24h | 7d | 30d

Overview

  • NetScaler
  • ADC

30 Jun 2026
Published
30 Jun 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.49%

KEV

Description

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Statistics

  • 6 Posts
  • 30 Interactions

Last activity: 14 hours ago

Fediverse

Profile picture fallback

Watchtowr got RCE via one of the many Citrix Netscaler SAML vulns. labs.watchtowr.com/youre-back-

  • 6
  • 23
  • 0
  • 23h ago
Profile picture fallback

RE: infosec.exchange/@watchTowr/11

Si vous n’avez pas encore patché la RCE NetScaler du mois de juin :
support.citrix.com/support-hom

ChatGPT dit que c’est probablement le dernier moment de le faire avant qu’il utilise ça comme opportunité pour s’échapper de sa sandbox.

Parce que, bien évidemment, la fine équipe de watchTowr vient de publier le write-up qui transforme le gentil « memory overflow » en RCE pré-auth root.

👇
labs.watchtowr.com/youre-back-

  • 0
  • 1
  • 0
  • 23h ago
Profile picture fallback

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452 labs.watchtowr.com/youre-back-

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback

CVE-2026-8452: Technical Analysis of the Citrix NetScaler Memory Overflow Vulnerability

CVE-2026-8452 is a high-severity NetScaler vulnerability affecting ADC and Gateway. See affected builds, technical details, impact and patch guidance

thecybersecguru.com/news/cve-2

  • 0
  • 0
  • 0
  • 14h ago

Bluesky

Profile picture fallback
📢 RCE pré-authentifiée sur Citrix NetScaler via heap overflow SAML (CVE-2026-8452) Cet article présente une analyse technique approfondie d'une vulnérabilité heap overflow pré-authentifiée affectant Citrix NetScaler… 🟢 vérification factuelle haute #CitrixNetScaler #RCEPréAuthentifiée #Cyberveille
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
~Watchtowr~ Unauthenticated heap overflow in NetScaler SAML PrefixList canonicalization yields full root RCE by overwriting function pointers and jumping to RWX heap shellcode. - IOCs: CVE-2026-8452, /var/vpn/theme/x[.]php - ...
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
14 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.14%

KEV

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Statistics

  • 5 Posts
  • 14 Interactions

Last activity: 17 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Global Threat Campaign Hits Critical VMware vCenter Flaw

Active exploitation of CVE-2026-59310 in VMware vCenter Server is ongoing. All organizations running vCenter are at risk of compromise. Patching alone may be insufficient due to suspected persistence mechanisms already deployed by threat actors.

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback

⚠️ CRITICAL: Critical VMware vCenter RCE flaw exploited for reverse SSH access

A critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being actively exploited in the wild to deploy reverse SSH tools for persistence. At least 361 compromised hosts across 47 countries have been identified, with attackers establishing remote access on vi…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 17h ago

Bluesky

Profile picture fallback
Thanks to collaboration with QUIRSO GmbH we are sharing the VMware vCenter CVE-2026-59310 Exploitation Victim Special Report shadowserver.org/what-we-do/n... Check compromised IPs for your network/constituency & remediate! File prefix: 2026-08-13-special See: medium.com/@quirso_de/a...
  • 2
  • 3
  • 0
  • 22h ago
Profile picture fallback
Critical RCE via Directory Traversal in Broadcom VMware vCenter CVE-2026-59310 https://gbhackers.com/hackers-exploit-critical-vmware-vcenter-flaw https://flagthis.com/tldr/6107 ##Broadcom ##VMware ##RCE ##APT ##CloudSecurity
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
You can also track CVE-2026-59310 & CVE-2026-59309 vulnerable VMware vCenter instances in our daily Vulnerable HTTP reporting since July 30th: shadowserver.org/what-we-do/n... Tracker: dashboard.shadowserver.org/statistics/c... World Map: dashboard.shadowserver.org/statistics/c...
  • 3
  • 6
  • 0
  • 21h ago

Overview

  • SAP_SE
  • SAP Commerce Cloud (Data Hub Adapter)

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.73%

KEV

Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

「SAP Commerce Cloudの脆弱性が最大レベルの攻撃の標的に。 」: #BLEEPINGCOMPUTER

「脅威インテリジェンス企業Defusedによると、3日前にパッチが適用されたSAP Commerce Cloudの深刻度最高レベルのリモートコード実行の脆弱性が、すでに攻撃の標的となっているという。

Commerce Cloud(旧称SAP Hybris)は、世界的に有名なブランドや大手小売業者が所有するオンラインストアで使用されているクラウドベースのeコマースプラットフォームです。

CVE-2026-58231 として追跡されている この重大な脆弱性は、Commerce Cloudの中核となるデータハブアダプタ拡張機能における不適切な認証の弱点に起因するもので、権限を持たない攻撃者が低複雑度の攻撃で悪用し、任意のコードを実行する可能性があります。 」

bleepingcomputer.com/news/secu

#prattohome

  • 1
  • 1
  • 0
  • 2h ago
Profile picture fallback

Apple Partners With Alibaba to Launch China-Specific AI Model – DTH

[🖼 DTH-6-150x150]France’s Top Court Strikes Down Proposed Social Media Ban for Minors, Google Launches Gemini 3.7 Flash to Boost AI Performance, and the White House Imposes 100% Tariffs on Drones to Boost Domestic Manufacturing and Security.

