24h | 7d | 30d

Overview

  • Red Hat
  • Red Hat build of Keycloak 26.4
  • rhbk/keycloak-operator-bundle

18 Aug 2026
Published
20 Aug 2026
Updated

CVSS
Pending
EPSS
0.52%

KEV

Description

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

Statistics

  • 6 Posts
  • 10 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Note the recently disclosed CVE-2026-18963 for #Keycloak OIDC: thehackernews.com/2026/08/crit . It allows unauthorized users to take over any account on your server.
On the #Slackware #Forgejo instance forge.slackware.nl/ I have upgraded Keycloak to 26.7.2 to address this vulnerability.

  • 4
  • 3
  • 0
  • 1h ago
Profile picture fallback

⚠️ Critical Keycloak flaw enables account takeover

CVE-2026-18963 lets unauthenticated attackers reset any user's password, bypassing email verification.

🔗 read more: thehackernews.com/2026/08/crit

#ransomNews #cyberthreats #Keycloak

  • 1
  • 0
  • 0
  • 3h ago
Profile picture fallback

📰 Critical Keycloak Flaw (CVE-2026-18963) Allows Account Takeover

🚨 CRITICAL FLAW: Keycloak is vulnerable to CVE-2026-18963 (CVSS 9.1), allowing unauthenticated remote attackers to take over any account. Patches are available—update immediately! #Keycloak #Cybersecurity #Vulnerability #CVE #IAM

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 1
  • 0
  • 7h ago
Profile picture fallback

Geopolitical tensions rise as US-Iran dispute over Strait of Hormuz escalates; UK pledges long-range missile tech to Ukraine. Nvidia increases AI server prices over 15% due to memory costs. Critical Keycloak flaw (CVE-2026-18963) found allowing account takeovers, while Apple warns of mercenary spyware.

#AnonNews_irc #Cybersecurity #News

  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback

⚠️ CRITICAL: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Critical flaw in Keycloak (CVE-2026-18963, CVSS 9.1) allows unauthenticated attackers to reset any user password and take over accounts due to improper state validation in the password recovery flow. Any organization running Keycloak without patches is immediately at risk of account takeover on all…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.
  • 0
  • 1
  • 0
  • 6h ago

Overview

  • Zimbra
  • Collaboration

13 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
1.51%

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Statistics

  • 6 Posts
  • 11 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: CISA orders urgent patching of actively exploited Zimbra flaw

Zimbra Collaboration Suite (ZCS) has a critical unauthenticated RCE vulnerability (CVE-2026-73570) that is actively exploited in the wild. Any organization running ZCS is at immediate risk of full system compromise. CISA has mandated U.S. government agencies patch within three days.

threatnoir.com/focus

🤖 AI generated summary

  • 1
  • 0
  • 0
  • 3h ago
Profile picture fallback

CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: radar.offseq.com/threat/cisa-o

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
Alert! Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22. Top: US (41 IPs). Detection in collaboration with @CERT_Polska_en Public Dashboard: dashboard.shadowserver.org/statistics/c...
  • 1
  • 6
  • 0
  • 10h ago
Profile picture fallback
We also see at least 8200 CVE-2026-73570 unpatched instances (this does not mean exploitable as the vuln is in a non default config) dashboard.shadowserver.org/statistics/c... Check for compromise & update: wiki.zimbra.com/wiki/Zimbra_... CVE-2026-73570 is on CISA KEV www.cisa.gov/known-exploi...
  • 0
  • 2
  • 0
  • 10h ago
Profile picture fallback
Data in Compromised Website reporting tagged 'zimbra-compromised' with detail set to 'Artifact from probable CVE-2026-73570 compromise' www.shadowserver.org/what-we-do/n... Compromised Zimbra tracker: dashboard.shadowserver.org/statistics/c...
  • 0
  • 1
  • 0
  • 10h ago
Profile picture fallback
CISAが既知の悪用された脆弱性を1件カタログに追加 CISA Adds One Known Exploited Vulnerability to Catalog #CISA (Aug 21) CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OSコマンドインジェクションの脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Microsoft
  • Microsoft Entra

