24h | 7d | 30d

Overview

  • Linux
  • Linux

04 Aug 2026
Published
04 Aug 2026
Updated

CVSS
Pending
EPSS
0.16%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root pagetables"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately.

Statistics

  • 6 Posts
  • 23 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

Instale já a correção para vulnerabilidade em máquinas virtuais

Se você usa Proxmox ou apenas tem um VPS, atualize já seu sistema. O problema permite o escape de máquinas virtuais e acesso à máquina física.

Se usa Debian, saiu o kernel 6.12.101-1 que corrige o problema. O Proxmox também já lançou atualização mesmo para quem não é assinante com o kernel 7.0.14-9.

:debian: security-tracker.debian.org/tr
:xp_secure_server: forum.proxmox.com/threads/prox
:xp_sys_info: cve.org/CVERecord?id=CVE-2026-
:github: github.com/V4bel/Zapscape

@fediadminbr

#FediAdminBR #MastoAdmin

  • 8
  • 9
  • 0
  • 11h ago
Profile picture fallback

「Zapscape KVMの新たな脆弱性により、特権を持つL1ゲストコードがLinuxホストに漏洩する可能性 」: #TheHackerNews

「Linuxカーネルの新たな脆弱性「Zapscape」 により、L1ゲスト仮想マシン(VM)内でカーネル権限を持つ攻撃者がKVM分離を回避し、ホスト上でコードを実行できる可能性があります。このリスクは、ネストされた仮想化が信頼できないゲストに公開されている場合に発生します。

この脆弱性は CVE-2026-64561 として追跡されており、ネストされたゲストメモリ変換に使用されるシャドウページテーブルを管理するKVM/x86のシャドウメモリ管理ユニット(MMU)に影響を与えます。

このバグを明らかにしたセキュリティ研究者の キム・ヒョヌ氏 は、実証されたエクスプロイト経路によって、カーネル権限、つまりroot権限でホスト上でコマンドを実行できると述べた。 」

thehackernews.com/2026/08/new-

#prattohome

  • 2
  • 2
  • 0
  • 23h ago
Profile picture fallback

MT @v4bel@x.com
💥 Introducing "Zapscape" (CVE-2026-64561)

A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU's recursive "ZAP" path. Can escape to the host on x86 public clouds that expose nested virtualization.

Details: zapscape.io

  • 2
  • 0
  • 0
  • 7h ago
Profile picture fallback

Zapscape: A Technical Deep-dive of the CVE-2026-64561 KVM Guest-to-Host Escape

Discover how Zapscape (CVE-2026-64561) exploits Linux KVM's Shadow MMU to achieve guest-to-host escape, including root cause, exploitation and more

thecybersecguru.com/news/zapsc

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback

A new Linux Kernel KVM vulnerability threatens cloud servers with virtual machine escape risks. Learn about CVE-2026-64561 and secure your host machine now.

securityexpress.info/linux-ker

  • 0
  • 0
  • 0
  • 19h ago

Bluesky

Profile picture fallback
ALERTA: Zapscape (CVE-2026-64561) é a nova vulnerabilidade que permite fuga de VMs KVM para o host Linux com privilégios ROOT. Saiba mais.-> tinyurl.com/mr3w8ky7
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • WordPress
  • WordPress

07 Aug 2026
Published
07 Aug 2026
Updated

CVSS v4.0
HIGH (8.9)
EPSS
Pending

KEV

Description

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

Statistics

  • 6 Posts
  • 1 Interaction

Last activity: Last hour

Fediverse

Profile picture fallback

‼️ BREAKING - A newly discovered pre-auth XSS affects every version.

XSS2Shell (CVE-2026-64638) can run attacker-controlled JS in a site's origin without a login. With a logged-in Administrator, one click, and required deployment conditions, it can be chained to PHP code execution.

Update your WordPress sites ASAP 🠖 thehackernews.com/2026/08/new-

  • 0
  • 1
  • 0
  • 14h ago
Profile picture fallback

New WordPress Pre-Authentication XSS Could Lead to PHP Code Execution, Patch Immediately

Learn how CVE-2026-64638 affects WordPress, why the pre-authentication XSS is dangerous, how researchers chained it to PHP code execution using XSS2Shell

thecybersecguru.com/news/wordp

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

: A Critical pre-auth to RCE vulnerability chain (CVE-2026-64638) dubbed is affecting all versions of WordPress Core. This vulnerability was discovered by AI (@pwn_ai). Patch to v7.0.3 ASAP - older versions backported:
👇
thehackernews.com/2026/08/new-

  • 0
  • 0
  • 1
  • 8h ago
Profile picture fallback

🚨 WordPress patches XSS2Shell flaw that could lead to server code execution

CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen.

The XSS itself requires no account. Researchers at pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page.

