24h | 7d | 30d

Overview

  • Oracle Corporation
  • PeopleSoft Enterprise PeopleTools

11 Jun 2026
Published
04 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
9.44%

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Statistics

  • 7 Posts
  • 5 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Cybersecurity: ShinyHunters exploit a critical Oracle PeopleSoft flaw (CVE-2026-35273), bypassing WAFs and deploying SIDEEYE backdoor across sectors. Geopolitics/Tech: President Trump rejects AI regulation, prioritizing innovation despite global concerns (Sept 26, 2026).

#Cybersecurity #AnonNews_irc #News

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
  • 1
  • 4
  • 0
  • 11h ago
Profile picture fallback
Renewed exploitation of Oracle PeopleSoft CVE-2026-35273 enables unauthenticated remote code execution, with attackers bypassing WAF protections and deploying web shells across global sectors.
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
@mandiant.com UNC6240 bypasses WAFs to exploit PeopleSoft and deploy web shells, MeshAgent, and SIDEEYE. - IOCs: 5[.]199[.]162[.]157, 162[.]219[.]30[.]165, winmanage-me[.]network - #CVE202635273 #ShinyHunters #ThreatIntel
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
ShinyHunters resumed mass exploitation of Oracle PeopleSoft CVE-2026-35273, bypassing WAF rules with a percent-encoded path and deploying web shells, Neo-ReGeorg tunnels, and MeshAgent across multiple sectors. #ShinyHunters #OraclePeopleSoft #UNC6240
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Google warns of renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft by ShinyHunters-linked group UNC6240 Attackers bypass WAF rules using […]
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
ShinyHunters is using URL encoding to bypass WAF rules and keep exploiting Oracle PeopleSoft CVE-2026-35273, deploying web shells and backdoors against education, healthcare, and government targets. #ShinyHunters #OraclePeopleSoft #UNC6240
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • WordPress
  • WordPress

22 Sep 2026
Published
26 Sep 2026
Updated

CVSS
Pending
EPSS
18.17%

Description

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 20 hours ago

Fediverse

Profile picture fallback

WordPress 7.1.1に更新したばかりでもCVE-2026-87902への対応が必要です。
7.1.1で修正されたClick2Shellとは別のWordPressコアの脆弱性です。
未ログインの第三者が細工したpagenameを送ることで条件次第でテーマ外のPHPファイルをテンプレートとして読み込ませられます。
コード実行にはテーマの構造や悪用できるPHPファイル、PHP設定など追加の条件があります。
「ダッシュボード」→「更新」で7.1系は7.1.2、旧系列は対応する修正版が適用済みか確認を。
公開当日から攻撃リクエストが観測されています。更新前の影響が気になる場合はアクセスログや不審なPHPファイルも調べてください。
chunlog.jp/wordpress-7-1-2-cve
#WordPress #PHP #セキュリティ

  • 0
  • 1
  • 0
  • 20h ago
Profile picture fallback
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a WordPress Core flaw, tracked as CVE-2026-87902 (CVSS score of 9.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-87902 allows an unauthenticated attacker to make the get_page_template() function include a readable local […]
U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • patriksimek
  • vm2

27 Sep 2026
Published
27 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
Pending

KEV

Description

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-string boundary. Untrusted guest code can therefore require the allowlisted module (e.g. `foo`) and then require the absolute path of a non-allowlisted sibling whose path merely shares the resolved prefix (e.g. `.../node_modules/foo2/index.js`); the sibling passes `isPathAllowedForModule` and is loaded through `hostRequire`, so its top-level code runs in the host process before the exports are wrapped with `vm.readonly`, resulting in a sandbox escape and arbitrary code execution in the host context.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

CVE-2026-100721: CRITICAL auth bypass in vm2 <3.12.2's NodeVM external-module resolver. Sandbox escape & arbitrary code exec possible. Upgrade to 3.12.2+ ASAP. radar.offseq.com/threat/vm2-be

