardening, and patch automation across GitLab environments. thecybermind.co/uzke

  • 0
  • 0
  • 0
  • 13h ago

Bluesky

Profile picture fallback
Dropped some research and detection/hunt content on CVE-2026-85706 🤓
  • 0
  • 4
  • 0
  • 16h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 3 Posts

Last activity: 9 hours ago

Bluesky

Profile picture fallback
Acronis Warns of Actively Exploited Linux Privilege Escalation Flaw Acronis has warned of CVE-2026-87886, a high-severity Linux privilege escalation vulnerability affecting its cPanel, WHM, and Plesk backup integrations.
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
Acronis disclosed CVE-2026-87886 in its cPanel, WHM, and Plesk backup plugins: a Linux local privilege escalation flaw (CVSS 7.8) already used in limited targeted attacks. #Acronis #cPanel #Plesk
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886) 📖 Read more: www.helpnetsecurity.com/2026/09/16/a... #backup #Linux #MSP #plugin #securityupdate #vulnerability #webhosting #cybersecurity #cybersecuritynews
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • mySCADA Technologies
  • mySCADA myPRO

15 Sep 2026
Published
15 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.65%

KEV

Description

The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.

Statistics

  • 3 Posts

Last activity: 16 hours ago

Fediverse

Profile picture fallback

CVE-2026-73807 | CRITICAL: mySCADA myPRO (v0 – 2.1) API flaw allows unauthenticated access to privileged functions. No patch yet — restrict API network access & monitor logs. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

Discover the latest mySCADA myPRO Manager vulnerabilities, including CVE-2026-73807, and learn how to patch your systems to prevent remote attacks.

securityonline.info/myscada-my

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
~Cisa~ Unauthenticated flaws enable privileged access and arbitrary SMS; update to 2.2. - IOCs: CVE-2026-73807, CVE-2026-82567 - #CVE-2026-73807 #CVE-2026-82567 #ThreatIntel
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts
  • 4 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Patch your Cisco ISE. CVE-2026-76460 a perfect 10 and is EITW. 🥳

sec.cloudapps.cisco.com/securi

The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.

  • 4
  • 0
  • 0
  • 1h ago
Profile picture fallback

An exploited Cisco ISE vulnerability (CVE-2026-76460) allows remote root access. Patch this critical Cisco ISE vulnerability to secure networks.

securityonline.info/cisco-ise-

  • 0
  • 0
  • 0
  • 1h ago

Overview

  • WSO2
  • WSO2 Universal Gateway

06 Aug 2026
Published
06 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.32%

KEV

Description

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 2 hours ago

Fediverse

Profile picture fallback

📰 Critical WSO2 API Flaw Under Active Attack, Exposes Enterprise Data

Critical auth bypass (CVE-2026-5430, CVSS 10.0) in WSO2 API Manager is now actively exploited. Attackers can take over admin accounts. Patched in April 2026, ensure your systems are updated! #WSO2 #APISecurity #CyberAttack

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
CVE-2026-5430 in WSO2 middleware is being exploited to bypass JWT authentication, enabling account takeover and access to API backends and credentials.
  • 1
  • 0
  • 0
  • 10h ago

Overview

  • jetmonsters
  • JetFormBuilder — Dynamic Blocks Form Builder

16 Sep 2026
Published
16 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.39%

KEV

Description

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for unauthenticated attackers to create a new administrator-level user account.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

CVE-2026-12793: CRITICAL privilege escalation in JetFormBuilder Dynamic Blocks Form Builder (<=3.6.2). Unauthenticated attackers can create admin accounts. Restrict access & monitor until patch. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

📰 Critical WordPress Plugin Flaw Allows Unauthenticated Admin Creation

Critical unauthenticated admin creation flaw (CVE-2026-12793, CVSS 9.8) found in JetFormBuilder WordPress plugin (<= 3.6.2). Public exploit available. Update or disable immediately to prevent site takeover! #WordPress #Vulnerability

🔗 cyber.netsecops.io/articles/wo

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • ConnectWise
  • ScreenConnect

08 Sep 2026
Published
12 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.69%

Description

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

Statistics

  • 2 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-84869 – ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

C-Suite threat intelligence and mitigation protocols for CVE-2026-84869, addressing active exploitation vectors within enterprise ConnectWise environments....

thecybermind.co/pxxw

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
CISA says CVE-2026-84869 is being actively exploited in ConnectWise ScreenConnect, enabling file transfer or execution. Over 1,000 exposed instances remain unpatched. #ScreenConnect #CISA #ConnectWise
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Issabel Foundation
  • Issabel Framework

15 Sep 2026
Published
15 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.52%

KEV

Description

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

An Issabel PBX vulnerability exploited in active attacks allows remote code execution. Patch this Issabel PBX vulnerability to secure systems.

securityonline.info/issabel-pb

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
CVE-2026-89026 enables unauthenticated remote command execution in Issabel Framework via a hard-coded JWT signing key.
  • 0
  • 0
  • 0
  • 2h ago
Showing 1 to 10 of 105 CVEs