A successful chain could potentially allow attackers to:

• Create API credentials
• Gain authenticated REST access
• Upload malicious plugin files
• Execute PHP on the server
• Access WordPress secrets and database credentials

WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch.

NHS England says exploitation is likely following the release of technical details and a PoC.

WordPress has not reported confirmed exploitation in the wild as of August 7.

Update immediately.

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
pwn.ai/blog/xss2shell

  • 0
  • 0
  • 0
  • Last hour

Overview

  • Linux
  • Linux

04 Aug 2026
Published
08 Aug 2026
Updated

CVSS
Pending
EPSS
0.18%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed transport (->ipaddr, ->state) and plants the dangling pointer into asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping only the pointer that is no longer on the list, removes every real transport, leaving the association with a transport_count of 0 and primary_path/active_path pointing at freed memory. Reject a DEL-IP that targets the transport the ASCONF is being processed against, mirroring the existing source-address guard, so the wildcard branch can never reuse a freed transport.

Statistics

  • 2 Posts
  • 20 Interactions

Last activity: 11 hours ago

Bluesky

Profile picture fallback
Linux-SCTP-Schwachstelle CVE-2026-64564: Update für Root- und Container-Escape-Risiko www.it-boltwise.de/linux-sctp-s... #Linux #LinuxNews #LinuxDE #LinuxNewsDE #LinuxEU #LinuxNewsEU #EULE #EULEde
  • 7
  • 13
  • 0
  • 13h ago
Profile picture fallback
CVE-2026-64564 (SCTPhantom) is a use-after-free bug in Linux’s SCTP networking code that can escalate to full root access and container […]
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • JetBrains
  • TeamCity

27 Jul 2026
Published
06 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.01%

Description

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 11 hours ago

Bluesky

Profile picture fallback
We have published our @rapid7.com analysis of CVE-2026-63077, an unauth RCE in JetBrains TeamCity that was disclosed last week and already added to KEV as being exploited in the wild. This one has a gnarly gadget chain and a polyglot SQL/JSP payload. Full analysis/PoC: www.rapid7.com/blog/post/ra...
  • 1
  • 0
  • 0
  • 11h ago
Profile picture fallback
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
PoC for CVE-2026-63077 here: github.com/sfewer-r7/CV...
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • WebPros
  • cPanel

31 Jul 2026
Published
07 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.56%

KEV

Description

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Statistics

  • 2 Posts

Last activity: 21 hours ago

Bluesky

Profile picture fallback
cPanel&WHMにデータベース権限昇格の脆弱性、認証済みユーザーが管理者権限相当の操作が可能に(CVE-2026-58048) rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
The latest update for #Indusface includes "CVE-2026-58048: cPanel & WHM Database Privilege Escalation Vulnerability" and "SwyftComply AI: How We Turn Vulnerability Flood Into Audit-Ready Protection". #cybersecurity #infosec https://opsmtrs.com/3ySs2VF
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Takayuki Miyauchi
  • TinyMCE Templates
  • tinymce-templates

23 Jul 2026
Published
23 Jul 2026
Updated

CVSS v3.1
MEDIUM (4.3)
EPSS
0.18%

KEV

Description

Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

Statistics

  • 1 Post
  • 22 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CVE-2026-65535: Ranch Overflow

  • 7
  • 15
  • 0
  • 1h ago

Overview

  • N-able
  • N-central

02 Aug 2026
Published
04 Aug 2026
Updated

CVSS v4.0
HIGH (8.2)
EPSS
4.10%

Description

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Statistics

  • 2 Posts

Last activity: 6 hours ago

Bluesky

Profile picture fallback
While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the CISA KEV catalog on August 3, 2026.
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
~Cybergcca~ Canadian Cyber Centre warns of actively exploited N-able N-central CVEs and new Google Chrome vulnerabilities. - IOCs: CVE-2026-18577, CVE-2026-18556 - #Chrome #Nable #ThreatIntel
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Linux
  • Linux

