Overview
- OpenClaw
- OpenClaw
01 Feb 2026
Published
03 Feb 2026
Updated
CVSS v3.1
HIGH (8.8)
EPSS
0.04%
KEV
Description
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
Statistics
- 2 Posts
Last activity: 7 hours ago
Bluesky
⚠️ OpenClaw – CVE-2026-25253 : un lien malveillant suffit à exécuter du code à distance en 1-clic
Tous les détails par ici 👇
- www.it-connect.fr/openclaw-cve...
#OpenClaw #Moltbot #IA #infosec #cybersecurite
Overview
Description
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Statistics
- 2 Posts
Last activity: 13 hours ago
Fediverse
Bitte schnell die betroffenen Systeme aktualisieren und sich einen neuen Hersteller des Vertrauens suchen... z.B. #CheckPoint 🫳 🎤
#Fortinet #FortiCloud #FortiOS #FortiManager #FortiWeb #FortiProxy #FortiAnalyzer #Sicherheitsluecke #EUVD_2026_4712 #CVE_2026_24858
Overview
Description
This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.
Statistics
- 2 Posts
- 42 Interactions
Last activity: 3 hours ago
Bluesky
🎉 Go 1.26 Release Candidate 3 is released!
🔒 Security: Includes an update for crypto/tls (CVE-2025-68121).
🏖 Run it in dev! Run it in prod! File bugs! go.dev/issue/new
📢 Announcement: groups.google.com/g/golang-ann...
⬇️ Download: go.dev/dl/#go1.26rc3
#golang
Overview
- Kubernetes
- ingress-nginx
03 Feb 2026
Published
04 Feb 2026
Updated
CVSS v3.1
MEDIUM (6.5)
EPSS
0.04%
KEV
Description
A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory.
Statistics
- 5 Posts
Last activity: 3 hours ago
Fediverse
CVE-2026-24514: ingress-nginx Admission Controller denial of service - https://github.com/kubernetes/kubernetes/issues/136680
Bluesky
🔴 CVE-2026-1580 and CVE-2026-24512 allow for config #injection via the "nginx.ingress.kubernetes.io/auth-method" ingress annotation and the "rules.http.paths.path" ingress field, respectively.
🟡 CVE-2026-24514 is a #DoS in the ingress-nginx admission controller, triggered by sending large requests.
Overview
Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
Statistics
- 1 Post
- 1 Interaction
Last activity: 12 hours ago
Bluesky
Overview
- Wikimedia Foundation
- MediaWiki - CSS extension
07 Jan 2026
Published
07 Jan 2026
Updated
CVSS
Pending
EPSS
0.06%
KEV
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wikimedia Foundation MediaWiki - CSS extension allows Path Traversal.This issue affects MediaWiki - CSS extension: 1.44, 1.43, 1.39.
Statistics
- 1 Post
- 1 Interaction
Last activity: 8 hours ago
Bluesky
Overview
- notepad-plus-plus
- notepad-plus-plus
03 Feb 2026
Published
03 Feb 2026
Updated
CVSS v4.0
HIGH (7.7)
EPSS
0.03%
KEV
Description
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user.
Statistics
- 1 Post
Last activity: 18 hours ago
Overview
- Rapid7
- Vulnerability Management
03 Feb 2026
Published
04 Feb 2026
Updated
CVSS v3.1
CRITICAL (9.6)
EPSS
0.02%
KEV
Description
Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup
via "Security Console" installations, resulting in full account takeover. The issue occurs due to the application processing these unsigned assertions and issuing session cookies that granted access to the
targeted user accounts. This has been fixed in version 8.34.0 of InsightVM.
Statistics
- 1 Post
Last activity: 17 hours ago
Overview
- Red Hat
- Red Hat Enterprise Linux 10
- bootc
27 Jan 2026
Published
03 Feb 2026
Updated
CVSS
Pending
EPSS
0.04%
KEV
Description
A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.
Statistics
- 2 Posts
Last activity: 4 hours ago
Bluesky
CRITICAL: #OpenSUSE glib2 update patches privilege escalation & memory corruption vulns (CVE-2026-1484). A must-patch for all admins. Read more: 👉 tinyurl.com/3cpdfnvz #Security
Overview
Description
Windows Search Remote Code Execution Vulnerability
Statistics
- 1 Post
Last activity: 14 hours ago