24h | 7d | 30d

Overview

  • NetScaler
  • ADC

23 Mar 2026
Published
24 Mar 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.02%

KEV

Description

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

Statistics

  • 12 Posts
  • 12 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

🚨 CVE-2026-3055 (CVSS 9.3), a unauth memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances that could see active exploitation itw

Vulnerability detection script available here:
github.com/rxerium/rxerium-tem

Patches are available as per Citrix's advisory:
support.citrix.com/support-hom

  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback

➡️ CVE-2026-3055 👀
👇
support.citrix.com/support-hom

  • CVE-2026-3055 - Out-of-Bounds Read vulnerability - CVSSv4 base score: 9.3
    Note: Citrix NetScaler ADC or Citrix Gateway must be configured as SAML IDP to be vulnerable to CVE-2026-3055.

    • CVE-2026-4368 - Race Condition vulnerability - CVSSv4 base score: 7.7Note: Affected appliances must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP proxy) or AAA virtual server to be vulnerable CVE-2026-4368.

( -> cve.circl.lu/search?q=CVE-2026 )

  • 1
  • 1
  • 0
  • 23h ago
Profile picture fallback

NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368

#citrix #vulnerabilitymanagement #vulnerability

vulnerability.circl.lu/bundle/

  • 1
  • 0
  • 0
  • 23h ago
Profile picture fallback

Urges Patching Critical NetScaler Vulnerabilities CVE-2026-3055 & CVE-2026-4368 Allowing Unauthenticated Data Leaks. This looks like another incarnation of !

Defenders need to act quickly. Patch Now!
👇
thehackernews.com/2026/03/citr

  • 0
  • 1
  • 1
  • 1h ago

Bluesky

Profile picture fallback
🚨 On March 23, 2026, #Citrix published a security advisory for a critical vuln. affecting their NetScaler ADC & Gateway products. CVE-2026-3055, an out-of-bounds read, allows unauthenticated remote attackers to leak information from the appliance's memory. Read on: r-7.co/41nwCJ7
  • 1
  • 1
  • 0
  • 19h ago
Profile picture fallback
CVE-2026-3055。アプライアンスがSAML IdP設定であればやられるようです。CVSSv4で9.3:Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems https://cybersecuritynews.com/netscaler-adc-and-gateway-vulnerabilities/
  • 1
  • 0
  • 0
  • 13h ago
Profile picture fallback
Critical NetScaler Flaw Exposes Enterprise Networks: CVE-2026-3055 Enables Memory Leak & Session Hijacking + Video Introduction: NetScaler ADC (Application Delivery Controller) and Gateway serve as the backbone for application traffic management, load balancing, and secure remote access in…
  • 1
  • 0
  • 0
  • 7h ago
Profile picture fallback
Critical NetScaler ADC, Gateway flaw may soon be exploited (CVE-2026-3055) 📖 Read more: www.helpnetsecurity.com/2026/03/24/n... #cybersecurity #cybersecuritynews #vulnerability @rapid7.com
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368 #CRITICAL support.citrix.com/support-home...
  • 1
  • 0
  • 0
  • 23h ago
Profile picture fallback
~Certeu~ Citrix patched critical flaws in NetScaler ADC & Gateway allowing info disclosure and session mix-up. - IOCs: CVE-2026-3055, CVE-2026-4368 - #Citrix #ThreatIntel #Vulnerability
  • 1
  • 0
  • 0
  • 19h ago
Profile picture fallback
~Cybergcca~ CCCS issued 9 advisories, highlighting an actively exploited Craft CMS flaw (CVE-2025-32432) and critical Citrix NetScaler vulnerabilities. - IOCs: CVE-2025-32432, CVE-2026-3055, CVE-2026-4368 - #CISA_KEV #ThreatIntel #Vulnerability
  • 1
  • 0
  • 0
  • 22h ago

Overview

  • Oracle Corporation
  • Oracle Identity Manager

20 Mar 2026
Published
24 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.04%

KEV

Description

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager and Oracle Web Services Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager and Oracle Web Services Manager. Note: Oracle Web Services Manager is installed with an Oracle Fusion Middleware Infrastructure. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Statistics

  • 8 Posts
  • 1 Interaction

Last activity: 2 hours ago

Fediverse

Profile picture fallback

📰 URGENT: Oracle Patches Critical 9.8 CVSS Unauthenticated RCE Flaw

📢 URGENT PATCH: Oracle has issued an emergency fix for CVE-2026-21992, a critical 9.8 CVSS unauthenticated RCE flaw in Identity Manager. Unpatched systems can be fully compromised. Patch immediately! 🚨 #Oracle #CyberSecurity #RCE #PatchNow

🔗 cyber.netsecops.io/articles/or

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback

CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild. securityweek.com/oracle-releas

