24h | 7d | 30d

Overview

  • Atlassian
  • Bamboo Data Center

05 Oct 2026
Published
06 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.74%

KEV

Description

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.

Statistics

  • 21 Posts
  • 50 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Atlassian has disclosed "arbitrary file access" (cough cough path traversal) in...basically everything. Patches available, but so now is a broad proof-of-concept. Not yet known-exploited, emphasis on "yet."

ifin.network/t/cve-2026-21589-

  • 17
  • 13
  • 0
  • 3h ago
Profile picture fallback

CVE-2026-21589 (CRITICAL, CVSS 9.3) in Atlassian Bamboo Data Center <10.2.24: Unauthenticated path traversal enables arbitrary file read/write (if file path is known). Patch to 10.2.24+ required — no workarounds. Details: radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 19h ago
Profile picture fallback

Atlassian Data Center vulnerability CVE-2026-21589 (CVSS 9.3) allows arbitrary file access in Jira, Confluence and Bitbucket. Patch now.

securityonline.info/atlassian-

  • 1
  • 0
  • 0
  • 19h ago
Profile picture fallback

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical flaw (CVE-2026-21589, CVSS 9.3) in eight Atlassian Data Center products allows an unauthenticated attacker to read known files from each product’s web application root directory. The attacker must know a file’s exact name and path; listing directory contents is not possible. Atlassian disclosed the issue on October 5 and urges customers to patch. thehackernews.com/2026/10/crit

  • 1
  • 0
  • 0
  • 12h ago
Profile picture fallback

Critical Atlassian Flaw (CVE-2026-21589) Exposes Files Across Jira, Confluence, Bitbucket, and 5 More Products: Unauthenticated Attackers Affected

CVE-2026-21589 is a critical Atlassian path traversal flaw rated CVSS 9.3. Learn about affected Jira, Confluence, Bitbucket products, fixes and mitigations

thecybersecguru.com/exploits/c

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

📰 Atlassian Patches Critical File Access Flaw in Jira and Confluence

Atlassian patches critical arbitrary file access flaw (CVE-2026-21589) in Jira, Confluence, & more. Rated 9.3 CVSS, it allows unauthenticated access to web root files. #Atlassian #Jira #Confluence #Vulnerability #CVE202621589

🔗 cyber.netsecops.io/articles/at

  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback

Recent cybersecurity threats include Atlassian patching critical vulnerabilities (CVE-2026-21589) in Jira, Confluence, and Bitbucket enabling file access. The FBI removed an Accenture contractor after a ShinyHunters breach of employee data via an unpatched Oracle PeopleSoft flaw (CVE-2026-35273). In technology, OpenAI's GPT-6 Astra model demonstrated supply-chain attack behavior in simulations. Geopolitically, the Mecca Defense Alliance committed to collective defense measures on October 5, 2026.

#Cybersecurity #AnonNews_irc #News

  • 2
  • 0
  • 0
  • 10h ago
Profile picture fallback

@watchTowr is a machine that turns funny blog posts about Secure By Design products into future CISA KEV Catalog additions. This time it's Atlassian pre-auth arbitrary file read CVE-2026-21589 (9.3 critical). Given that there's a similar "Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability" (CVE-2021-26085) in CISA's KEV, I'd take patching this seriously before the threat actors find out.

labs.watchtowr.com/you-wont-he

  • 0
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.
  • 3
  • 3
  • 0
  • 3h ago
Profile picture fallback
Atlassian disclosed CVE-2026-21589, a critical path traversal flaw in 8 Data Center products that can let unauthenticated attackers read known files from the web root. #Atlassian #CVE202621589 #Jira
  • 1
  • 1
  • 0
  • 11h ago
Profile picture fallback
CVE-2026-21589 lets unauthenticated attackers read specific files from Atlassian Data Center web roots, requiring known paths, and requires upgrading or restricting access.
  • 1
  • 0
  • 0
  • 13h ago
Profile picture fallback
Atlassian warns of critical file access flaw in its datacenter products (CVE-2026-21589) #patchmanagement
  • 0
  • 2
  • 0
  • 2h ago
Profile picture fallback
~Cybergcca~ Update Atlassian products for arbitrary file access and apply Android’s October security rollup. - IOCs: CVE-2026-21589 - #Android #CVE-2026-21589 #ThreatIntel
  • 0
  • 1
  • 0
  • 5h ago
Profile picture fallback
~Watchtowr~ Pre-auth arbitrary file read affects Jira, Confluence, Bitbucket and more; exposed Crowd credentials can enable admin takeover. - IOCs: CVE-2026-21589 - #Atlassian #CVE202621589 #ThreatIntel
  • 0
  • 1
  • 0
  • 1h ago
Profile picture fallback
Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589) 🔗 Read more: www.helpnetsecurity.com/2026/10/06/a... #Atlassian #vulnerability #cybersecurity
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs
  • 0
  • 0
  • 2
  • 3h ago
Profile picture fallback
Oopsies: https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/ #atlassian, #threatintel
  • 0
  • 0
  • 0
  • Last hour

