24h | 7d | 30d

Overview

  • Microsoft
  • Windows 10 Version 1607

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (7.0)
EPSS
0.36%

Description

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Statistics

  • 25 Posts
  • 15 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

「Microsoft 製品の脆弱性対策について(2026年8月)」: #IPA

「 2026年8月12日(日本時間)に Microsoft 製品に関するセキュリティ更新プログラム(月例)が公表されています。
これらの脆弱性を悪用された場合、アプリケーションプログラムが異常終了する、攻撃者によってパソコンを制御される、といった様々な被害が発生するおそれがあります。

この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。 」

ipa.go.jp/security/security-al

#prattohome

  • 2
  • 1
  • 0
  • 10h ago
Profile picture fallback

「マイクロソフトは、現在攻撃を受けているWindowsドライバーのゼロデイ脆弱性を含む398件の脆弱性を修正した。 」: #TheHackerNews

「マイクロソフトは火曜日に月例のセキュリティアップデートを公開したが、修正された脆弱性の1つが既に攻撃に悪用されている。

このバグは、ネットワークソケット操作を処理するWindowsカーネルの中核ドライバに存在します。既にマシン上でコードを実行している攻撃者は、このバグを利用してSYSTEM権限に昇格できます。このパッチが最初にリリースされます。

この脆弱性は CVE-2026-68820 (CVSSスコア:7.0)として追跡されており、今月のリリースでマイクロソフトが現在悪用されていると警告している唯一の脆弱性です。悪用は、ドライバーの競合状態をトリガーすることによって行われます。マイクロソフトは、この悪用を行った組織を公表していません。」

thehackernews.com/2026/08/micr

#prattohome

  • 1
  • 0
  • 0
  • 11h ago
Profile picture fallback

🚨 THREAT ALERT: CISA adds CVE-2026-68820 (Windows WinSock AFD Use-After-Free) to the KEV catalog due to active exploitation. Local attackers can elevate privileges to system level. Access our TSUITE brief with CrowdStrike CQL telemetry queries: thecybermind.co/jily

  • 0
  • 1
  • 0
  • 7h ago
Profile picture fallback

📰 Lazarus Group Exploits Windows Zero-Day in Espionage Campaign

Microsoft patches actively exploited Windows zero-day (CVE-2026-68820) used by Lazarus Group. The bug allows SYSTEM-level access and was used in the 'Operation Dream Job' campaign to deploy rootkits against the defense sector. #CVE202668820 #Lazarus ...

🔗 cyber.netsecops.io/articles/la

  • 0
  • 0
  • 1
  • 17h ago
Profile picture fallback

Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild, plus two disclosed bugs.

securityonline.info/microsoft-

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.

securityonline.info/lazarus-ze

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. radar.offseq.com/threat/fresh-