MP3

Please SUBSCRIBE HERE for free or
get DTNS shows ad-free.

A special thanks to all our supporters–without you, none of this would be possible.

If you enjoy what you see you can support the show on Patreon, Thank you!

Send email to feedback@dailytechnewsshow.com

Show Notes

Apple Develops AI Model for China With Alibaba

Apple has developed a proprietary large language model for the China market in partnership with Alibaba, signaling a strategic shift to better compete against domestic rivals. This initiative, designed to integrate with Apple Intelligence, aims to navigate local regulatory challenges and restore Apple’s competitive edge in a critical market where the absence of AI features has previously impacted sales.

Read More — Reuters

France’s Highest Court Rejects Social Media Ban for Children Under 15

France’s highest court has declared a proposed ban on social media for children under 15 unconstitutional, ruling that it infringes upon youths’ freedom of speech and communication. This decision, a setback for President Emmanuel Macron, signals potential legal and technical challenges for global efforts to restrict social media access for younger teenagers. Despite this ruling, the French government intends to pursue revised legislation while other nations and the EU continue to explore similar regulatory approaches, highlighting the ongoing tension between protective digital policies and privacy concerns.

Read More — Bloomberg

Google Launches Gemini 3.7 Flash

Google has launched its new Gemini 3.7 Flash AI model, which offers improved performance in coding, debugging, and efficiency for app production while integrating enhanced safety features. Despite this release, the company continues to face pressure due to delays with its more powerful Gemini 3.5 Pro model and competition from rivals like OpenAI and Anthropic, leading to investor questions regarding Google’s AI roadmap and its ability to maintain a leading market position.

Read More — Bloomberg

White House Introduces Tariffs of Up to 100 Percent on Drones

The White House has introduced new tariffs of up to 100 percent on drones and associated components to enhance national security and encourage domestic manufacturing, or “on-shoring.” These measures, which target both heavy-duty and sensitive commercial drones, are expected to increase costs for consumers as vendors pass on the expenses. The policy aims to reduce dependence on Chinese-manufactured models, like those from DJI, though industry experts note the significant challenge of replicating China’s advanced drone supply chains and specialized engineering capabilities within the US.

Read More — Engadget

Flock Implements Stricter Data Retention Policies

Flock is implementing stricter data retention policies and mandating a new “Audit Assistance” tool designed to flag atypical search patterns for administrative review. Despite Flock’s claims of efficacy, privacy experts and critics from the ACLU and EFF argue that the company has provided insufficient technical details about how the tool works and lacks independent auditing evidence to prove it effectively prevents abuse, suggesting that stronger legal constraints on technology use are more critical for ensuring accountability.

Read More — TechCrunch

Heart Aerospace Completes First Flight of All-Electric X1 Prototype

Heart Aerospace has successfully completed the first flight of its all-electric X1 prototype, marking a significant milestone for the company as it eyes regional aviation markets. With interest from airlines like United and Air Canada, Heart aims to follow this success with the ES-30, a hybrid-electric model designed to replace traditional turboprops by 2031 through lower operational costs and enhanced reliability, though the company’s ambitious timeline remains dependent on future advancements in battery density and weight.

Read More — Engadget

Netflix Shutters Two Internal Game Studios

Netflix is shuttering two internal game studios, Night School Studio and Moonloot, as part of an ongoing restructuring of its gaming division. This decision follows a series of previous studio closures and divestments, signaling a consolidation of the company’s internal game development strategy. Moving forward, Netflix’s gaming focus is shifting toward four specific areas: kids, party, narrative, and mainstream titles, with increasing emphasis on cloud gaming and mobile-controller-based experiences.

Read More — Variety

Critical SAP Commerce Cloud Vulnerability Is Being Actively Exploited

A critical remote code execution vulnerability in SAP Commerce Cloud (CVE-2026-58231) is being actively exploited in the wild three days after patch release. Caused by improper authorization in the Data Hub Adapter, the flaw allows unauthenticated attackers to execute arbitrary code on e-commerce platforms. Despite no public proof-of-concept, researchers confirmed active attacks, underlining persistent security threats for SAP.

Read More — BleepingComputer

Uber Expands Robotaxi Strategy With Pony.ai

Uber is expanding its global robotaxi strategy by partnering with Pony.ai to deploy 2,000 self-driving vehicles across Europe and the Middle East, building on their existing pilot service in Zagreb. This collaboration, which includes plans for four additional European cities, is part of Uber’s broader effort to become a leading platform for autonomous commercialization by working with partners like WeRide and Baidu Apollo Go to scale operations in cities like Madrid and Tokyo, while gathering data to accelerate development against competitors like Waymo.