  • 0
  • 0
  • 1
  • 2h ago

Bluesky

Profile picture fallback
Oracle社、Identity Managerにおける認証前リモートコード実行の脆弱性(CVE-2026-21992)に対する緊急修正プログラムをリリース Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) #HelpNetSecurity (Mar 23) www.helpnetsecurity.com/2026/03/23/o...
  • 0
  • 1
  • 0
  • 14h ago
Profile picture fallback
Oracle Patches Critical Identity RCE Read More: buff.ly/SRyprxy #OracleSecurity #CVE202621992 #RemoteCodeExecution #IdentitySecurity #PatchNow #VulnerabilityManagement #EnterpriseSecurity #InfosecAlert
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
~Sophos~ Critical unauthenticated RCE flaw in Oracle Fusion Middleware components. - IOCs: CVE-2026-21992 - #CVE2026_21992 #Oracle #threatintel
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Oracle Identity Managerに致命的な脆弱性(CVE-2026-21992) rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
Oracle releases urgent patch for CVE-2026-21992, a critical unauthenticated remote code execution flaw in Oracle Identity Manager 12.2.1.4.0 exploitable via HTTP. #OraclePatch #RemoteCodeExec #USA
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Pending

24 Jun 2025
Published
03 Nov 2025
Updated

CVSS
Pending
EPSS
0.17%

KEV

Description

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

📰 Warning: Critical 10.0 CVSS Quest KACE Flaw from 2025 Now Actively Exploited

🔥 ACTIVE EXPLOITATION: A year-old, 10.0 CVSS flaw in Quest KACE SMA (CVE-2025-32975) is now being actively exploited. Attackers are gaining full admin control, deploying Mimikatz, and moving laterally. Patch and isolate from the internet NOW! #CVE

🔗 cyber.netsecops.io/articles/ol

  • 0
  • 0
  • 0
  • 23h ago

Bluesky

Profile picture fallback
CVE-2025-32975: Arctic Wolf Observes Exploitation of Quest KACE Systems Management Appliance #patchmanagement
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • NetScaler
  • ADC

23 Mar 2026
Published
24 Mar 2026
Updated

CVSS v4.0
HIGH (7.7)
EPSS
0.02%

KEV

Description

Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup

Statistics

  • 7 Posts
  • 7 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

➡️ CVE-2026-3055 👀
👇
support.citrix.com/support-hom

  • CVE-2026-3055 - Out-of-Bounds Read vulnerability - CVSSv4 base score: 9.3
    Note: Citrix NetScaler ADC or Citrix Gateway must be configured as SAML IDP to be vulnerable to CVE-2026-3055.

    • CVE-2026-4368 - Race Condition vulnerability - CVSSv4 base score: 7.7Note: Affected appliances must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP proxy) or AAA virtual server to be vulnerable CVE-2026-4368.

( -> cve.circl.lu/search?q=CVE-2026 )

  • 1
  • 1
  • 0
  • 23h ago
Profile picture fallback

NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368

#citrix #vulnerabilitymanagement #vulnerability

vulnerability.circl.lu/bundle/

  • 1
  • 0
  • 0
  • 23h ago
Profile picture fallback

Urges Patching Critical NetScaler Vulnerabilities CVE-2026-3055 & CVE-2026-4368 Allowing Unauthenticated Data Leaks. This looks like another incarnation of !

Defenders need to act quickly. Patch Now!
👇
thehackernews.com/2026/03/citr

  • 0
  • 1
  • 1
  • 1h ago

Bluesky

Profile picture fallback
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368 #CRITICAL support.citrix.com/support-home...
  • 1
  • 0
  • 0
  • 23h ago
Profile picture fallback
~Certeu~ Citrix patched critical flaws in NetScaler ADC & Gateway allowing info disclosure and session mix-up. - IOCs: CVE-2026-3055, CVE-2026-4368 - #Citrix #ThreatIntel #Vulnerability
  • 1
  • 0
  • 0
  • 19h ago
Profile picture fallback
~Cybergcca~ CCCS issued 9 advisories, highlighting an actively exploited Craft CMS flaw (CVE-2025-32432) and critical Citrix NetScaler vulnerabilities. - IOCs: CVE-2025-32432, CVE-2026-3055, CVE-2026-4368 - #CISA_KEV #ThreatIntel #Vulnerability
  • 1
  • 0
  • 0
  • 22h ago

Overview

  • Apple
  • macOS

12 Dec 2025
Published
23 Mar 2026
Updated

CVSS
Pending
EPSS
0.48%

Description

A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 26.1, iOS 18.7.2 and iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, tvOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 and iPadOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.

Statistics

  • 9 Posts
  • 5 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

There has been a lot of sloppy reporting regarding DarkSword, with basically every news outlet saying that iOS 18 is vulnerable. It’s not, if you have the latest 18.7.3.

