Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 4 Posts
- 1 Interaction
Fediverse
‼️ PoC released for CVE-2026-54121 codenamed Certighost
CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.
⚠️ CRITICAL: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Certighost (CVE-2026-54121) allows any domain user to obtain a Domain Controller certificate and execute DCSync attacks to steal the krbtgt secret without admin rights. This gives attackers a direct path to full domain compromise. Any organization running unpatched Active Directory is at immediate…
Certighost (CVE-2026-54121) : un compte AD standard suffit pour usurper un contrôleur de domaine https://www.it-connect.fr/certighost-cve-2026-54121-ad-cs-controleur-de-domaine/ #ActuCybersécurité #ActiveDirectory #Cybersécurité #Vulnérabilité #Microsoft
Overview
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
Bluesky
Overview
- Microsoft
- Azure Portal
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
🚨 CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability
CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.
CVSS: 9.3
More information: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62835
CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at https://radar.offseq.com/threat/cve-2026-62835-cwe-285-improper-authorization-in-microsoft-azure-portal-defd11bbcf2e17c7 #OffSeq #Azure #Vuln #CloudSecurity
Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
‼️ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
CVSS: 9.1
Scanner: https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
Details and Mitigation: https://support.checkpoint.com/results/sk/sk185169/
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Overview
- Tycon Systems
- TPDIN-Monitor-WEB2
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-61884 (CRITICAL, CVSS 9.8) in Tycon TPDIN-Monitor-WEB2 v2.3.9: Server-side auth validation missing — empty creds grant admin access. Restrict management interface, monitor for unauthorized logins. https://radar.offseq.com/threat/cve-2026-61884-cwe-288-in-tycon-systems-tpdin-monitor-web2-38fd252c1e4f018a #OffSeq #CVE #IoT #Infosec
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Microsoft
- Microsoft Purview Data Governance
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: https://radar.offseq.com/threat/cve-2026-57106-cwe-918-server-side-request-forgery-ssrf-in-microsoft-microsoft-purview-data-governance-0983080847f54f67 #OffSeq #Vuln #SSRF #Microsoft #CyberSec