24h | 7d | 30d

Overview

  • Johnson Controls
  • EasyIO NEO

01 Oct 2026
Published
02 Oct 2026
Updated

CVSS v4.0
HIGH (7.3)
EPSS
0.12%

KEV

Description

- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture fallback
~Cisa~ EasyIO Neo controllers expose credentials and session data over cleartext HTTP; upgrade to EC V3.3b64 or CW V3.3b26. - IOCs: CVE-2026-64893 - #CVE-2026-64893 #ICS #ThreatIntel
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • BerriAI
  • litellm

28 Sep 2026
Published
01 Oct 2026
Updated

CVSS v4.0
HIGH (7.6)
EPSS
0.27%

KEV

Description

LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the victim's role, including proxy_admin privileges, and permanently overwrite the victim's stored identity binding to retain persistent unauthorized access to administrative endpoints exposing API keys and user management.

Statistics

  • 1 Post

Last activity: 10 hours ago

Bluesky

Profile picture fallback
CVE-2026-93355: Account Takeover in LiteLLM
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Erlang
  • OTP
  • otp

22 Sep 2026
Published
24 Sep 2026
Updated

CVSS v4.0
HIGH (8.2)
EPSS
0.42%

KEV

Description

Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID during the TLS handshake. The BER OID decoder asn1rtt_ber:dec_subidentifiers/3 in lib/asn1/src/asn1rtt_ber.erl and the equivalent PER helper asn1rtt_per_common:dec_subidentifiers/3 in lib/asn1/src/asn1rtt_per_common.erl accumulate a base-128 subidentifier into an unbounded integer using (Av bsl 7) + H per continuation byte. Each shift and addition on the growing accumulator is linear in the number of bits already accumulated, giving quadratic total work in the size of a single subidentifier. The JER helper asn1rtt_jer:json2oid/1 in lib/asn1/src/asn1rtt_jer.erl exhibits the same class of unbounded-integer parsing when decoding a dot-separated OID from JSON. A DER-encoded OBJECT IDENTIFIER with one very large arc (approximately 262 KB of continuation bytes) consumes roughly 13 seconds of CPU on typical hardware. The vulnerable decoder is generated into every ASN.1 module that contains an OBJECT IDENTIFIER, including OTP-PUB-KEY which is reached during X.509 certificate parsing via public_key:pkix_decode_cert/2. This decoder runs before any signature or trust chain verification, so any Erlang service that parses peer TLS certificates is exposed: the default for TLS clients (which always parse the server certificate) and for mutual-TLS servers (which parse client certificates). This vulnerability is associated with program files lib/asn1/src/asn1rtt_ber.erl, lib/asn1/src/asn1rtt_per_common.erl and lib/asn1/src/asn1rtt_jer.erl and program routines asn1rtt_ber:dec_subidentifiers/3, asn1rtt_per_common:dec_subidentifiers/3 and asn1rtt_jer:json2oid/1. This issue affects OTP from OTP 17.0 before OTP 27.3.4.18, OTP 28.5.0.7, and OTP 29.1.1, corresponding to asn1 from 3.0 before 5.3.4.3, 5.4.3.1, and 5.5.2. Whether OTP before OTP 17.0, corresponding to asn1 before 3.0, is affected is unknown.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

CVE-2026-65634 Erlang/OTP DoS: crafted OID in TLS handshake triggers unbounded integer growth in the asn1 decoder CVSS 7.5. No patch yet. Limit OID parsing or update as soon as the fix lands. valtersit.com/cve/CVE-2026-656 #CVE #infosec #Erlang

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Legion of the Bouncy Castle Inc.
  • BC-JAVA
  • bcmls