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

⚠️ CRITICAL: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Microsoft patched CVE-2026-68820, a zero-day use-after-free in afd.sys kernel driver actively exploited for SYSTEM privilege escalation. This is the fourth afd.sys zero-day since 2022, with historical links to nation-state actors. All Windows systems running unpatched afd.sys are at immediate risk…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign.
  • 1
  • 3
  • 0
  • 1h ago
Profile picture fallback
Check Point researchers look into the latest variant of the Operation Dream Job campaign where the threat actor exploited CVE-2026-68820, a 0-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of Lazarus’s kernel-mode rootkit FudModule. research.checkpoint.com/2026/shatter...
  • 1
  • 1
  • 0
  • 7h ago
Profile picture fallback
Microsoft patches 398 flaws, including exploited CVE-2026-68820 that lets local attackers reach SYSTEM, plus four unauthenticated 9.8 RCEs.
  • 0
  • 1
  • 0
  • 17h ago
Profile picture fallback
Lazarus-linked Operation Dream Job hit defense firms in Europe and India with trojanized PDF viewers, spear-phishing, and new FudModule exploits, including CVE-2026-68820 and Roundcube abuse. #Lazarus #India #Europe
  • 0
  • 1
  • 0
  • 14h ago
Profile picture fallback
~Checkpoint~ Lazarus deploys Troy backdoor and FudModule rootkit exploiting CVE-2026-68820 zero-day in Windows AFD.sys via trojanized PDF viewers. - IOCs: 135[.]181[.]67[.]203, 135[.]181[.]185[.]158, enveil[.]online - #Lazarus #ThreatIntel #ZeroDay
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
CVE-2026-68820 in afd.sys is actively exploited to escalate privileges to SYSTEM, and Microsoft’s monthly updates also patch four unauthenticated RCE flaws.
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Microsoft’s August 2026 Patch Tuesday fixes an actively exploited zero-day (CVE-2026-68820) in the Windows kernel driver, used by Lazarus Group […]
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
"Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack" published by Checkpoint. #DreamJob, #Troy, #FudModule, #Lazarus, #MISTPEN, #CVE202668820, #ForestTiger https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
「この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。」
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820) 🔗 Read more: www.helpnetsecurity.com/2026/08/12/a... #patchtuesday #patching #windows #0day #sharepointserver #cybersecurity #cybersecuritynews #ITsec @microsoft.com @dustinchilds.bsky.social @thezdi.bsky.social
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
微软八月例行更新修复 421 个 bug,包括正被朝鲜黑客利用的 0day 微软本周二释出了八月例行安全更新,共修复 421 个 bug,比上个月少约 200 个,在 AI 辅助漏洞披露和修复时代,bug 修复数动辄数百已成为新常态。其中一个 bug CVE-2026-68820 正被朝鲜黑客组织 Lazarus Group 利用。它是 Windows Ancillary Function Driver for WinSock 的一个释放后使用 bug,攻击者能利用该 bug 以 SYSTEM 权限执行代码且无需用户交互。
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
Lazarus Group is exploiting Windows zero-day CVE-2026-68820 in fake job lures to hit defense, aerospace, and aviation targets with SYSTEM-level malware and data theft. #LazarusGroup #India #WindowsZeroDay
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
Microsoft lança atualização de emergência para corrigir a CVE-2026-68820, uma falha de gravidade elevada no controlador Ancillary Function para WinSock. A vulnerabilidade, que afeta diversas versões do Windows, já está a ser explorada em ataques reais. 🚨 #falha #lan #microsoft #windows
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
Microsoft released patches for 421 CVEs, including exploited zero-days CVE-2026-68820 and CVE-2026-62832 enabling local privilege escalation without user interaction.
  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback
~Cisa~ CISA added three actively exploited vulnerabilities (Cisco ASA/FTD, Windows WinSock, Metabase) to the KEV Catalog. - IOCs: CVE-2026-20349, CVE-2026-68820, CVE-2026-72898 - #CISA #CVE #ThreatIntel
  • 0
  • 1
  • 0
  • 20h ago
Profile picture fallback
@talosintelligence.com Microsoft's August 2026 update patches 421 vulnerabilities, including 62 critical and one actively exploited EoP flaw (CVE-2026-68820). - IOCs: CVE-2026-68820, CVE-2026-62893, CVE-2026-62878 - #CVE #PatchTuesday #ThreatIntel
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Cisco
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (8.6)
EPSS
0.97%

Description

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Statistics

  • 12 Posts
  • 2 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback
  • 0
  • 1
  • 0
  • 20h ago
Profile picture fallback

Cisco confirms CVE-2026-20349, a Cisco ASA and FTD VPN vulnerability (CVSS 8.6), is exploited in the wild to crash firewalls. Patch now.

