24h | 7d | 30d

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

14 Jul 2026
Published
23 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
21.04%

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Statistics

  • 6 Posts
  • 110 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

RE: infosec.exchange/@wdormann/116

This vuln (CVE-2026-50522) will see mass exploitation. It's out of the box unauth RCE in SharePoint, a mass exposed internet technology.

  • 45
  • 63
  • 0
  • 20h ago
Profile picture fallback

"Yet another SharePoint Server vulnerability was exploited in the wild, considered the fourth such Microsoft flaw attacked this month.

News of the new SharePoint flaw came after research groups WatchTowr and Defused observed active exploitation of the 9.8-rated CVE-2026-50522. It also came about one week after the Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch three other SharePoint Server bugs."

scworld.com/news/sharepoint-vu

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

CRITICAL THREAT: CVE-2026-50522 in Microsoft SharePoint enables unauthenticated remote code execution via untrusted data deserialization. Active exploitation is confirmed! Get the forensic detection queries and hardening strategies needed to secure your infrastructure now. thecybermind.co/jttd

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
SharePointの深刻なRCE脆弱性CVE-2026-50522、PoC公開後に実際のサイバー攻撃への悪用を確認 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #cyberattack #incident
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
2/6 Fresh exploitation signals Check Point says SmartConsole CVE-2026-16232 is actively exploited; SharePoint CVE-2026-50522 is now exploitation-priority.
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Linux
  • Linux

23 Jul 2026
Published
23 Jul 2026
Updated

CVSS
Pending
EPSS
0.22%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and returns an inaccurate value in *shared. If *shared is now false, the directio write proceeds with a stale data fork mapping. Fix this by querying the data fork mapping if the sequence counter changes across the ILOCK cycle.

Statistics

  • 7 Posts
  • 3 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

RefluXFS: Rechteausweitung im Linux-Kernel über XFS-Dateisystem

Unter der Bezeichnung CVE-2026-64600, kurz RefluXFS, wurde eine Schwachstelle im Linux-Kernel bekannt, die es einem gewöhnlichen, nicht privilegierten lokalen Benutzer erlaubt, sich Root-Rechte zu verschaffen. Betroffen sind Systeme mit reflink-fähigem XFS-Dateisystem – darunter zahlreiche Standardinstallationen großer Unternehmensdistributionen

all-about-security.de/refluxfs

#linux #cve #xfs #cybersecurity

  • 2
  • 0
  • 0
  • 13h ago
Profile picture fallback
  • 1
  • 0
  • 0
  • 4h ago
Profile picture fallback

RefluXFS (CVE-2026-64600): Linux Kernel XFS Flaw Lets Local Users Gain Root by Overwriting Protected Files

Learn how the RefluXFS Linux kernel vulnerability (CVE-2026-64600) exploits an XFS copy-on-write race condition to gain root privileges

thecybersecguru.com/news/reflu

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

⚠️ CRITICAL: RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)

A race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files and escalate to root, bypassing SELinux. The flaw affects kernel versions 4.11 and later, potentially impacting over 16 million systems. Any user with local access can exploit this to g…

threatnoir.com/focus

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
RefluXFS: Local Privilege Escalation via XFS reflink direct-I/O race
(CVE-2026-64600)

https://www.openwall.com/lists/oss-security/2026/07/22/14

Mythos writes Qualys advisories now FML :P
  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
RefluXFS: Local Privilege Escalation via XFS reflink direct-I/O race (CVE-2026-64600) www.openwall.com -> Mythos writes Qualys advisories now FML :P Original->
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • checkpoint
  • Quantum Security Management

22 Jul 2026
Published
23 Jul 2026
Updated

CVSS
Pending
EPSS
1.07%

Description

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Statistics

  • 6 Posts
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Geopolitical tensions escalate: US strikes on Iran continue, with President Trump threatening action against Iran's nuclear sites. In technology and cybersecurity, Check Point patched an actively exploited zero-day (CVE-2026-16232) in SmartConsole, allowing admin access. The US warns of Iranian state-backed hackers targeting critical industrial control systems. Significantly, OpenAI disclosed its AI model autonomously breached another company's systems during internal cybersecurity testing.

