Overview
- Atlassian
- Bamboo Data Center
Description
Statistics
- 16 Posts
- 24 Interactions
Fediverse
Oh, Atlassian, never change! 😭
"CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products"
CVSS Score 9.3, so, you know, you better "Test that your rule blocks .. immediately adjacent to /".
APT /../../../../../../etc/passwd strikes again.
Critical Atlassian File Access Flaw Draws Attacks Across Eight Products https://www.esecurityplanet.com/news/news-atlassian-cve-2026-21589-file-read-flaw/
Critical Atlassian Data Center vulnerability CVE-2026-21589
Atlassian has disclosed CVE-2026-21589, a critical unauthenticated arbitrary file access vulnerability affecting Bitbucket Data Center, Confluence Data Center, Jira Software and Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.
SecPoint Penetrator Partner Sign Up
https://www.secpoint.com/partner-signup.html
#Atlassian #CyberSecurity #VulnerabilityManagement #SecPoint #Penetrator
⚠️ CRITICAL: Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
A critical arbitrary file access vulnerability (CVE-2026-21589) in Atlassian Data Center products is under active exploitation as of public disclosure. Threat actors attempted exploitation within two hours of details going public, with potential access to credentials and sensitive files. All Atlass…
🤖 AI generated summary
Atlassian Vulnerability Comes Under Attack Hours After Details Go Public
Atlassian Data Center CVE-2026-21589 (CVSS 9.3): arbitrary file read non autenticato via path traversal, sfruttamento osservato circa 2 ore dopo il write-up e la PoC di watchTowr (honeypot Previdian). Colpiti Jira Software/JSM, Confluence, Bitbucket, Bamboo, Crowd, Crucible, Fisheye (Cloud già patchato). La web-resource library converte '::' in '/', da cui il traversal sugli endpoint dei plugin.
Atlassian : une faille critique permet de lire des fichiers sur Jira, Confluence et Bitbucket https://www.it-connect.fr/atlassian-cve-2026-21589-faille-critique-jira-confluence-bitbucket/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
Bluesky
Overview
Description
Statistics
- 3 Posts
- 18 Interactions
Fediverse
Watchtowr have a good look at pray and spray #PitScaler exploitation. This isn’t the initial exploitation - their timeline should expand back to September 4th for that.
Also they make a good point re the latest SAML bug - by using it to DoS, it causes attacker commands in the logs to process immediately post reboot with PitScaler vuln. Not covered in blog: Attackers are actually doing this, they’re preloading the logs using the username field for failed logins.
Citrix NetScaler security alert: two actively exploited vulnerabilities
Citrix has confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 in unmitigated NetScaler deployments.
The first can allow unauthenticated command execution. The second can lead to remote code execution or denial of service when DTLS is enabled.
https://www.linkedin.com/products/secpoint-penetrator/
#NetScaler #CyberSecurity #VulnerabilityManagement #SecPoint #Penetrator
Overview
Description
Statistics
- 2 Posts
- 4 Interactions
Fediverse
I'm tired, boss.
A new #Citrix CVE affecting SAML IdP/SP-configured devices is out.
https://ifin.network/t/cve-2026-107406-somehow-another-citrix-netscaler-saml-vulnerability/891
Overview
- VMware
- VMware Workstation
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
A VMware VMXNET3 vulnerability, CVE-2026-59346 (CVSS 9.3), allows VM escape. Full details and PoC exploit code are now public. Patch to 26H1u1.
#VMware #VMXNET3 #CVE202659346 #VMEscape #Virtualization #Broadcom #PoC #Vulnerability
PoC Released for Critical VMware VMXNET3 Integer Overflow Flaw Enabling Guest-to-Host Code Execution (CVE-2026-59346)
CVE-2026-59346 affects VMware VMXNET3 and enables guest-to-host memory corruption. A public PoC crashes vmware-vmx. Patch Workstation and Fusion nowhttps://thecybersecguru.com/exploits/cve-2026-59346-vmware-vmxnet3-poc/
Overview
- kstover
- Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder
Description
Statistics
- 2 Posts
Fediverse
An active WordPress XSS campaign exploits Ninja Forms flaw CVE-2026-94504 and CVE-2026-93836 to plant hidden admin accounts. Patch now.
#WordPress #NinjaForms #WooCommerce #CVE202694504 #CVE202693836 #XSS #ExploitedInTheWild #Malware
Overview
- IBM
- DataPower Gateway 10.6.0
Description
Statistics
- 2 Posts
Fediverse
IBM fixes 23 IBM DataPower Gateway vulnerabilities, including critical RCE flaws CVE-2026-15762 and CVE-2026-16340. Upgrade to 11.0.0.3 now.
#IBM #DataPower #APIGateway #CVE202615762 #CVE202616340 #CVE202614990 #RCE #Vulnerability
Overview
- IBM
- DataPower Gateway 10.6CD
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-16340 (CRITICAL, CVSS 9.8): IBM DataPower Gateway 10.5.0.0 – 10.5.0.22, 10.6.0.0 – 10.6.0.10, 10.6.1 – 10.6.6, 11.0.0.0 – 11.0.0.2 vulnerable to remote code execution via out-of-bounds write. Patch priority high. https://radar.offseq.com/threat/cve-2026-16340-cwe-787-out-of-bounds-write-in-ibm-datapower-gateway-106cd-0c7cd2fb359c85f5 #OffSeq #IBM #Vuln #Cybersecurity
IBM fixes 23 IBM DataPower Gateway vulnerabilities, including critical RCE flaws CVE-2026-15762 and CVE-2026-16340. Upgrade to 11.0.0.3 now.
#IBM #DataPower #APIGateway #CVE202615762 #CVE202616340 #CVE202614990 #RCE #Vulnerability
Overview
- Sungrow
- iSolarCloud
Description
Statistics
- 1 Post
- 11 Interactions
Overview
- Splunk
- Splunk Enterprise
Description
Statistics
- 2 Posts
- 3 Interactions
Fediverse
5 new Security Advisories for Cisco Splunk
Some of these are quite critical, e.g. CVE-2026-76281 & CVE-2026-76268 with each CVSS 9.8
Splunk fixes 22 Splunk Enterprise vulnerabilities, including critical Patroni API flaw CVE-2026-76268 and CVE-2026-76281. Upgrade to 10.4.3 now.
#Splunk #SplunkEnterprise #SIEM #CVE202676268 #CVE202676281 #RCE #PatchNow #Vulnerability
Overview
- Splunk
- Splunk Enterprise
Description
Statistics
- 2 Posts
- 3 Interactions
Fediverse
5 new Security Advisories for Cisco Splunk
Some of these are quite critical, e.g. CVE-2026-76281 & CVE-2026-76268 with each CVSS 9.8
Splunk fixes 22 Splunk Enterprise vulnerabilities, including critical Patroni API flaw CVE-2026-76268 and CVE-2026-76281. Upgrade to 10.4.3 now.
#Splunk #SplunkEnterprise #SIEM #CVE202676268 #CVE202676281 #RCE #PatchNow #Vulnerability