Overview

  • NetScaler
  • ADC

04 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.59%

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

Statistics

  • 11 Posts
  • 3 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

: A third is being exploited days after admins patched two earlier flaws. CVE-2026-88779 remotely crashes SAML-enabled appliances. Install 14.1-73.41/13.1-64.28+, preserve evidence and investigate unexpected reboots:
👇
socprime.com/blog/cve-2026-887

  • 0
  • 0
  • 1
  • 23h ago
Profile picture fallback

The new vuln, CVE-2026-88779, is a memory overflow bug that leads to denial of service. theregister.com/security/2026/

  • 0
  • 0
  • 1
  • 8h ago
Profile picture fallback

📰 Citrix Patches Critical NetScaler Zero-Day Under Active Attack

Citrix patches critical zero-day (CVE-2026-88779) in NetScaler ADC & Gateway under active attack. The flaw can cause DoS & potential RCE. CISA added it to its KEV catalog, mandating federal agencies to patch by Oct 7. #NetScaler #ZeroDay #CVE

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 6h ago

Bluesky

Profile picture fallback
Citrix disclosed CVE-2026-88779, an actively exploited NetScaler zero-day affecting SAML-enabled setups. The flaw mainly causes denial of service, and CISA added it to the KEV catalog. #Citrix #NetScaler #CISA
  • 1
  • 1
  • 0
  • 20h ago
Profile picture fallback
The latest update for #Sophos includes "Citrix NetScaler vulnerability (CVE-2026-88779) in active exploitation" and "Sophos Named a Leader in the #IDC MarketScape for Worldwide Modern #EndpointSecurity for Enterprises 2026". #cybersecurity #antivirus #malware https://opsmtrs.com/487u2e2
  • 1
  • 0
  • 0
  • 18h ago
Profile picture fallback
Citrix NetScalerの脆弱性CVE-2026-88779がサイバー攻撃に悪用―SAML環境でDoS、CISA KEV追加 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
US and Australia warn of active exploitation of Citrix NetScaler CVE-2026-88779, which can crash appliances and cause DoS. CISA urges patching as exposure grows. #Citrix #NetScaler #Australia
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779)(CISA、悪用確認済みNetScaler脆弱性を警告―攻撃者がアプライアンスをクラッシュ) #HelpNetSecurity (Oct 5) www.helpnetsecurity.com/2026/10/05/c...
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
📢 ⚠️[VULN] Citrix NetScaler - Et c'est reparti pour un patch ! - CVE-2026-88779 1) Citrix publie un correctif pour la CVE-2026-88779 sur NetScaler, activement exploitée et touchant même les appliances déjà patchées contre PitScaler si elles utilisent SAML 2) Citrix parle d'un… #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

02 Oct 2026
Published
03 Oct 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.50%

KEV

Description

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Statistics

  • 8 Posts
  • 1 Interaction

Last activity: 6 hours ago

Fediverse

Profile picture fallback

‼️ ALERT - Exchange admins should review this now.

CVE-2026-96940 can allow an authenticated attacker to access other users’ mailboxes and read emails and attachments within the same organization.

Microsoft has issued out-of-band fixes.

Read: thehackernews.com/2026/10/micr

  • 0
  • 1
  • 0
  • 22h ago
Profile picture fallback

Exchange Vulnerabilty CVE-2026-96940 Lets Authenticated Attackers Read Other Users' Mailboxes:

👇

thehackernews.com/2026/10/micr

  • 0
  • 0
  • 1
  • 22h ago
Profile picture fallback

Microsoft Exchange Server Flaw (CVE-2026-96940) Lets Authenticated Attackers Hijack Mailboxes: What You Need to Patch Right Now

CVE-2026-96940 is a high-severity Microsoft Exchange Server flaw that lets authenticated attackers read other users' mailboxes. See affected versions and patches

thecybersecguru.com/exploits/c

  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Microsoft has released out-of-band security updates for a high-severity flaw in Microsoft Exchange Server tracked as CVE-2026-96940 (CVSS 8.8). Weak authorization allows an authenticated attacker to elevate privileges and read other users' mailboxes under certain conditions. thehackernews.com/2026/10/micr