#AnonNews_irc #Cybersecurity #AI

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) 📖 Read more: www.helpnetsecurity.com/2026/07/23/c... #configurationmanagement #firewall #securityupdate #vulnerability #cybersecurity #cybersecuritynews
  • 0
  • 1
  • 0
  • 8h ago
Profile picture fallback
CVE-2026-16232 is a exploited authentication-bypass zero-day in Check Point Security Management and Multi-Domain Management, enabling admin login and policy changes.
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
Check Point patched CVE-2026-16232, an actively exploited SmartConsole auth bypass that can grant admin tokens and allow policy changes when Management Server exposure is not restricted. #CheckPoint #SmartConsole #CVE202616232
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
2/6 Fresh exploitation signals Check Point says SmartConsole CVE-2026-16232 is actively exploited; SharePoint CVE-2026-50522 is now exploitation-priority.
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
~Cybergcca~ Multiple CVEs actively exploited in Check Point and Microsoft products; patch immediately. - IOCs: CVE-2026-16232, CVE-2026-56164, CVE-2026-56155 - #CVE2026 #PatchNow #ThreatIntel
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • snapd

21 Jul 2026
Published
22 Jul 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.14%

KEV

Description

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.

Statistics

  • 4 Posts
  • 2 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

🚨 A flaw in Ubuntu’s snap-confine could turn local user access into root.

CVE-2026-8933 chains FUSE and symlink race conditions to plant malicious udev rules and execute commands as root.

Default Ubuntu Desktop 24.04, 25.10, and 26.04 installations are affected.

Read how the exploit works: thehackernews.com/2026/07/ubun

  • 0
  • 1
  • 0
  • 13h ago

Bluesky

Profile picture fallback
Ubuntu snap-confine flaw CVE-2026-8933 can let a local user gain root on default Ubuntu Desktop 24.04, 25.10, and 26.04 installs via a sandbox race condition chained with FUSE and symlink abuse. #Ubuntu #snapd #CVE20268933
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
⚠️ Quand un renforcement de la sécurité ouvre la porte à un accès root… 👀 Un score CVSS de 7.8 sur 10, et un accès root à la clé, voici ce qui se cache derrière la CVE-2026-8933 située dans snap-confine. 👉 www.it-connect.fr/cve-2026-893... #Cybersecurite #Linux #Ubuntu
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Palo Alto Networks
  • Cloud NGFW

13 May 2026
Published
14 Jul 2026
Updated

CVSS v4.0
HIGH (7.8)
EPSS
86.68%

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Statistics

  • 3 Posts

Last activity: 13 hours ago

Fediverse

Profile picture fallback

Critical Palo Alto Networks PAN-OS vulnerability (CVE-2026-0257) is actively exploited for Qilin ransomware attacks. Geopolitically, the US-Iran conflict sees continued strikes and threats to shipping in the Strait of Hormuz. In technology, NVIDIA unveiled a new AI tool for real-time fake video detection. (July 22, 2026).

#Cybersecurity #Geopolitics #AI

  • 0
  • 0
  • 0
  • 21h ago

Bluesky

Profile picture fallback
The latest update for #ArcticWolf includes "What the OpenAI–Hugging Face Incident Really Tells Us" and "Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware". #cybersecurity #infosec #networks https://opsmtrs.com/2ZFbaTl
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • PTC
  • Windchill PDMLink

18 Jun 2026
Published
30 Jun 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
1.25%

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Statistics

  • 3 Posts
  • 6 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Cl0p sfrutta una falla critica in PTC Windchill e FlexPLM: webshell ed estorsioni nella supply chain del manufacturing

La gang Cl0p, nota per gli attacchi di massa a MOVEit e GoAnywhere, sta ora sfruttando CVE-2026-12569 in PTC Windchill e FlexPLM per compromettere aziende manifatturiere, automotive, aerospaziali e retail. Webshell JSP, furto dati ed estorsioni: analisi tecnica completa con IoC.

insicurezzadigitale.com/cl0p-s

  • 1
  • 0
  • 1
  • 2h ago

Bluesky

Profile picture fallback
Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569) | Ransom-ISAC Blog - Ransom-ISAC A coordinated Unified Threat Advisory covering active Cl0p ransomware affiliate exploitation of internet-expose Read more: https://ransom-isac.com/blog/clop-windchill-flexplm-exploitation/
  • 2
  • 3
  • 0
  • 13h ago

Overview

  • Linux
  • Linux

04 Jul 2026
Published
18 Jul 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.12%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check.

Statistics

  • 2 Posts
  • 18 Interactions

Last activity: 20 hours ago

Fediverse

Profile picture fallback

So, uhm, at this point, seems like local privilege escalation vulnerabilities are numerous enough that you can pretty much assume that any local user can become root and escape most containers, yes?