29 Jul 2026
Published
05 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.12%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_timer_del() // Observes old leader p = pid_task(pid, pid_type); de_thread() switch_leader(); release_task(old_leader) __exit_signal(old_leader) sighand = lock(old_leader, sighand); posix_cpu_timers*_exit(); sighand = lock_task_sighand(p) unhash_task(old_leader); sh = lock(p, sighand) old_leader->sighand = NULL; unlock(sighand); (p->sighand == NULL) unlock(sh) return NULL; // Returns without action if(!sighand) return 0; free_posix_timer(); This is "harmless" unless the deleted timer was armed and enqueued in p->signal because on exec() a TGID targeted timer is inherited. As sys_timer_delete() freed the underlying posix timer object run_posix_cpu_timers() or any timerqueue related add/delete operations on other timers will access the freed object's timerqueue node, which results in an UAF. There is a similar problem vs. posix_cpu_timer_set(). For regular posix timers it just transiently returns -ESRCH to user space, but for the use case in do_cpu_nanosleep() it's the same UAF just that the k_itimer is allocated on the stack. Also posix_cpu_timer_rearm() fails to rearm the timer, which means it stops to expire. While debating solutions Frederic pointed out another problem: posix_cpu_timer_del(tmr) __exit_signal(p) posix_cpu_timers*_exit(p); unhash_task(p); p->sighand = NULL; sh = lock_task_sighand(p) sighand = p->sighand; if (!sighand) return NULL; lock(sighand); if (!sh) WARN_ON_ONCE(timer_queued(tmr)); On weakly ordered architectures it is not guaranteed that posix_cpu_timer_del() will observe the stores in posix_cpu_timers*_exit() when p->sighand is observed as NULL, which means the WARN() can be a false positive. Solve these issues by: 1) Changing the store in __exit_signal() to smp_store_release(). 2) Adding a smp_acquire__after_ctrl_dep() into the !sighand path of lock_task_sighand(). 3) Creating a helper function for looking up the task and locking sighand which does not return when sighand == NULL. Instead it retries the task lookup and only if that fails it gives up. 4) Using that helper in the three affected functions. #1/#2 ensures that the reader side which observes sighand == NULL also observes all preceeding stores, i.e. the stores in posix_cpu_timers*_exit() and the ones in unhash_task(). #3 ensures that the above described non-leader exec() situation is handled gracefully. When the task lookup returns the old leader, but sighand == NULL then it retries. In the non-leader exec() case the subsequent task lookup will observe the new leader due to #1/#2. In normal exit() scenarios the subsequent lookup fails. When the task lookup fails, the function also checks whether the timer is still enqueued and issues a warning if that's the case. Unfortunately there is nothing which can be done about it, but as the task is already not longer visible the timer should not be accessed anymore. This check also requires memory ordering, which is not provided when the first lookup fails. To achieve that the check is preceeded by a smp_rmb() which pairs with the smp_wmb() in write_seqlock() in __exit_signal(). That ensures that the stores in posix_cpu_timers*_exit() are visible. The history of the non-leader exec() issue goes back to the early days of posix CPU timers, which stored a pointer to the group leader task in the timer. That obviously fails when a non-leader exec() switches the leader. commit e0a70217107e ("posix-cpu-timers: workaround to suppress the problems with mt exec") added a temporary workaround for that in 2010 which surv ---truncated---

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 15 hours ago

Fediverse

Profile picture fallback

Tails 7.10.1 patches CVE-2026-64560 in the Linux kernel and expat library flaws that could let attackers deanonymize users and gain admin privileges.

securityonline.info/tails-7-10

  • 1
  • 1
  • 0
  • 17h ago
Profile picture fallback

Tails 7.10.1 patches CVE-2026-64560, a Linux kernel race condition letting a compromised Tor Browser gain root and deanonymize users via a malicious website.

meterpreter.org/tails-cve-2026

  • 1
  • 0
  • 0
  • 15h ago

Overview

  • Microsoft
  • Microsoft Teams

06 Aug 2026
Published
07 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.45%

KEV

Description

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 13 hours ago

Fediverse

Profile picture fallback

CVE-2026-65667 - Critical privilege escalation in Microsoft Teams. Missing authorization enables network-based elevation. CVSS 10. Patch unavailable - monitor for updates. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-656

  • 1
  • 0
  • 0
  • 13h ago

Overview

  • Linux
  • Linux

27 Jul 2026
Published
05 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.13%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guard preventing a generated nested action attribute from exceeding U16_MAX. An oversized generated container can thus be closed with a truncated nla_len. A later dump or teardown then walks a structurally different stream than the one that was validated. In particular, an oversized nested CLONE/CT action may cause subsequent bytes in the generated stream to be interpreted as independent actions. Keep the larger total-action-stream behavior, but make nested action close reject generated containers that do not fit in nla_len, and return the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse construction order before discarding failed wrappers, so resources copied into the rejected tails are released before the wrappers are removed. Most failed outer wrappers are discarded by truncating actions_len after child resources have been released. CHECK_PKT_LEN also trims its parent after branch resources are gone. SET/TUNNEL close failures unwind their known tun_dst ownership directly, and SET_TO_MASKED has no external ownership and truncates on close failure.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 9 hours ago

Fediverse

Profile picture fallback

📰 Linux Kernel Flaw "OVSwrap" Allows Root Privilege Escalation

New Linux kernel LPE flaw 'OVSwrap' (CVE-2026-64531) allows local users to gain root. The bug in Open vSwitch datapath poses a critical risk to multi-tenant and container environments. Patch now! #Linux #Kernel #Vulnerability #CyberSecurity

🔗 cyber.netsecops.io/articles/li

  • 1
  • 0
  • 0
  • 9h ago
Showing 1 to 10 of 46 CVEs