securityonline.info/cisco-asa-

  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback

「Ciscoは、ASAおよびFTD VPNの脆弱性が悪用され、デバイスがクラッシュする可能性があると警告している。 」: #BLEEPINGCOMPUTER

「シスコは、Secure Firewall ASAおよびThreat Defense(FTD)ソフトウェアに存在する深刻なサービス拒否攻撃の脆弱性が、影響を受けるデバイスをリモートからクラッシュさせる攻撃で積極的に悪用されていると警告している。

CVE-2026-20349として追跡されているこの脆弱性は、深刻度スコアが8.6であり、特定のリモートアクセスサービスが有効になっているCisco Secure Firewall Adaptive Security Appliance(ASA)またはSecure Firewall Threat Defense(FTD)ソフトウェアを実行しているデバイスに影響を与えます。

シスコは本日公開したセキュリティ勧告の中で、この脆弱性はHTTPリクエスト処理時のエラーチェックが不十分なことに起因すると述べた。 」

bleepingcomputer.com/news/secu

#prattohome

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

🚨 THREAT ALERT: CISA adds CVE-2026-20349 (Cisco ASA/FTD Heap Inspection DoS) to the KEV catalog due to active exploitation. Unauthenticated remote actors can crash perimeter firewalls. Read our full TSUITE brief with SPL, KQL, AQL & Chronicle queries: thecybermind.co/jily

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. securityweek.com/cisco-patches

  • 0
  • 0
  • 1
  • 3h ago
Profile picture fallback

📰 Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Cisco patches an actively exploited zero-day (CVE-2026-20349) in ASA and FTD firewalls. The flaw allows a remote, unauthenticated attacker to cause a denial-of-service (DoS). Patch immediately to prevent network disruption. #Cisco #ZeroDay #CyberSecu...

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
Cisco warns that CVE-2026-20349, an 8.6 DoS flaw in Secure Firewall ASA and FTD VPN services, is being actively exploited to crash devices. Fixed releases and hot fixes are available. #Cisco #CVE202620349 #VPN
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
CVE-2026-20349 enables unauthenticated attackers to trigger reloads and denial-of-service on Cisco ASA/FTD firewalls via crafted HTTP requests to SSL VPN.
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
Cisco patched CVE-2026-20349 in Secure Firewall ASA and FTD, a zero-day that could let remote attackers trigger DoS via crafted HTTP requests to the Remote Access SSL VPN service. #Cisco #CVE202620349 #CISA
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
Cisco has confirmed active exploitation of a high-severity vulnerability (CVE-2026-20349) in its Secure Firewall ASA and FTD Software. The flaw […]
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
~Cisa~ CISA added three actively exploited vulnerabilities (Cisco ASA/FTD, Windows WinSock, Metabase) to the KEV Catalog. - IOCs: CVE-2026-20349, CVE-2026-68820, CVE-2026-72898 - #CISA #CVE #ThreatIntel
  • 0
  • 1
  • 0
  • 20h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

14 Jul 2026
Published
10 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
1.63%

KEV

Description

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Statistics

  • 10 Posts
  • 5 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Rapid7 published full details and a PoC for CVE-2026-55040, a critical SharePoint authentication bypass that forges JWT tokens. Patch now.

securityonline.info/sharepoint

  • 3
  • 1
  • 0
  • 10h ago
Profile picture fallback
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)

https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/
  • 0
  • 1
  • 0
  • 10h ago
Profile picture fallback

「研究者らが、認証不要のリモートコード実行(RCE)を実現するAI支援型SharePointエクスプロイトチェーンを公開 」: #TheHackerNews

「セキュリティ研究者らは、有効なアカウントを持たずに、管理者を含むあらゆるユーザーとしてMicrosoft SharePointサーバーに侵入する方法を発見した。この発見に大きく貢献したのが、AIエージェントを用いた作業だった。

CVE-2026-55040 (CVSS 9.1)として追跡されているこの脆弱性は 、SharePoint Server Subscription Edition、SharePoint Server 2019、およびSharePoint Server 2016に影響します。マイクロソフトの影響を受ける製品リストには、これら3つのオンプレミス版のみが含まれており、SharePoint Onlineは含まれていません。