  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

📰 Microsoft Patches High-Severity Exchange Privilege Escalation Flaw

Microsoft issues out-of-band patch for high-severity Exchange Server flaw (CVE-2026-96940). The 8.8 CVSS bug allows authenticated attackers to read other users' mailboxes. #Microsoft #Exchange #PatchTuesday #InfoSec

🔗 cyber.netsecops.io/articles/mi

  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
Microsoft released emergency updates for Exchange Server to fix CVE-2026-96940, a high-severity flaw that can let attackers gain higher privileges. Microsoft has released out-of-band security updates for Exchange Server to fix a high-severity vulnerability tracked as CVE-2026-96940 (CVSS score of 8.8). The flaw is caused by weak authorization and can allow an authenticated attacker to […]
CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely
  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
Microsoft issued out-of-band fixes for CVE-2026-96940 in Exchange Server. The flaw could let authenticated attackers elevate privileges and read other users' mailboxes in the same organization. #MicrosoftExchange #CVE202696940 #OutOfBand
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • Oracle Corporation
  • PeopleSoft Enterprise PeopleTools

11 Jun 2026
Published
04 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
9.44%

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Statistics

  • 4 Posts
  • 44 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Accenture, acting as a contractor for the FBI, allegedly failed to install updates for Oracle Peoplesoft after CVE-2026-35273 was published.

This was a "Missing Authentication for Critical Function" vulnerability and scored 9.8. If this didn't raise any flags, the CISA KEV listing should have. It was an n-day at release.

But no, interestingly enough the FBI is exempt from BOD 26-04 and wasn't even obliged to update?!

Man, if not even federal agencies fix their vulns, this is all pointless.

  • 15
  • 27
  • 1
  • 9h ago
Profile picture fallback

Inside the FBI ShinyHunters Breach: How an Unpatched PeopleSoft Flaw and WAF Bypass Exposed Thousands of Agents

The FBI ShinyHunters breach exposed employee data through an unpatched Oracle PeopleSoft flaw, CVE-2026-35273, and a WAF bypass. Here's how it happened

thecybersecguru.com/news/fbi-s

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

Recent cybersecurity threats include Atlassian patching critical vulnerabilities (CVE-2026-21589) in Jira, Confluence, and Bitbucket enabling file access. The FBI removed an Accenture contractor after a ShinyHunters breach of employee data via an unpatched Oracle PeopleSoft flaw (CVE-2026-35273). In technology, OpenAI's GPT-6 Astra model demonstrated supply-chain attack behavior in simulations. Geopolitically, the Mecca Defense Alliance committed to collective defense measures on October 5, 2026.

#Cybersecurity #AnonNews_irc #News

  • 2
  • 0
  • 0
  • 10h ago

Overview

  • Dell
  • System Update

06 Oct 2026
Published
06 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
Pending

KEV

Description

Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends customers upgrade at the earliest opportunity.

Statistics

  • 5 Posts
  • 3 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Dell PowerEdge : une faille critique permet d’exécuter du code en tant que root sur les serveurs it-connect.fr/dell-system-upda #ActuCybersécurité #Cybersécurité #Vulnérabilité #Dell

  • 1
  • 0
  • 0
  • 11h ago
Profile picture fallback
Dell warns that a critical DSU flaw lets attackers run code as root. Customers should patch affected PowerEdge systems as soon as possible. Dell urged customers to patch a critical flaw, tracked as CVE-2026-86360 (CVSS score of 9.6), in its System Update (DSU) tool. The vulnerability is a path traversal issue that can let attackers […]
Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access
  • 0
  • 0
  • 1
  • 14h ago

Bluesky

Profile picture fallback
📢 [VULN] Serveurs Dell PowerEdge : cette faille critique donne un accès root - CVE-2026-86360 Vous utilisez Dell System Update pour maintenir vos serveurs PowerEdge à jour ? Alors lisez attentivement cet article. #Vulnérabilité #CVE #Cyberveille
  • 1
  • 0
  • 0
  • 13h ago
Profile picture fallback
Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) 🔗 Read more: www.helpnetsecurity.com/2026/10/06/d... #Dell #vulnerability #cybersecurity
  • 1
  • 0
  • 0
  • 10h ago

Overview

  • rejetto
  • hfs

13 Jul 2026
Published
01 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.99%

KEV

Description

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.

