Overview
- 0xJacky
- nginx-ui
Description
Statistics
- 13 Posts
- 4 Interactions
Fediverse
CVE-2026-33032: Authentifizierungslücke in nginx-ui wird aktiv ausgenutzt
Eine fehlende Middleware-Zeile im webbasierten Nginx-Verwaltungstool nginx-ui genügt, damit Angreifer im Netzwerk sämtliche Konfigurationsdateien manipulieren und den Webserver übernehmen können – ganz ohne Anmeldedaten
A critical vulnerability in Nginx UI is being actively exploited, allowing attackers to gain complete control over affected servers.
Nginx UI (nginx-ui) is an open source, web-based management tool for the Nginx web server.
The flaw, tracked as CVE-2026-33032, was recently fixed in version 2.3.4.
⚠️ CRITICAL: Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
CVE-2026-33032 is a critical authentication bypass in nginx-ui that allows unauthenticated attackers to modify Nginx configurations and take over the service completely. An estimated 2,689 vulnerable instances remain exposed globally and active exploitation is confirmed in the wild. Any unpatched n…
📰 Critical Auth Bypass in nginx-ui (CVE-2026-33032) Actively Exploited for Full Nginx Takeover
🚨 CRITICAL FLAW: nginx-ui is being actively exploited via an auth bypass (CVE-2026-33032, CVSS 9.8). Unauthenticated attackers can gain full RCE. Patch to version 2.3.4+ immediately! #nginx #CyberSecurity #Vulnerability
Bluesky
Overview
- Cisco
- Cisco Webex Meetings
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
Cisco Webex – CVE-2026-20184 : cette faille critique nécessite une action de l’admin https://www.it-connect.fr/cisco-webex-cve-2026-20184-cette-faille-critique-necessite-une-action-de-ladmin/ #ActuCybersécurité #Vulnérabilités #Cybersécurité #Cisco
Bluesky
Overview
- Microsoft
- Windows Server 2012 R2
Description
Statistics
- 2 Posts
- 1 Interaction
Bluesky
Overview
- Microsoft
- Microsoft Defender Antimalware Platform
Description
Statistics
- 2 Posts
Fediverse
Fully exploitable Windows Defender vulnerability with full source code public for >8 days no CVE assigned so far (BlueHammer).
Writeup: https://hackingpassion.com/bluehammer-windows-defender-zero-day/
Full source code: https://github.com/Nightmare-Eclipse/BlueHammer
/cc @bsi Was ist eigentlich der "Prozess" für vollständig öffentliche Lücken zu denen es seit über einer Woche noch nicht einmal eine CVE Nummer gibt?
Edit: Patch and CVE number CVE-2026-33825 available by now. Took 6 days though.
Overview
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
Critical Fortinet FortiClient EMS Vulnerability CVE-2026-21643 Actively Exploited — CISA Demands Patch Today
#CyberSecurity
https://securebulletin.com/critical-fortinet-forticlient-ems-vulnerability-cve-2026-21643-actively-exploited-cisa-demands-patch-today/
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Antiker Fehler in MS Excel wird angegriffen
Kaum zu glauben, aber wahr: Die Sicherheitslücke CVE-2009-0238 vom Februar 2009, gegen die längst ein Update vorliegt, wird offenbar gerade aktiv in Angriffen ausgenutzt. Jedenfalls ist sie am 2026-04-14 in den KEV Katalog der CISA aufgenommen worden; die US-Behörden müssen innerhalb von zwei Wochen ihre Systeme aktualisieren. Betroffen sind
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, 2007 SP1
Excel Viewer 2003 Gold und SP3
Excel Viewer
Compatibility Pack für Word, Excel, und PowerPoint 2007 Dateiformate SP1
Excel in Microsoft Office 2004 und 2008 for Mac
Ein Angreifer kann die volle Kontrolle über den
https://www.pc-fluesterer.info/wordpress/2026/04/16/antiker-fehler-in-ms-excel-wird-angegriffen/
#Empfehlung #Hintergrund #Warnung #cybercrime #exploits #Microsoft #office #sicherheit #unplugMicrosoft
Overview
- Red Hat
- Red Hat OpenShift GitOps
- openshift-gitops-1/argocd-image-updater-rhel8
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🚨 CRITICAL: CVE-2026-6388 in Red Hat OpenShift GitOps (CVSS 9.1) lets attackers with ImageUpdater access bypass namespace boundaries in multi-tenant setups. Restrict permissions & monitor changes. No patch yet — see https://radar.offseq.com/threat/cve-2026-6388-insufficient-granularity-of-access-c-fbeba818 #OffSeq #RedHat #GitOps #Vuln
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Microsoft dropped two wormable bugs in this month's Patch Tuesday. CVE-2026-33824 is a double free in the Windows IKE extension that lets an unauthorised attacker execute code over the network.
No auth needed, no user interaction. ZDI gave it two "bugs of the month" labels in the same release because both the IKE and TCP/IP flaws are wormable.
1/2
Overview
- @fastify/static
- @fastify/static
Description
Statistics
- 2 Posts
- 1 Interaction