24h | 7d | 30d

Overview

  • Alibaba
  • Fastjson

23 Jul 2026
Published
23 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
0.41%

KEV

Description

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

Statistics

  • 4 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Hackers target US firms in FastJson RCE zero-day attacks

A critical RCE zero-day (CVE-2026-16723) in FastJson Java library versions 1.2.68-1.2.83 is actively exploited against U.S. firms across multiple sectors. Attackers can execute arbitrary code without user interaction. FastJson 1.x is unmaintained, leaving affected systems without patches.

threatnoir.com/focus

  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

Discover the critical Fastjson RCE CVE-2026-16723 vulnerability. Learn how attackers exploit Spring Boot applications and find mitigation strategies.

meterpreter.org/fastjson-rce-c

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

📰 Unpatched FastJson RCE Zero-Day (CVE-2026-16723) Actively Exploited

🚨 ACTIVE EXPLOITATION: A critical, unpatched RCE zero-day (CVE-2026-16723) in FastJson 1.x is being exploited in the wild. Affects versions 1.2.68-1.2.83. Users must migrate to FastJson2 or enable SafeMode now! #Java #ZeroDay #CyberAttack

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/un

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
パッチ未提供のFastjsonの脆弱性、攻撃に悪用される(CVE-2026-16723) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/46925/
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

14 Jul 2026
Published
28 Jul 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
1.05%

KEV

Description

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Ich hatte gestern über die Active Directory-Schwachstelle Certighost (CVE-2026-54121) berichtet. Heute warnt Microsoft davor.

borncity.com/blog/2026/07/27/c

  • 0
  • 1
  • 1
  • 22h ago
Profile picture fallback

Certighost AD CS vulnerability details and PoC code for CVE-2026-54121 are public. The flaw let a low-privileged user impersonate a Domain Controller.

securityonline.info/certighost

  • 0
  • 0
  • 0
  • 6h ago

Bluesky

Profile picture fallback
Windows Active Directory証明書サービスの脆弱性 Certighost CVE-2026-54121-AD CSを悪用してドメイン全体を掌握するPoC公開 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #cyberattack #脆弱性
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • vBulletin
  • vBulletin

27 Jul 2026
Published
28 Jul 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
1.27%

KEV

Description

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.

Statistics

  • 3 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

A critical vBulletin pre-auth RCE vulnerability, CVE-2026-61511, threatens unpatched forums. Learn how attackers exploit template math evaluation.

meterpreter.org/vbulletin-pre-

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
vBulletinに認証不要のRCE 脆弱性 CVE-2026-61511、公開PoCありで6.2.2への更新を推奨 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
📢 RCE non authentifiée dans vBulletin ≤ 6.2.1 via la méthode runMaths() (CVE-2026-61511) 📝 ## 🔍 Contexte Publié le 27 juillet 2026 sur le blog de r… https://cyberveille.ch/posts/2026-07-29-rce-non-authentifiee-dans-vbulletin-6-2-1-via-la-methode-runmaths-cve-2026-61511/ #CVE_2026_61511 #Cyberveille
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

14 May 2026
Published
19 Jun 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
5.64%

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Statistics

  • 3 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

A TA488 half-click exploit abuses CVE-2026-42897 in Outlook Web Access to drop OWAReaper, a stealthy implant that survives device reimaging.

securityonline.info/ta488-owar

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
TA488 is exploiting CVE-2026-42897 in Outlook Web Access to deploy OWAReaper, targeting government, telecom, finance, hospitality, and aerospace sectors with stealthy persistence and exfiltration. #USA #TA488 #OutlookWebAccess
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
The fresh evidence Proofpoint reports CVE-2026-42897 exploitation ending in OWAReaper, built to survive credential rotation and endpoint re-imaging.
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • JetBrains
  • TeamCity

27 Jul 2026
Published
28 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.65%

KEV

Description

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Statistics

  • 3 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

📰 JetBrains Patches Critical Unauthenticated RCE Flaw in TeamCity

🚨 CRITICAL ALERT: JetBrains patches CVE-2026-63077, a 9.8 CVSS unauthenticated RCE in TeamCity On-Premises. All versions affected. Exploit allows full server takeover. Upgrade immediately to prevent supply chain attacks! #TeamCity #CI/CD #CyberSecurity