Google has a more in depth analysis, with a lot more information on the specific versions of iOS that are affected.

TL;DR It doesn’t seem to affect 18.7.3 at least (might also not work on 18.7.2 given that CVE-2025-43520, which DarkSword uses, has been patched in .2).

cloud.google.com/blog/topics/t

#iOS #DarkSword

  • 3
  • 0
  • 0
  • 5h ago
Profile picture fallback

@peternlewis sloppy reporting, as usual.

Google has a more in depth analysis, with a lot more information on the specific versions of iOS that are affected.

TL;DR It doesn’t seem to affect 18.7.3 at least (might also not work on 18.7.2 given that CVE-2025-43520, which DarkSword uses, has been patched in .2).

cloud.google.com/blog/topics/t

  • 0
  • 2
  • 6
  • 5h ago
Profile picture fallback

Unfortunately it looks like CVE-2025-43520 was patched in iOS 26.1b4, the exact build I happened to leave my test device on...

I might play around with it on my Mac or in one of the new iOS pccvre VMs though.

  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Cisco
  • Cisco Secure Firewall Management Center (FMC)

04 Mar 2026
Published
20 Mar 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.65%

Description

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Critical patch alert: The US government has ordered a maximum severity patch for a Cisco vulnerability (CVE-2026-20131) that's being exploited in ransomware campaigns.

Read more: steelefortress.com/86cy1e

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
~Zscaler~ Unauthenticated RCE vulnerability (CVSS 10) in Cisco Secure FMC actively exploited in the wild, granting root access. - IOCs: CVE-2026-20131 - #CVE202620131 #Cisco #RCE #ThreatIntel
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • curl
  • curl

08 Jan 2026
Published
08 Jan 2026
Updated

CVSS
Pending
EPSS
0.04%

KEV

Description

When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Notepad++ 8.9.3 mit einigen Korrekturen und einer berbesserten SIcherheit für cURL (CVE-2025-14819)

deskmodder.de/blog/2026/03/24/

  • 2
  • 0
  • 1
  • 4h ago

Overview

  • Google
  • Chrome

12 Mar 2026
Published
14 Mar 2026
Updated

CVSS
Pending
EPSS
4.44%

Description

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 14 hours ago

Fediverse

Profile picture fallback

Global cybersecurity alerts include active exploitation of Chrome Zero-Days (CVE-2026-3909/3910) and a Quest KACE SMA flaw for credential harvesting. Advanced threats like Android haptic keyloggers and deepfake identity fraud are emerging. Geopolitically, Persian Gulf tensions remain high, while the US announced a new cyber strategy to defend companies from foreign adversaries. In tech, NVIDIA Nemotron 3 Super is now on Amazon Bedrock.

#Cybersecurity #GeopoliticalNews #TechBrief

  • 2
  • 0
  • 0
  • 14h ago

Overview

  • djangoproject
  • Django
  • django

03 Feb 2026
Published
03 Feb 2026
Updated

CVSS
Pending
EPSS
5.38%

KEV

Description

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 23 hours ago

Fediverse

Profile picture fallback

🚨 In this week’s threat alert, CrowdSec reports on CVE-2026-1207, a critical Django SQL injection vulnerability now actively exploited in the wild. Attackers are targeting GeoDjango setups using PostGIS with focused reconnaissance. Notably, this vulnerability hasn’t yet been added to the CISA KEV catalog.

Learn how the vulnerability works and how to secure your systems in our latest article: crowdsec.net/vulntracking-repo

  • 1
  • 1
  • 1
  • 23h ago

Overview

  • mpetroff
  • pannellum

21 Feb 2026
Published
25 Feb 2026
Updated

CVSS v4.0
MEDIUM (5.3)
EPSS
Pending

KEV

Description

Pannellum is a lightweight, free, and open source panorama viewer for the web. In versions 3.5.0 through 2.5.6, the hot spot attributes configuration property allowed any attribute to be set, including HTML event handler attributes, allowing for potential XSS attacks. This affects websites hosting the standalone viewer HTML file and any other use of untrusted JSON config files (bypassing the protections of the escapeHTML parameter). As certain events fire without any additional user interaction, visiting a standalone viewer URL that points to a malicious config file — without additional user interaction — is sufficient to trigger the vulnerability and execute arbitrary JavaScript code, which can, for example, replace the contents of the page with arbitrary content and make it appear to be hosted by the website hosting the standalone viewer HTML file. This issue has been fixed in version 2.5.7. To workaround, setting the Content-Security-Policy header to script-src-attr 'none' will block execution of inline event handlers, mitigating this vulnerability. Don't host pannellum.htm on a domain that shares cookies with user authentication to mitigate XSS risk.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.

IOCs:
000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics

  • 1
  • 1
  • 0
  • Last hour
Showing 1 to 10 of 48 CVEs