この攻撃手法は、認証されていないリモート攻撃者が、選択したユーザーの身元を偽装することを可能にします。 」

thehackernews.com/2026/08/rese

#prattohome

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. bleepingcomputer.com/news/micr

  • 0
  • 0
  • 1
  • 3h ago
Profile picture fallback

New SharePoint auth bypass already being exploited hours after PoC went public

Rapid7 published a proof-of-concept exploit today for CVE-2026-55040, an authentication bypass in SharePoint's JWT token validation that lets an attacker impersonate any user or admin without credentials....

itnerd.blog/2026/08/12/new-sha

  • 0
  • 0
  • 1
  • Last hour
Profile picture fallback

En las últimas 24 horas, se detectaron vulnerabilidades críticas en Microsoft SharePoint que permiten ejecución remota de código sin autenticación, potenciada por IA, y fallas en autenticación con manipulación de tokens. Cisco alerta sobre exploits activos que afectan sus VPN ASA y FTD, mientras México enfrenta pérdidas millonarias por rezago en ciberseguridad. Además, DEF CON ofrece acceso libre a su valioso contenido formativo. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 12/08/26 📆 |====

🔓 VULNERABILIDAD CRÍTICA EN MICROSOFT SHAREPOINT: EJECUCIÓN REMOTA DE CÓDIGO

Rapid7 y Microsoft han revelado una grave vulnerabilidad en SharePoint, identificada como CVE-2026-63520, que permite la ejecución remota de código sin autenticación cuando se combina con otra falla. Esta amenaza pone en riesgo servidores corporativos, facilitando ataques sofisticados que pueden comprometer datos sensibles y el control del sistema. Mantener SharePoint actualizado es vital para proteger su entorno. Descubre los detalles completos sobre esta vulnerabilidad y cómo proteger tu infraestructura aquí 👉 djar.co/3cd5Vh

🛡️ ANÁLISIS DETALLADO DE FALLAS EN LA AUTENTICACIÓN DE MICROSOFT SHAREPOINT (CVE-2026-55040)

Un análisis técnico profundo revela cómo CVE-2026-55040 permite eludir el sistema de autenticación mediante la manipulación del token JWT en SharePoint. Esta brecha puede ser explotada por atacantes para suplantar identidades y obtener acceso indebido, facilitando ataques posteriores. Comprender la naturaleza de esta vulnerabilidad es esencial para implementar medidas de defensa eficaces. Consulta el informe técnico completo y fortalece tu seguridad aquí 👉 djar.co/SrXg

🤖 CADENA DE EXPLOTACIÓN CON ASISTENCIA DE IA EN SHAREPOINT: RIESGO DE EJECUCIÓN REMOTA SIN AUTENTICAR

Investigadores han demostrado cómo la vulnerabilidad CVE-2026-55040, combinada con CVE-2026-63520, permite a los atacantes no autenticados ejecutar código remotamente en SharePoint. El uso de inteligencia artificial en esta cadena de explotación agiliza y potencia la sofisticación del ataque, elevando los riesgos para organizaciones que no actualizan a tiempo sus sistemas. Infórmate sobre esta amenaza avanzada y cómo mitigarla inmediatamente 👉 djar.co/h7SaRv

🔥 ALERTA DE CISCO: VULNERABILIDAD EN VPN ASA Y FTD CON EXPLOIT ACTIVAMENTE USADO

Cisco ha emitido una advertencia crítica sobre una vulnerabilidad de alta gravedad en sus productos Secure Firewall ASA y Threat Defense (FTD). Ha sido detectado un exploit activo que provoca ataques de denegación de servicio remoto, llevando a la caída de dispositivos, comprometiendo la continuidad operativa de las redes corporativas. Es imprescindible aplicar los parches y seguir las recomendaciones oficiales para evitar interrupciones. Conoce la advertencia oficial y pasos para proteger tus dispositivos aquí 👉 djar.co/qy7j