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/je

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
JetBrains社がTeamCityオンプレミス版における認証不要の重大なリモートコード実行(RCE)の脆弱性(CVE-2026-63077)を修正 JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) #HelpNetSecurity (Jul 28) www.helpnetsecurity.com/2026/07/28/t...
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
📢 Vulnérabilité critique RCE non authentifiée dans TeamCity On-Premises (CVE-2026-63077) 📝 ## 🔍 Contexte Le 27 juillet 2026, JetBrains a publié sur son … https://cyberveille.ch/posts/2026-07-29-vulnerabilite-critique-rce-non-authentifiee-dans-teamcity-on-premises-cve-2026-63077/ #CI_CD #Cyberveille
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • checkpoint
  • Quantum Security Management

22 Jul 2026
Published
23 Jul 2026
Updated

CVSS
Pending
EPSS
69.97%

Description

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 8 hours ago

Fediverse

Profile picture fallback

CVE-2026-16232 is a SmartConsole authentication bypass in Check Point Security Management. Exploited in the wild, with a public PoC now available.

securityonline.info/check-poin

  • 0
  • 1
  • 0
  • 17h ago
Profile picture fallback

En las últimas 24 horas, expertos revelan nuevas amenazas en criptografía impulsadas por IA, vulnerabilidades críticas en Check Point, OpenWrt y NGINX que permiten ejecuciones remotas, una masiva filtración que compromete la privacidad en VPNs y recomendaciones clave de EE.UU. y Australia para proteger infraestructuras críticas. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 29/07/26 📆 |====

🔐 ANÁLISIS DE CRIPTOANÁLISIS CON MODELOS DE LENGUAJE

Investigadores de Anthropic, utilizando la vista previa de Claude Mythos, han descubierto nuevas técnicas para atacar algoritmos criptográficos. Este avance revela cómo los potentes modelos de inteligencia artificial pueden identificar vulnerabilidades en la criptografía tradicional, planteando importantes desafíos para la seguridad futura y la necesidad de fortalecer los sistemas criptográficos ante estas nuevas amenazas. Profundiza en este análisis y sus implicaciones para proteger tus datos en la era digital visitando esta fuente clave 👉 djar.co/jewM

🚨 ANÁLISIS TÉCNICO DE VULNERABILIDAD EN CHECK POINT SMARTCONSOLE (CVE-2026-16232)

Se ha identificado una vulnerabilidad crítica de bypass de autenticación en el proceso de inicio de sesión de SmartConsole, que afecta a los servidores de gestión de seguridad de Check Point. Esta falla permite que atacantes eludan mecanismos de seguridad y comprometan el control de los sistemas afectados. Conocer en detalle esta vulnerabilidad y sus mitigaciones es esencial para administradores y profesionales de seguridad. Descubre el análisis detallado aquí 👉 djar.co/huOngt

⚠️ FALLO CRÍTICO EN OPENWRT DHCPV6 PERMITE EJECUCIÓN DE CÓDIGO REMOTO

La versión 24.10.8 de OpenWrt corrige una falla grave (CVE-2026-53921) en el servicio odhcpd, causada por solicitudes DHCPv6 manipuladas que provocan un desbordamiento de pila. Esta vulnerabilidad podría permitir que atacantes no autenticados ejecuten código con privilegios de root, poniendo en riesgo la integridad de dispositivos y redes basadas en OpenWrt. Actualiza tu sistema y conoce cómo proteger tu infraestructura accediendo a los detalles aquí 👉 djar.co/HXTzQ

🔥 VULNERABILIDAD CRÍTICA EN NGINX PUEDE CAUSAR CAÍDAS Y EJECUCIÓN REMOTA DE CÓDIGO

F5 ha publicado un parche para CVE-2026-42533, un error de desbordamiento en el heap del módulo regex map de NGINX. Esta vulnerabilidad puede provocar la caída de procesos esenciales y, bajo ciertas configuraciones, permitir la ejecución remota de código malicioso, afectando la disponibilidad y seguridad de los servidores web. Aprende cómo detectar, mitigar y actualizar tu entorno para evitar incidentes graves consultando la información completa aquí 👉 djar.co/lxu8x

