24h | 7d | 30d

Overview

  • Palo Alto Networks
  • Cloud NGFW

13 May 2026
Published
14 Jul 2026
Updated

CVSS v4.0
HIGH (7.8)
EPSS
96.90%

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Statistics

  • 2 Posts

Last activity: 14 hours ago

Fediverse

Profile picture fallback

ReliaQuest reports active exploitation of CVE-2026-0257, an authentication-bypass flaw affecting Palo Alto Networks PAN-OS GlobalProtect and Prisma Access.

It says groups Qilin and Settra are using it to create unauthorized VPN connections and enter internal corporate networks; those connections may resemble routine remote work and delay detection.

Exposure is configuration-dependent: authentication override cooki…

en.hacks.gr/reliaquest-qilin-k

#PaloAltoNetworks #PANOS #GlobalProtect #PrismaAccess

  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback

Ransomware Actors Weaponize Palo Alto GlobalProtect Authentication Bypass for Stealthy VPN Access

Palo Alto GlobalProtect CVE-2026-0257 is being exploited by Qilin and Settra ransomware actors. Check affected PAN-OS versions, IOCs, and fixes

thecybersecguru.com/news/cve-2

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • WuKongOpenSource
  • Wukong_HRM

11 Oct 2026
Published
11 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.55%

KEV

Description

Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.

Statistics

  • 2 Posts

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CRITICAL: CVE-2026-108707 in WuKong_HRM (≤ commit 186115e) enables auth bypass — attackers can access all HRM APIs, gaining admin rights and exposing sensitive HR data. Restrict endpoints & monitor for unauthorized access. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

CVE-2026-108707 - Critical Auth Bypass in Wukong_HRM allows full API takeover & sensitive HR data theft. CVSS 9.8. Restrict API access immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-108

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • ceph
  • ceph

27 Aug 2026
Published
01 Sep 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
0.09%

KEV

Description

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that uses a hard-coded initialization vector and no message authentication, allowing an attacker to forge credentials and gain cluster-wide access. Because the ciphertext is malleable and the monitor will encrypt attacker-chosen entity names, an attacker holding one low-privilege key and able to observe CephX traffic can use the monitor as an encryption oracle and splice ciphertext blocks into valid tickets for privileged entities such as Manager, MDS, and OSD. The same lack of authentication also lets an attacker with CephX permissions escalate privileges by flipping a single bit in a service ticket to set its allow_all field to true. This issue is fixed in versions 20.2.4 and 19.2.6.

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

The issue now is: Ceph 20 is still on an older NFS Ganesha version which hasn't got the fix yet. Ceph 21 does have the fix, but it also has the fix for this CVE: medium.com/rook-io/rook-adviso

And this CVE fix, in turn, only works with kernels > 7.0. Which means I'm currently in a bit of a deadlock. I can't really update my hosts to the newer Ubuntu, because of the Ganesha bug. But I also can't update Ceph/Ganesha because I need a newer kernel.

#HomeLab

  • 1
  • 3
  • 0
  • 3h ago

Overview

  • Ollama
  • Ollama

08 Oct 2026
Published
08 Oct 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.71%

KEV

Description

Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by the `digestToPath` function. An unauthenticated remote attacker can specify a path traversal sequence as a layer digest, causing a malicious binary to be written outside the model store.  Critically if the server process has write access to `/usr/lib/ollama` (the default in most Ollama Docker images), an attacker can write the malicious file to that directory. On the next server restart, the file is loaded and executed, resulting in remote code execution as root. This issue was fixed in version 0.35.0.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 11 hours ago

Fediverse

Profile picture fallback

🚨 Critical Ollama Vulnerability: CVE-2026-103663

A critical security vulnerability has been disclosed in Ollama, the popular platform for running AI models locally and on private infrastructure.

The vulnerability allows unauthenticated attackers to exploit a path traversal weakness in the model-pull functionality, potentially writing malicious files outside the intended model directory.