  • 1
  • 1
  • 0
  • Last hour

Overview

  • cyberlord92
  • miniOrange OTP Login, Verification and SMS Notifications

26 Sep 2026
Published
26 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as sufficient authentication whenever the unauthenticated, unverified POST parameter mo_wp_login_intent is submitted with the value otp, causing mo_get_user() to skip wp_authenticate_username_password() and resolve a WP_User purely from a username lookup. This makes it possible for unauthenticated attackers to log in as any existing administrator account by supplying only a known username and an empty password alongside mo_wp_login_intent=otp, with no password or OTP verification required. Exploitation is conditional on a site administrator having simultaneously enabled the following plugin options: WP Login OTP, Login with Only OTP, Allow Users to Login with Username and Password, and Admin OTP Bypass.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

CVE-2026-85984: CRITICAL auth bypass in miniOrange OTP Login plugin ≤5.5.5. Attackers can log in as admin with just a username if certain options are enabled. Disable risky settings and check vendor guidance. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 3h ago

Overview

  • Wikimedia Foundation
  • Mediawiki - ExternalData Extension

25 Sep 2026
Published
26 Sep 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.95%

KEV

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 21 hours ago

Fediverse

Profile picture fallback

Mediawiki ExternalData Extension <3.7 has a CRITICAL OS Command Injection vuln (CVE-2026-100382). Unauthenticated attackers could run arbitrary OS commands. No exploits yet. Restrict access, monitor activity. radar.offseq.com/threat/improp

  • 0
  • 1
  • 0
  • 21h ago

Overview

  • SolarWinds
  • Access Rights Manager

17 Sep 2026
Published
18 Sep 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.69%

KEV

Description

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

Statistics

  • 2 Posts

Last activity: 11 hours ago

Bluesky

Profile picture fallback
Master Key Included: Detecting SolarWinds ARM CVE-2026-28326
  • 0
  • 0
  • 1
  • 11h ago

Overview

  • edgelesssys
  • contrast

27 Sep 2026
Published
27 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.1)
EPSS
Pending

KEV

Description

Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI and the Coordinator (or between the Coordinator and an attested component) and forge reports or extract secrets from any single TEE machine under their physical control can relay such a report to impersonate a Contrast Coordinator or a Contrast workload, defeating identity verification in Contrast's attested TLS (aTLS).

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

CVE-2026-100835: Contrast <1.16.0 faces CRITICAL remote attestation relay attacks. Any valid TEE attestation report is accepted, risking trust bypass. Upgrade ASAP. radar.offseq.com/threat/contra

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Red Hat
  • Exploit Intelligence
  • exploit-intelligence/agent-client-rhel9

18 Sep 2026
Published
18 Sep 2026
Updated

CVSS
Pending
EPSS
0.42%

KEV

Description

A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This vulnerability can lead to Cross-Site Scripting (XSS) and JSON Injection, potentially allowing a remote attacker to execute arbitrary code in a user's browser or manipulate data.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CVE-2026-93432: Quarkus Qute XSS/JSON injection via eval sub-templates. CVSS 6.1, no patch yet. Audit your templates and watch for updates. valtersit.com/cve/CVE-2026-934 #CVE #infosec #Quarkus

  • 0
  • 0
  • 0
  • 5h ago

Overview

  • OISF
  • suricata

18 Sep 2026
Published
25 Sep 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
0.41%

KEV

Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fully reset state when processing Content-Type: message/rfc822 encapsulation. An outer MIME part's encoding or filename state can leak into the inner message, allowing crafted mail to evade detections based on file.data, file.name, or extracted URLs when SMTP MIME decoding is enabled. This issue is fixed in version 8.0.6.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

CVE-2026-57229 Suricata SMTP MIME parser state leak lets crafted mail evade file.data, file.name and URL detections. CVSS 5.3, no patch yet. Isolate or review SMTP MIME decoding now. valtersit.com/cve/CVE-2026-572 #CVE #Suricata #infosec

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • IBM
  • MQ for HPE NonStop

18 Sep 2026
Published
22 Sep 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.44%

KEV

Description

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.

Statistics

  • 1 Post

Last activity: 16 hours ago

Fediverse

Profile picture fallback

CVE-2026-11727: IBM MQ C client DoS, possible RCE, via unvalidated queue manager responses. CVSS 8.1, unpatched. Apply mitigations now. valtersit.com/cve/CVE-2026-117 #CVE #infosec #IBM

  • 0
  • 0
  • 0
  • 16h ago
Showing 1 to 10 of 35 CVEs