"FragGap" LPE via IPv4/IPv6 UDP corking path

blog.qwerty.or.kr/en/posts/cdf
github.com/qwerty-po/security-
github.com/sgkdev/ipv6_frag_es

  • 6
  • 12
  • 0
  • 23h ago

Bluesky

Profile picture fallback
Linux Kernelの脆弱性(IPV6_FRAG_ESCAPE: CVE-2026-53362, CVE-2026-53366) #security #vulnerability #セキュリティ #脆弱性 #linux #kernel #ipv6 #selinux security.sios.jp/vulnerabilit...
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • WordPress
  • WordPress

17 Jul 2026
Published
22 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
38.60%

Description

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 9 hours ago

Fediverse

Profile picture fallback

CISA Alerts on Actively Exploited SQL Injection Flaw in WordPress Core #wordpress

CISA alerts to actively exploited WordPress Core SQL injection vulnerability (CVE-2026-63030), now in KEV. Attacks can lead to remote code execution and full site takeover, especially when combined with CVE-2026-60137. Patch now, monitor logs, and apply vendor fixes to reduce exposure. More details: ift.tt/0v3osyg

Source: ift.tt/0v3osyg | Image: ift.tt/rXtkoGB

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

⚠️ CRITICAL: Critical wp2shell WordPress flaws exploited to install webshells

Critical unauthenticated RCE vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) are being actively exploited via REST API batch processing to deploy webshells and malicious plugins. All unpatched WordPress instances are at risk. Attackers are actively scanning and compromising sites…

threatnoir.com/focus

  • 0
  • 0
  • 0
  • 13h ago

Bluesky

Profile picture fallback
Elastic researchers analyse wp2shell, a pre-authentication remote code execution chain in WordPress Core (CVE-2026-63030, CVE-2026-60137). www.elastic.co/security-lab...
  • 0
  • 1
  • 0
  • 9h ago
Profile picture fallback
@elastic.co wp2shell exploits a REST batch endpoint route confusion in WordPress Core enabling unauthenticated remote code execution via SQL injection and webshell deployment. - IOCs: CVE-2026-63030, CVE-2026-60137, wp2shell - ...
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • WordPress
  • WordPress

17 Jul 2026
Published
22 Jul 2026
Updated

CVSS v3.1
MEDIUM (5.9)
EPSS
20.40%

Description

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 9 hours ago

Fediverse

Profile picture fallback

CISA Alerts on Actively Exploited SQL Injection Flaw in WordPress Core #wordpress

CISA alerts to actively exploited WordPress Core SQL injection vulnerability (CVE-2026-63030), now in KEV. Attacks can lead to remote code execution and full site takeover, especially when combined with CVE-2026-60137. Patch now, monitor logs, and apply vendor fixes to reduce exposure. More details: ift.tt/0v3osyg

Source: ift.tt/0v3osyg | Image: ift.tt/rXtkoGB

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

⚠️ CRITICAL: Critical wp2shell WordPress flaws exploited to install webshells

Critical unauthenticated RCE vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) are being actively exploited via REST API batch processing to deploy webshells and malicious plugins. All unpatched WordPress instances are at risk. Attackers are actively scanning and compromising sites…

threatnoir.com/focus

  • 0
  • 0
  • 0
  • 13h ago

Bluesky

Profile picture fallback
Elastic researchers analyse wp2shell, a pre-authentication remote code execution chain in WordPress Core (CVE-2026-63030, CVE-2026-60137). www.elastic.co/security-lab...
  • 0
  • 1
  • 0
  • 9h ago
Profile picture fallback
@elastic.co wp2shell exploits a REST batch endpoint route confusion in WordPress Core enabling unauthenticated remote code execution via SQL injection and webshell deployment. - IOCs: CVE-2026-63030, CVE-2026-60137, wp2shell - ...
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • NLnet Labs
  • Unbound

22 Jul 2026
Published
22 Jul 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.46%

KEV

Description

In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to 'dname_query_hash()' as a label length writing over the stack variable 'labuf'. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

CVE-2026-55973 - Buffer Overflow in NLnet Labs Unbound 1.23.0-1.25.1. EDNS Report-Channel option mishandling leads to memory corruption. CVSS 7.5. No patch yet. Disable dns-error-reporting immediately. #CVE #infosec #DNSSEC

valtersit.com/cve/CVE-2026-559

  • 1
  • 2
  • 0
  • 8h ago
Showing 1 to 10 of 51 CVEs