💸 IMPACTO DEL REZAGO EN CIBERSEGURIDAD EN MÉXICO: PÉRDIDAS MILLONARIAS

El rezago en ciberseguridad que enfrenta México está generando un impacto económico de miles de millones de pesos, afectando tanto al sector privado como al público. La falta de inversiones adecuadas y estrategias de protección digital robustas pone en riesgo la estabilidad tecnológica y financiera del país. Conocer esta realidad invita a reflexionar sobre la urgencia de implementar políticas y prácticas eficaces en seguridad informática. Lee el análisis completo sobre esta problemática y su impacto económico aquí 👉 djar.co/QWHu9

📼 ACCESO LIBRE A TODO EL CONTENIDO DE DEF CON: PRESENTACIONES, DOCUMENTALES Y MÁS

Para quienes buscan formación continua en seguridad informática, media.defcon.org ofrece un archivo completo con videos, presentaciones, documentales y más del reconocido congreso DEF CON. Este extenso repositorio es una fuente invaluable de conocimiento actual, técnicas, y tendencias en hacking ético y defensa digital. No pierdas la oportunidad de aprender de los mejores expertos del mundo. Explora todo el material disponible para potenciar tu expertise aquí 👉 djar.co/XzsPs

  • 0
  • 0
  • 0
  • 5h ago

Bluesky

Profile picture fallback
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) www.rapid7.com -> Original->
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
Rapid7's PoC for CVE-2026-55040, a critical SharePoint auth bypass, is already being used in attacks on honeypots. Microsoft patched it in July 2026. #SharePoint #Rapid7 #CVE202655040
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Microsoft
  • Microsoft Malware Protection Engine

16 Jun 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
10.75%

KEV

Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Statistics

  • 8 Posts
  • 8 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

🚨Nightmare Eclipse has released a new zero-day PoC called ShieldBreak

Per the security researcher: "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass."

GitHub: github.com/MSNightmare/ShieldB

  • 3
  • 2
  • 0
  • 20h ago
Profile picture fallback

On another news NightmareEclipse (the goat?) returned with a new PoC, after Microsoft failed to fully patch RoguePlanet (CVE-2026-50656), the current PoC only made for latest Windows 11 release, but they said that Windows 10 also still vulnerable. And yeah, it works even after the latest update

github.com/MSNightmare/ShieldB

  • 1
  • 1
  • 0
  • 19h ago
Profile picture fallback

A public PoC named ShieldBreak bypasses Microsoft's CVE-2026-50656 patch, enabling Windows Defender privilege escalation to SYSTEM.

securityonline.info/shieldbrea

  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

„Microsoft hat mit dem August 2026-Patchday zwar einige Sicherheitskorrekturen ausgeliefert. Aber die RoguePlanet genannte Schwachstelle (CVE-2026-50656) soll nicht ausreichend abgeschwächt worden sein. Der als Nightmare Eclipse agierende Sicherheitsforscher hat einen ShieldBreak genannten Proof of Concept (PoC) veröffentlicht.“

borncity.com/blog/2026/08/12/s

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

August 2026 Patchday: Updates gerade freigegeben, da veröffentlicht Nightmare Eclipse #Shieldbreak als Proof of Concept (PoC). Der PoC umgeht die ungenügend gepatchte #Defender Schwachstelle CVE-2026-50656 (#RoguePlanet).
borncity.com/blog/2026/08/12/s

  • 0
  • 0
  • 1
  • 8h ago

Bluesky

Profile picture fallback
ShieldBreak is a claimed patch bypass for Defender flaw CVE-2026-50656, with a PoC tested on Windows 11 25H2 and Server 2025.
  • 0
  • 1
  • 0
  • Last hour
Profile picture fallback
CVE-2026-50656, this PoC demonstrates a full patch bypass.
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 3 Posts
  • 3 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-17106: Docker docker cp Container-to-Host Arbitrary File Write