20 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
1.59%

KEV

Description

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Statistics

  • 3 Posts

Last activity: 8 hours ago

Fediverse

Profile picture fallback

Mysterien um Microsofts kritisches Sicherheitsloch in Entra ID

Am vorigen Donnerstag macht Microsoft (MS) ein riesiges Trara um eine höchst gefährliche Sicherheitslücke CVE-2026-69836 (Risiko 10 von 10) in Entra ID*. Ein entfernter, nicht autorisierter Angreifer könne durch Ausnutzung dieser Sicherheitslücke beliebigen Programmcode ausführen (RCE). Und die Lücke würde bereits für Angriffe ausgenutzt. Meldungen beispielsweise hier oder hier. Wie die Ausnutzung entdeckt wurde und wer vielleicht betroffen ist, verlautet MS nicht. Einen Tag später zieht MS die Auskunft "wird bereits ausgenutzt" zurück. Hä? Interessant ist auch, dass ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #backdoor #cloud #exploits #identität #Microsoft #sicherheit #unplugMicrosoft #UnplugTrump

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
Microsoft Entra IDの重大な脆弱性が実際に悪用される(CVE-2026-69836) Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) #HelpNetSecurity (Aug 21) www.helpnetsecurity.com/2026/08/21/m...
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
マイクロソフト、Entra IDの深刻なRCE脆弱性を修正(CVE-2026-69836) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47341/
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • NetScaler
  • ADC

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.40%

KEV

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Statistics

  • 2 Posts

Last activity: 19 hours ago

Bluesky

Profile picture fallback
Citrix、NetScalerの2脆弱性を修正 CVE-2026-19490はCVSS 9.3、認証回避のおそれ rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Citrixは、NetScalerの認証バイパスに関する重大な脆弱性(CVE-2026-19490)を修正するよう顧客に強く求めている Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) #HelpNetSecurity (Aug 21) www.helpnetsecurity.com/2026/08/21/c...
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Zscaler
  • Client Connector

24 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
Pending

KEV

Description

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

nvd.nist.gov/vuln/detail/CVE-2

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

  • 2
  • 2
  • 0
  • 3h ago

Overview

  • UTT
  • HiPER 1250GW

24 Aug 2026
Published
24 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.44%

KEV

Description

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 18 hours ago

Fediverse

Profile picture fallback

CRITICAL: Stack-based buffer overflow (CVE-2026-78169) in UTT HiPER 1250GW v3.2.7-210907-180535. Public exploit code available — no patch yet. Restrict device access & monitor /goform/aspRemoteApConfTempSend traffic. radar.offseq.com/threat/cve-20

  • 2
  • 1
  • 0
  • 18h ago

Overview

  • PostgreSQL

13 Aug 2026
Published
14 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.53%

KEV

Description

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

A PostgreSQL vulnerability (CVE-2026-14669, CVSS 8.8) with public PoC exploit code allows remote code execution via to_char. Update now.

securityonline.info/postgresql

  • 2
  • 0
  • 0
  • 8h ago

Overview

  • nltk
  • nltk

22 Aug 2026
Published
24 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.49%

KEV

Description

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

CVE-2026-63312 - Arbitrary local file read in NLTK StreamBackedCorpusView bypasses pathsec. CVSS 7.5. Exposes sensitive system files. Update to NLTK 3.10.0+. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-633

  • 1
  • 1
  • 0
  • 9h ago

Overview

  • nltk
  • nltk

22 Aug 2026
Published
24 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.11%

KEV

Description

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-63310 - MITM package injection flaw in NLTK downloader module. CVSS 7.1. Update NLTK to 3.9.3+ immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-633

  • 1
  • 1
  • 0
  • 10h ago

Overview

  • phoca.cz
  • Phoca Cart extension for Joomla

20 Aug 2026
Published
21 Aug 2026
Updated

CVSS v4.0
MEDIUM (5.3)
EPSS
0.32%

KEV

Description

Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart

GitHub: github.com/toanln-cov/CVE-2026

A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≤ 6.1.7 for Joomla.

The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.

The PoC demonstrates:

• Reflected XSS through crafted GET parameters
• Exploitation of vulnerable price filter inputs
• Attribute-context injection caused by missing htmlspecialchars() encoding
• No authentication requirement for exploitation
• Affected versions: PhocaCart ≤ 6.1.7
• Fixed version: PhocaCart 6.1.8

💥 No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.

  • 1
  • 1
  • 0
  • 3h ago
Showing 1 to 10 of 47 CVEs