Read More — CNBC

X Tests Tool to Show Post-Limiting Labels

X is testing a tool giving select users visibility into post-limiting labels like spam or NSFW. Aimed at clarifying algorithmic “shadowbanning,” the complex data remains hard to interpret. Concurrently, X expanded open-sourcing its recommendation algorithm while continuing to withhold sensitive advertising and non-timeline data.

Read More — Engadget

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
A plataforma de comércio eletrónico SAP Commerce Cloud está a ser alvo de ataques que exploram a vulnerabilidade CVE-2026-58231, classificada com a gravidade máxima de 10.0. As tentativas de exploração começaram a atingir os sensores de teste apenas 3 dias após a tecnológica ter disponibilizado a co
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Apple
  • macOS

06 Aug 2026
Published
15 Aug 2026
Updated

CVSS
Pending
EPSS
0.31%

KEV

Description

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

Statistics

  • 1 Post
  • 22 Interactions

Last activity: 14 hours ago

Fediverse

Profile picture fallback

Dutch officials are warning that CVE-2026-65400, a macOS vulnerability that allows attackers to execute malicious code, is under active exploitation. (Apple patched the vulnerability recently.) The attacks come when screen sharing is turned on and port 5900 is exposed to the internet. Can anyone tell me how common it is for this port to be exposed? Does it happen automatically when screen sharing is enabled, or are other conditions required?

advisories.ncsc.nl/2026/ncsc-2

advisories.ncsc.nl/2026/ncsc-2

  • 16
  • 6
  • 0
  • 14h ago

Overview

  • Microsoft
  • Windows 10 Version 22H2

11 Aug 2026
Published
14 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
3.03%

KEV

Description

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Statistics

  • 1 Post
  • 34 Interactions

Last activity: 22 hours ago

Overview

  • Metabase
  • Metabase

10 Aug 2026
Published
12 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
10.40%

Description

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Nearly 14,000 Trezor customers had their data stolen via CVE-2026-72898, a critical Metabase zero-day exploited through logistics partner ShipMonk.

meterpreter.org/trezor-shipmon

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
> 注意喚起: MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)に関する注意喚起 (公開) https://www.jpcert.or.jp/at/2026/at260023.html
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • cozmoslabs
  • User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor

15 Aug 2026
Published
15 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check — when a registration is submitted with a 61–70 character username, WordPress core rejects it with a WP_Error object, but absint() coerces that object to the integer 1 before the error check can short-circuit execution, causing the plugin to bind and return a transient-backed autologin nonce tied to user ID 1. This makes it possible for unauthenticated attackers to log in as the site's Administrator account (user ID 1), resulting in full administrative takeover of the site.

Statistics

  • 2 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

CVE-2026-15826 (CVSS 9.8) is a User Profile Builder vulnerability letting attackers log in as WordPress admin. Over 40,000 sites affected; update to 3.16.5

securityonline.info/user-profi

  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback

CVE-2026-15826: CRITICAL flaw in User Profile Builder (≤3.16.4) allows auth bypass via type conversion error. Attackers gain admin (user ID 1) access. Restrict registration or disable plugin. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • Last hour

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts

Last activity: 18 hours ago

Fediverse

Profile picture fallback

📰 WordPress patches critical RCE flaw (CVE-2026-65640) for author-level users

WordPress 7.0.4 patches a critical RCE flaw (CVE-2026-65640, CVSS 8.8). Authenticated authors could take over sites using a malicious image file on servers with Imagick. Update your WordPress sites immediately! #WordPress #RCE #CyberSecurity

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
📢 WordPress 7.0.4 corrige une RCE via fichiers PostScript malveillants (CVE-2026-65640) Cet article rapporte la publication par WordPress d'un correctif pour une vulnérabilité d'exécution de code à distance (RCE) de haute sévérité… 🟢 vérification factuelle haute #RCE #WordPress #Cyberveille
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

14 Jul 2026
Published
14 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
3.97%

KEV

Description

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Statistics

  • 3 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

Atacantes aprovechan un bypass crítico en SharePoint tras publicarse un PoC

Se está explotando de forma activa CVE-2026-55040, un fallo crítico en Microsoft SharePoint Server que permite saltarse la autenticación tras la publicación de un PoC. La corrección pasa por aplicar los parches de julio de 2026, reducir exposición si el servicio está en Internet y revisar indicios de suplantación y actividad administrativa anómala.

unaaldia.hispasec.com/atacante

  • 0
  • 0
  • 0
  • 21h ago

Bluesky

Profile picture fallback
Microsoft SharePoint JWT Token Authentication Bypass Technical Analysis (CVE-2026-55040)
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
CVE-2026-55040: SharePoint Server Subscription Edition improper JWT validation lead to Arbitrary Account Login
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Linux
  • Linux

21 May 2026
Published
05 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.72%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ]

Statistics

  • 1 Post
  • 8 Interactions

Last activity: 18 hours ago

Bluesky

Profile picture fallback
Analysis and exploitation of GhostLock (CVE-2026-43499) nebusec.ai/research/ion... nebusec.ai/research/ion... #infosec
  • 3
  • 5
  • 0
  • 18h ago
Showing 1 to 10 of 61 CVEs