CopyEscape (CVE-2026-17106) lets a malicious Docker container abuse docker cp to overwrite host files through a filesystem race and symlink extraction flaw

thecybersecguru.com/news/copye

  • 0
  • 0
  • 0
  • 23h ago

Bluesky

Profile picture fallback
CVE-2026-17106, a container-to-host arbitrary file-write vulnerability in Docker’s docker cp command
  • 1
  • 2
  • 0
  • 23h ago
Profile picture fallback
Kritická zranitelnost v Dockeru, sledovaná jako CVE-2026-17106 a označovaná jako „CopyEscape“, umožňuje škodlivým kontejnerům přepisovat soubory na hostitelském systému
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Metabase
  • Metabase

10 Aug 2026
Published
12 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
1.07%

Description

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

🚨 CRITICAL THREAT: CISA adds CVE-2026-72898 (Metabase SQL Injection) to the KEV catalog due to active exploitation. Unauthenticated attackers can hijack admin rights and steal database credentials. Full TSUITE brief with SPL, KQL, AQL & YARA-L: thecybermind.co/jily

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
🚨 Critical Metabase SQL injection (CVE-2026-72898) CVSS 10.0. No authentication required. Actively exploited in the wild.
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
~Cisa~ CISA added three actively exploited vulnerabilities (Cisco ASA/FTD, Windows WinSock, Metabase) to the KEV Catalog. - IOCs: CVE-2026-20349, CVE-2026-68820, CVE-2026-72898 - #CISA #CVE #ThreatIntel
  • 0
  • 1
  • 0
  • 20h ago

Overview

  • Zoom Communications
  • Zoom Clients

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (8.3)
EPSS
0.41%

KEV

Description

Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.

Statistics

  • 2 Posts

Last activity: 21 hours ago

Bluesky

Profile picture fallback
Zoom patched four flaws, including CVE-2026-53413, a zero-click RCE in Zoom's annotator that could let an attacker take over another participant's machine. #Zoom #CVE-2026-53413 #RCE
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
Zoomsday: Zero-click RCE in Zoom, from any meeting participant to any other (CVE-2026-53413)
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Ivanti
  • Endpoint Manager

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.87%

KEV

Description

Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.

Statistics

  • 3 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. securityweek.com/ivanti-epm-up

  • 0
  • 0
  • 1
  • 3h ago

Bluesky

Profile picture fallback
Ivanti patched 4 flaws in Endpoint Manager and Neurons for MDM, including a credential leak in SQL connections and a crash bug. No in-the-wild exploitation seen. #Ivanti #EndpointManager #CVE202618129
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Trusted Computing Group
  • TPM2.0

11 Aug 2026
Published
11 Aug 2026
Updated

CVSS
Pending
EPSS
0.22%

KEV

Description

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.

Statistics

  • 2 Posts

Last activity: 12 hours ago

Bluesky

Profile picture fallback
Compute Engine update on August 11, 2026 https://docs.cloud.google.com/compute/docs/release-notes#August_11_2026 #googlecloud A vulnerability (CVE-2026-6726) in the Trusted Computing Group's TPM 2.0 reference implementation code was discovered and is being addressed
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
JVNVU#96623328: TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727) https://jvn.jp/vu/JVNVU96623328/
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Phoenix Contact
  • AXC F 1152

12 Aug 2026
Published
12 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.59%

KEV

Description

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

Statistics

  • 2 Posts
  • 4 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

BoF in a PROFINET service?! I'm shocked. Shocked! Well, not that shocked.

nvd.nist.gov/vuln/detail/CVE-2

  • 0
  • 3
  • 0
  • 2h ago
Profile picture fallback

VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

  • 0
  • 1
  • 0
  • 8h ago
Showing 1 to 10 of 82 CVEs