#SecPoint #Ollama #AISecurity #CyberSecurity #VulnerabilityManagement

  • 1
  • 0
  • 0
  • 11h ago

Overview

  • OpenSSL
  • OpenSSL

01 Nov 2022
Published
14 Apr 2026
Updated

CVSS
Pending
EPSS
90.77%

KEV

Description

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address to overflow four attacker-controlled bytes on the stack. This buffer overflow could result in a crash (causing a denial of service) or potentially remote code execution. Many platforms implement stack overflow protections which would mitigate against the risk of remote code execution. The risk may be further mitigated based on stack layout for any given platform/compiler. Pre-announcements of CVE-2022-3602 described this issue as CRITICAL. Further analysis based on some of the mitigating factors described above have led this to be downgraded to HIGH. Users are still encouraged to upgrade to a new version as soon as possible. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. Fixed in OpenSSL 3.0.7 (Affected 3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6).

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

from my link log —

Why the OpenSSL punycode vulnerability was not detected by fuzz testing.

allsoftwaresucks.blogspot.com/

saved 2022-11-21 dotat.at/:/U3II7.html

  • 0
  • 2
  • 0
  • 6h ago

Overview

  • topoteretes
  • cognee

04 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
MEDIUM (5.3)
EPSS
0.34%

KEV

Description

A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

@wdormann ikr? Seems like VulDB has a template of sorts (its not exact, see e.g. the different phrasing in cve.org/CVERecord?id=CVE-2026- ) that expects a function name which.. just doesn't make sense most of the time? And the followup part of the template

The manipulation of the argument $argname results in $cwe-friendly-name.

just never makes sense for hardcoded credentials? I have said it before, I should become a CNA of my own, doesn't seem to be THAT hard...

  • 0
  • 1
  • 0
  • 4h ago

Overview

  • ThemeREX Group
  • IPharm
  • ipharm

10 Oct 2026
Published
11 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.33%

KEV

Description

Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.

Statistics

  • 1 Post

Last activity: 15 hours ago

Fediverse

Profile picture fallback

ThemeREX IPharm ipharm ≤1.2.4 hit by CRITICAL deserialization vuln (CVE-2026-93936, CVSS 9.8) 🛡️ Allows object injection & potential system compromise. No patch yet — restrict access, increase monitoring. radar.offseq.com/threat/deseri

  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Arista Networks
  • VeloCloud Orchestrator (VCO) On-Prem

22 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
1.06%

Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

Statistics

  • 1 Post

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-93952 Arista VeloCloud Orchestrator on-prem: remote attacker can reach privileged internal functionality, full CIA impact. CVSS 10. Patch under review; hosted already fixed. Patch now: valtersit.com/cve/CVE-2026-939 #CVE #infosec #Arista

  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Tautulli
  • Tautulli

21 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
MEDIUM (5.1)
EPSS
0.57%

KEV

Description

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter into a JavaScript string in data/interfaces/default/search.html using manual escaping that handles quotes and slashes but not backslashes. A backslash-quote sequence can terminate the string, so an unauthenticated attacker can send a crafted link that executes script in the Tautulli web context when an authenticated user follows it. This issue is fixed in version 2.17.2.

Statistics

  • 1 Post

Last activity: 20 hours ago

Fediverse

Profile picture fallback

CVE-2026-45381 Tautulli before 2.17.2: reflected XSS via /search backslash-quote bypass, CVSS 6.1. Unauthenticated crafted link runs script in an authed user's session. Patch still under review, so restrict exposure until 2.17.2 valtersit.com/cve/CVE-2026-453 #CVE #infosec #Tautulli

  • 0
  • 0
  • 0
  • 20h ago

Overview

  • Unknown
  • Veeqo for WooCommerce

11 Oct 2026
Published
11 Oct 2026
Updated

CVSS
Pending
EPSS
0.14%

KEV

Description

The Veeqo for WooCommerce WordPress plugin through 2.2.8 does not restrict who can trigger its remote bridge-installation process or validate the URL it is given before downloading and extracting it, allowing users with Subscriber-level access and above to make the Veeqo for WooCommerce WordPress plugin through 2.2.8 download and extract an attacker-controlled archive containing arbitrary PHP files into the WordPress root.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-93550 (HIGH): Veeqo for WooCommerce ≤2.2.8 lets Subscriber+ users upload arbitrary PHP files via insufficient URL validation, risking full site compromise. Restrict access & monitor plugin activity. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 10h ago
Showing 1 to 10 of 35 CVEs