24h | 7d | 30d

Overview

  • N-able
  • N-central

02 Aug 2026
Published
04 Aug 2026
Updated

CVSS v4.0
HIGH (8.2)
EPSS
2.53%

Description

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Statistics

  • 10 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

ALERT: Active exploitation verified for CVE-2026-18577 in N-able N-central. Unauthenticated attackers can execute account takeovers via alternate path manipulation. Access our complete threat breakdown, SPL/KQL detection logic, and hardening guidance here: thecybermind.co/jily

  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback

URGENT C-SUITE BRIEF: Active exploitation verified on CISA KEV for CVE-2026-18577 (N-able N-central). Executive leadership must oversee immediate patch deployment, supply chain auditing, and trust model revalidation to safeguard organizational assets. Full strategic analysis: thecybermind.co/0156

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback

Geopolitical: Trump indicates ongoing talks with Iran for Strait of Hormuz reopening (Aug 3-4), though Tehran denies. Gaza operations persist.
Technology: SK hynix & Sandisk unveil HBF standard for AI memory (Aug 4). White House schedules AI safety talks (Aug 4).
Cybersecurity: CISA alerts to active exploitation of N-able N-central flaw (CVE-2026-18577) (Aug 3). Interpol: AI fuels over 55% of African cybercrime (Aug 3).
#AnonNews_irc #Cybersecurity #News

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
N-able says CVE-2026-18577 is being actively exploited in N-central hosted and on-prem servers before 2026.3. Hotfix 2026.3.1.7 is available for the auth bypass flaw. #Ncentral #CVE202618577 #Nable
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
CISAが既知の悪用された脆弱性を1件カタログに追加 CISA Adds One Known Exploited Vulnerability to Catalog #CISA (Aug 3) CVE-2026-18577 N-able N-central認証バイパス(代替パスまたはチャネルの使用)の脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
CISA added CVE-2026-18577 to KEV after reports of active exploitation, enabling authentication bypass and administrative takeover in N-able N-central.
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
Fresh exploitation signal CISA added N-central CVE-2026-18577 to KEV on evidence of active exploitation. N-able says instances below 2026.3.1 need the 2026.3.1.7 hotfix.
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
The latest update for #ArcticWolf includes "CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate #Patching" and "You Can't Buy Your Way Out of Downtime". #cybersecurity #infosec #networks https://opsmtrs.com/2ZFbaTl
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
CISA "added high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild" thehackernews.com/2026/08/cisa... "CVE-2026-18577 (CVSS score: 8.2) .. incomplete patching for CVE-2026-18556" #cybersec tech
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
~Cybergcca~ Six advisories covering critical vulnerabilities in N-able, IBM, Dell, WebPros, Tenable, and Check Point products, including an actively exploited N-able flaw. - IOCs: CVE-2026-18577, CVE-2026-58047, CVE-2026-18574 - ...
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Alibaba
  • Fastjson

23 Jul 2026
Published
23 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
0.41%

KEV

Description

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

Statistics

  • 2 Posts
  • 4 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

#news #noticias #actualidad

Un zero-day crítico en Fastjson abre la puerta a ataques remotos en servidores Java

Una vulnerabilidad crítica, CVE-2026-16723, se explota de forma activa en Fastjson 1.x para lograr ejecución remota de código en servidores que procesan JSON. La rama 1.x no tiene parche oficial, así que la contención pasa por activar SafeMode, usar una build noneautotype o migrar a fastjson2.

unaaldia.hispasec.com/un-zero-

  • 1
  • 3
  • 0
  • 8h ago

Bluesky

Profile picture fallback
📢 Exploitation active de CVE-2026-16723 dans Fastjson : RCE sans authentification SecurityWeek, publié le 28 juillet 2026. L'article rapporte l'exploitation active d'une vulnérabilité critique dans Fastjson, une bibliothèque Java de… 🟢 vérification factuelle haute #Fastjson #RCE #Cyberveille
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • WebPros
  • cPanel