🔍 FILTRACIÓN MASIVA EN VPN PONE EN DUDA SUS RECLAMOS DE PRIVACIDAD

Una conocida VPN, que aseguraba no almacenar registros, ha expuesto 58 millones de logs de conexión junto con datos sensibles de usuarios, dispositivos y pagos. Esta brecha contradice directamente sus políticas de privacidad, poniendo en riesgo la seguridad y anonimato de millones de usuarios. Conoce los detalles de esta filtración y cómo proteger tu privacidad digital aquí 👉 djar.co/LZurv

🛡️ CISA Y SOC DELGADOS DE AUS EMITEN RECOMENDACIONES PARA AISLAR SISTEMAS VITALES EN CIBERATAQUES

Las agencias de seguridad cibernética de EE. UU. y Australia han publicado guías para que las organizaciones que gestionan infraestructuras críticas puedan aislar sistemas tecnológicos esenciales durante ataques cibernéticos, minimizando daños y garantizando la continuidad operativa. Este consejo es vital para proteger sectores estratégicos frente a amenazas persistentes. Consulta las mejores prácticas para blindar tus sistemas aquí 👉 djar.co/HPgGvv

👨‍💻 ARCANUM SECURITY: CAPACITACIÓN Y CONSULTORÍA DE VANGUARDIA EN CIBERSEGURIDAD

La firma liderada por Jason Haddix ofrece soluciones modernas en seguridad informática mediante capacitación especializada y consultoría estratégica. Su enfoque innovador ayuda a organizaciones a anticipar y neutralizar amenazas, fortaleciendo su postura de ciberseguridad. Explora sus servicios y cómo pueden ayudarte a proteger tu empresa visitando su sitio oficial 👉 djar.co/Em1CSB

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
CVE-2026-16232 enables unauthenticated remote attackers to obtain SmartConsole application tokens and authenticate with full administrative privileges on vulnerable Check Point management servers.
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 3 Posts

Last activity: 5 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

OpenWrt released a critical patch (v24.10.8) for CVE-2026-53921, a stack overflow in the DHCPv6 service (odhcpd) that allows unauthenticated remote code execution as root. Any unpatched OpenWrt device is exploitable by sending crafted DHCPv6 packets. This affects routers and edge devices across ent…

threatnoir.com/focus

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

En las últimas 24 horas, expertos revelan nuevas amenazas en criptografía impulsadas por IA, vulnerabilidades críticas en Check Point, OpenWrt y NGINX que permiten ejecuciones remotas, una masiva filtración que compromete la privacidad en VPNs y recomendaciones clave de EE.UU. y Australia para proteger infraestructuras críticas. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 29/07/26 📆 |====

🔐 ANÁLISIS DE CRIPTOANÁLISIS CON MODELOS DE LENGUAJE

Investigadores de Anthropic, utilizando la vista previa de Claude Mythos, han descubierto nuevas técnicas para atacar algoritmos criptográficos. Este avance revela cómo los potentes modelos de inteligencia artificial pueden identificar vulnerabilidades en la criptografía tradicional, planteando importantes desafíos para la seguridad futura y la necesidad de fortalecer los sistemas criptográficos ante estas nuevas amenazas. Profundiza en este análisis y sus implicaciones para proteger tus datos en la era digital visitando esta fuente clave 👉 djar.co/jewM

🚨 ANÁLISIS TÉCNICO DE VULNERABILIDAD EN CHECK POINT SMARTCONSOLE (CVE-2026-16232)

Se ha identificado una vulnerabilidad crítica de bypass de autenticación en el proceso de inicio de sesión de SmartConsole, que afecta a los servidores de gestión de seguridad de Check Point. Esta falla permite que atacantes eludan mecanismos de seguridad y comprometan el control de los sistemas afectados. Conocer en detalle esta vulnerabilidad y sus mitigaciones es esencial para administradores y profesionales de seguridad. Descubre el análisis detallado aquí 👉 djar.co/huOngt

⚠️ FALLO CRÍTICO EN OPENWRT DHCPV6 PERMITE EJECUCIÓN DE CÓDIGO REMOTO

La versión 24.10.8 de OpenWrt corrige una falla grave (CVE-2026-53921) en el servicio odhcpd, causada por solicitudes DHCPv6 manipuladas que provocan un desbordamiento de pila. Esta vulnerabilidad podría permitir que atacantes no autenticados ejecuten código con privilegios de root, poniendo en riesgo la integridad de dispositivos y redes basadas en OpenWrt. Actualiza tu sistema y conoce cómo proteger tu infraestructura accediendo a los detalles aquí 👉 djar.co/HXTzQ