03 Oct 2026
Published
03 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.19%

KEV

Description

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored but never parsed or validated, so the end-entity certificate's public key was never required to match signature_key as RFC 9420 sec. 5.3 requires. A party could therefore present another party's certificate as its credential while signing the leaf, and the enclosing KeyPackage, with an unrelated key, and be accepted under that other party's identity through KeyPackage.verify() and the Group leaf-validation path. In a deployment that admits external commits without an independent credential-admission check, an unauthenticated attacker could be admitted under a victim's X.509 identity, evict the victim (resynchronization compares whole credentials rather than signing keys), derive the current epoch, decrypt subsequent group messages, and send messages accepted as the victim. TreeKEM.LeafNode now requires the end-entity certificate's subject public key, in the cipher suite's signature encoding, to equal signature_key for an X.509 credential and rejects the leaf otherwise, including an empty chain or a certificate whose key type does not match the cipher suite; certificate-chain and identity validation to a trust anchor remain the application's responsibility per RFC 9420 sec. 5.3.1. Deployments using only basic credentials are unaffected.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

CRITICAL CVE-2026-71885 in Bouncy Castle BC-JAVA (<1.86): Improper X.509 cert validation in MLS lets attackers impersonate users & compromise group comms. Upgrade to 1.86+ ASAP. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • dgtlmoon
  • changedetection.io

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.65%

KEV

Description

A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Statistics

  • 1 Post

Last activity: 6 hours ago

Fediverse

Profile picture fallback

CVE-2026-95271: improper auth in changedetection.io up to 0.60.7 lets remote attackers bypass login. CVSS 7.3, exploit public, no patch yet. Isolate or restrict access now. valtersit.com/cve/CVE-2026-952 #CVE #infosec

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • checkpoint
  • Quantum Security Management

22 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
19.65%

Description

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
One Port to Root: Weaponizing Check Point Management CVE-2026-93616 bishopfox.com/blog/weaponi...
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Net-IDN-Encode

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS
Pending
EPSS
0.63%

KEV

Description

Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the result with defined to detect the end of the input. substr on an exhausted string returns the empty string rather than undef, so decoding continues past the end. The empty string converts to a digit value below the range, reducing the accumulator, and the decoder derives one extra code point and its position from it. The result is deterministic. The XS backend rejects the same label. Net::IDN::Punycode uses this backend wherever the XS does not build. The two backends disagree about what such a label means, so a sender can pick a label that one installation resolves to a name and another rejects.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture fallback

CVE-2026-87080 Net::IDN::Punycode CVSS 9.1: truncated label decodes to unencoded chars, enabling spoofing. Patch under review - update Perl module now. valtersit.com/cve/CVE-2026-870 #CVE #infosec #Perl

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Checkmk GmbH
  • Checkmk

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS v4.0
LOW (2.3)
EPSS
0.35%

KEV

Description

Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords in clear text from GET responses, although the setup GUI never displays these values.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

CVE-2026-92882 Checkmk: credentialed API user can read SNMP community strings, SNMPv3 passphrases and IPMI passwords in cleartext from REST GET responses. CVSS 6.5. No patch yet. Restrict API access and monitor now. valtersit.com/cve/CVE-2026-928 #CVE #infosec #Checkmk

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • e4jvikwp
  • VikAppointments Services Booking Calendar

03 Oct 2026
Published
03 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.88%

KEV

Description

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires at least one File-type custom field to be published on the confirmation page shortcode, as this field is not created by default during plugin installation.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture fallback

VikAppointments Booking Calendar plugin (<=1.2.21) for WordPress is vulnerable to CRITICAL path traversal (CVE-2026-87115). Unauth attackers can delete files, risking RCE. Check for File-type fields & secure your site! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Cisco
  • Cisco Catalyst SD-WAN Manager

30 Sep 2026
Published
02 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.58%

Description

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
Revenge of the SD-WAN: Exploring and Exploiting Yet Another Critical Cisco SD-WAN Vulnerability (CVE-2026-76504) www.vulncheck.com/blog/revenge...
  • 0
  • 0
  • 0
  • 6h ago
Showing 31 to 40 of 55 CVEs