31 Jul 2026
Published
01 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.50%

KEV

Description

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 8 hours ago

Bluesky

Profile picture fallback
A cPanel patch fixes CVE-2026-58048, which let authenticated users run SQL in MySQL/MariaDB root context, crossing privilege boundaries and enabling full administrative commands.
  • 1
  • 0
  • 0
  • 8h ago

Overview

  • GL.iNet
  • GL-MT3000

04 Aug 2026
Published
04 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
2.61%

KEV

Description

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

CVE-2026-18686 - Critical command injection in GL.iNet GL-MT3000 via nas-web.add_user. Public exploit, CVSS 9.8, unpatched. Restrict access and monitor now. #CVE #GLiNet #infosec

valtersit.com/cve/cve-2026-186

  • 0
  • 2
  • 0
  • 8h ago
Profile picture fallback

CVE-2026-18686: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated code execution possible — no patch yet. Limit admin interface exposure & monitor for abuse. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 2 hours ago

Fediverse

Profile picture fallback

📰 Thermo Fisher DNA Software Flaw Allows Undetectable Evidence Tampering

A critical flaw (CVE-2026-17583) in Thermo Fisher's forensic DNA software allows for nearly undetectable evidence tampering. The vulnerability impacts the integrity of the criminal justice system. Patches are available. #CyberSecurity #Forensics #DNA

🔗 cyber.netsecops.io/articles/fl

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
Thermo Fisher patched CVE-2026-17583, which could let attackers make nearly undetectable changes to Applied Biosystems DNA files before analysis.
  • 0
  • 1
  • 0
  • 9h ago

Overview

  • rails
  • rails

30 Jul 2026
Published
04 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.70%

KEV

Description

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

Statistics

  • 2 Posts

Last activity: 12 hours ago

Fediverse

Profile picture fallback

A critical KindaRails2Shell Rails RCE flaw (CVE-2026-66066) in Active Storage exposes servers to secret theft and remote code execution via image uploads.

meterpreter.org/kindarails2she

  • 0
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
Ruby on RailsのActive Storageにおけるリモートコード実行につながる脆弱性(CVE-2026-66066)に関する注意喚起 #JPCERTCC (Aug 3) www.jpcert.or.jp/at/2026/at26...
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • checkpoint
  • Security Management Server

03 Aug 2026
Published
03 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.99%

KEV

Description

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2026-18574: Check Pointの認証バイパスにより管理サーバーが侵害される CVE-2026-18574: Check Point Authentication Bypass Hits Management Server #DailyCyberSecurity (Aug 3) securityonline.info/cve-2026-185...
  • 1
  • 0
  • 0
  • 14h ago
Profile picture fallback
~Cybergcca~ Six advisories covering critical vulnerabilities in N-able, IBM, Dell, WebPros, Tenable, and Check Point products, including an actively exploited N-able flaw. - IOCs: CVE-2026-18577, CVE-2026-58047, CVE-2026-18574 - ...
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Zyxel
  • WAX650S firmware

04 Aug 2026
Published
04 Aug 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.95%

KEV

Description

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CVE-2026-6837 - Post-auth command injection in Zyxel WAX650S export-cgi. Admin RCE. CVSS 7.2. Unpatched - restrict admin access now. #CVE #Zyxel #infosec

valtersit.com/cve/CVE-2026-683

  • 1
  • 1
  • 0
  • 5h ago

Overview

  • GL.iNet
  • GL-MT3000

03 Aug 2026
Published
04 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
1.99%

KEV

Description

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 19 hours ago

Fediverse

Profile picture fallback

CVE-2026-18685: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated RCE possible. No patch yet — restrict access & monitor for abuse. Details: radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 19h ago

Overview

  • Xlight
  • Xlight FTP Server

29 Jul 2026
Published
29 Jul 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.62%

KEV

Description

Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length field passed directly to the GCM decrypt function, overwriting the stack cookie and return address to potentially achieve remote code execution before any authentication occurs.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Pre-Auth Stack Buffer Overflow Hits Xlight FTP Server (CVE-2026-67192)

securityonline.info/xlight-ftp

  • 1
  • 0
  • 0
  • 4h ago
Showing 1 to 10 of 64 CVEs