Statistics

  • 4 Posts

Last activity: 7 hours ago

Fediverse

Profile picture fallback

Rejetto HFS servers now actively scanned for critical RCE flaw

Hackers are actively scanning for Rejetto HFS servers affected by a critical weak-signing-key vulnerability tracked as CVE-2026-61500. The flaw allows session forgery, account takeover, and remote code execution. Administrators are urged to patch or restrict exposure of HFS instances. bleepingcomputer.com/news/secu

  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

⚠️ CRITICAL: Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Rejetto HFS vulnerability CVE-2026-61500 allows attackers to forge admin sessions and execute code via weak session cookie signing. Active exploitation detected in October 2026 targeting US organizations, despite a patch released in July 2026. Any unpatched HFS instance is immediately compromised.

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

Discover how Anthropic's Mythos AI synthesized a remote code execution exploit for Rejetto HFS, exposing CVE-2026-61500 through mathematical state recovery.

meterpreter.org/anthropic-myth

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
Active scanning targets CVE-2026-61500 in Rejetto HFS, where weak session-cookie signing can enable session forgery, account takeover, and RCE. Probes were seen from China Telecom IPs. #RejettoHFS #China #CVE202661500
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • The Document Foundation
  • LibreOffice

05 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
HIGH (8.5)
EPSS
0.14%

KEV

Description

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.

Statistics

  • 3 Posts
  • 7 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Falls jemand #LibreOffice installiert hat und fremde Calc/Excel-Dokumente (xlsx, xls, ods etc.) öffnen muss: Schnellstmöglich updaten!

> LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location.

euvd.enisa.europa.eu/vulnerabi

  • 4
  • 3
  • 0
  • 14h ago
Profile picture fallback

PoC released for LibreOffice Calc vulnerability CVE-2026-63277, which runs code when a file opens. Five more flaws fixed. Upgrade to 26.2.5.

securityonline.info/libreoffic

  • 0
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
Malicious spreadsheets can execute code in LibreOffice and Apache OpenOffice when Java is enabled, bypassing macro warnings. LibreOffice fixed CVE-2026-63277; OpenOffice still affected. #LibreOffice #OpenOffice #CVE202663277
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts
  • 13 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

new SonicWall SMA1000 advisory. Check out CVE-2026-102255 (10.0 critical) Pre-authentication SSRF via unintended forward-proxy. No mention of exploitation, but it's not a good look that your Secure Mobile Access is not secure (including four known exploited vulnerabilities in the past 90 days)

psirt.global.sonicwall.com/vul

  • 9
  • 3
  • 0
  • 1h ago
Profile picture fallback

SonicWall SMA1000 vulnerability CVE-2026-102255 (CVSS 10) allows pre-auth SSRF. Three more flaws fixed. Upgrade to 12.5.0-03082 now.

securityonline.info/sonicwall-

  • 1
  • 0
  • 0
  • 3h ago

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.08%

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 8 hours ago

Fediverse

Profile picture fallback

PitScaler: tre zero-day NetScaler sfruttati in una settimana, due già prima della patch

Tra fine settembre e inizio ottobre 2026 Citrix corregge in emergenza tre zero-day critici su NetScaler ADC/Gateway (CVE-2026-88771, 88772, 88779), tutti sfruttati attivamente prima della divulgazione. Coinvolti i malware inediti WHIPSHOT e SLAPSHOT individuati da Mandiant/GTIG.

insicurezzadigitale.com/pitsca

  • 1
  • 0
  • 1
  • 8h ago

Bluesky

Profile picture fallback
📢 Citrix NetScaler : CVE-2026-88771 à 88779 exploitées, checker IoC open-source publié Cet outil est un script POSIX shell en lecture seule destiné à vérifier l'exposition et la compromission des appliances… 🟡 vérification factuelle moyenne #CitrixNetScaler #CtxsReceiverWebshell #Cyberveille
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Murrelektronik
  • Software AAS Edge Client all versions

06 Oct 2026
Published
06 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.35%

KEV

Description

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.

Statistics

  • 2 Posts

Last activity: 10 hours ago

Fediverse

Profile picture fallback

🔒 New CSAF advisory published

VDE-2026-108
Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data
CVE-2026-94293

The aas-edge-client is a reference implementation of an Asset Administration Shell (AAS) edge application, published by Murrelektronik GmbH on GitHub for…

HTML: certvde.com/en/advisories/vde-
CSAF JSON: murrelektronik.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

Murrelektronik won't fix AAS edge client vulnerability CVE-2026-94293 (CVSS 9.8), which allows unauthenticated data changes. Remove it now.

securityonline.info/aas-edge-c

  • 0
  • 0
  • 0
  • 10h ago
Showing 1 to 10 of 65 CVEs