🔥 VULNERABILIDAD CRÍTICA EN NGINX PUEDE CAUSAR CAÍDAS Y EJECUCIÓN REMOTA DE CÓDIGO

F5 ha publicado un parche para CVE-2026-42533, un error de desbordamiento en el heap del módulo regex map de NGINX. Esta vulnerabilidad puede provocar la caída de procesos esenciales y, bajo ciertas configuraciones, permitir la ejecución remota de código malicioso, afectando la disponibilidad y seguridad de los servidores web. Aprende cómo detectar, mitigar y actualizar tu entorno para evitar incidentes graves consultando la información completa aquí 👉 djar.co/lxu8x

🔍 FILTRACIÓN MASIVA EN VPN PONE EN DUDA SUS RECLAMOS DE PRIVACIDAD

Una conocida VPN, que aseguraba no almacenar registros, ha expuesto 58 millones de logs de conexión junto con datos sensibles de usuarios, dispositivos y pagos. Esta brecha contradice directamente sus políticas de privacidad, poniendo en riesgo la seguridad y anonimato de millones de usuarios. Conoce los detalles de esta filtración y cómo proteger tu privacidad digital aquí 👉 djar.co/LZurv

🛡️ CISA Y SOC DELGADOS DE AUS EMITEN RECOMENDACIONES PARA AISLAR SISTEMAS VITALES EN CIBERATAQUES

Las agencias de seguridad cibernética de EE. UU. y Australia han publicado guías para que las organizaciones que gestionan infraestructuras críticas puedan aislar sistemas tecnológicos esenciales durante ataques cibernéticos, minimizando daños y garantizando la continuidad operativa. Este consejo es vital para proteger sectores estratégicos frente a amenazas persistentes. Consulta las mejores prácticas para blindar tus sistemas aquí 👉 djar.co/HPgGvv

👨‍💻 ARCANUM SECURITY: CAPACITACIÓN Y CONSULTORÍA DE VANGUARDIA EN CIBERSEGURIDAD

La firma liderada por Jason Haddix ofrece soluciones modernas en seguridad informática mediante capacitación especializada y consultoría estratégica. Su enfoque innovador ayuda a organizaciones a anticipar y neutralizar amenazas, fortaleciendo su postura de ciberseguridad. Explora sus servicios y cómo pueden ayudarte a proteger tu empresa visitando su sitio oficial 👉 djar.co/Em1CSB

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Microsoft
  • Windows 10 Version 1809

14 Jul 2026
Published
28 Jul 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.27%

KEV

Description

Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Statistics

  • 2 Posts
  • 5 Interactions

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2026-50469 - ProjFS File Delete bad-jubies.github.io/projected-fi... #windows #vulnerability #exploitation #exploit #cve #informationsecurity
  • 0
  • 1
  • 0
  • 3h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts
  • 4 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

RE: christine-seeman.com/cve-2026-

Patch your #rails there's a new CVE out there specifically about active storage and if your app accepts image uploads.

#ruby #rubyonrails

  • 2
  • 2
  • 0
  • 1h ago

Bluesky

Profile picture fallback
深刻度「緊急」のRails脆弱性「KindaRails2Shell」(CVE-2026-66066)の概要と対応指針 - GMO Flatt Security Blog https://blog.flatt.tech/entry/kindarails2shell_rails
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Pending

08 Jul 2013
Published
06 Aug 2024
Updated

CVSS
Pending
EPSS
78.57%

KEV

Description

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

Statistics

  • 2 Posts

Last activity: 17 hours ago

Bluesky

Profile picture fallback
36,000+ internet-exposed BMCs were found running IPMI, and nearly 25,000 leaked password hashes before login due to CVE-2013-4786. Offline cracking could expose weak or factory-set passwords. #IPMI #BMC #HPEiLO
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Researchers hacked thousands of data centers using a 20-year-old vulnerability, CVE-2013-4786, affecting BMCs. They exposed 24,650 systems and recovered many passwords using common wordlists. The issue affects Supermicro and HPE servers, posing significant security risks.
  • 0
  • 0
  • 0
  • 17h ago
Showing 1 to 10 of 53 CVEs