24h | 7d | 30d

Overview

  • wolfsoftwaresystemsltd
  • WolfStack

12 Aug 2026
Published
12 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.62%

KEV

Description

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate without any session, API key, or user account. Attackers can reach an affected node's management port to enumerate all Docker and LXC containers on the host and execute arbitrary commands as root inside any container via the POST /api/containers/{runtime}/{id}/exec endpoint.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-73519: WolfStack <25.9.2 vulnerable to hard-coded secret in src/auth/mod.rs — remote attackers can bypass auth & run root commands in containers via the management port. Restrict access & monitor for X-WolfStack-Secret usage. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Palo Alto Networks
  • GlobalProtect App

13 Aug 2026
Published
13 Aug 2026
Updated

CVSS v4.0
MEDIUM (4.5)
EPSS
0.09%

KEV

Description

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture fallback
Paloaltoの脆弱性情報 「CVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability (Severity: MEDIUM)」が公開されました。 → https://security.paloaltonetworks.com/CVE-2026-0296
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • @fastify/busboy
  • @fastify/busboy

13 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.47%

KEV

Description

@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendored streaming search stores its skip table in a fixed 256 entry byte array, and a boundary of exactly 252 bytes makes the search needle 256 bytes, which truncates the default skip distance to zero and turns the search into a CPU bound loop on a small body. A single small request can keep one core busy and deny service to other requests handled by the same process. The issue is fixed in @fastify/busboy 3.2.1, which widens the skip table so the skip distance is preserved. Users should upgrade to 3.2.1.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

🚨 High-severity security fix in @fastify/busboy@3.2.1 just released!

Patches CVE-2026-19484: @fastify/busboy vulnerable to denial of service via oversized multipart boundary

github.com/fastify/busboy/secu

  • 0
  • 0
  • 1
  • 4h ago

Overview

  • Palo Alto Networks
  • GlobalProtect App

13 Aug 2026
Published
13 Aug 2026
Updated

CVSS v4.0
MEDIUM (5.2)
EPSS
0.19%

KEV

Description

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture fallback
Paloaltoの脆弱性情報 「CVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) (Severity: MEDIUM)」が公開されました。 → https://security.paloaltonetworks.com/CVE-2026-0298
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • OpenStack
  • Designate

12 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
0.52%

KEV

Description

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA responses). Exploitation requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters, which is a non-default but documented and supported configuration for self-service tiering.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture fallback

OpenStack Designate CRITICAL vuln (CVE-2026-71193, CVSS 9.6): Authenticated users can hijack or disrupt DNS cross-tenant by bypassing zone checks via AttributeFilter in multi-pool deployments. Disable AttributeFilter until patched. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Red Hat
  • Red Hat Enterprise Linux 10
  • rsyslog

12 Aug 2026
Published
13 Aug 2026
Updated

CVSS
Pending
EPSS
0.40%

KEV

Description

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Bluesky

Profile picture fallback
rsyslog: fix CVE-2026-19654 https://github.com/NixOS/nixpkgs/pull/552215 https://tracker.security.nixos.org/issues/NIXPKGS-2026-2403 #security
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
[Backport release-26.05] rsyslog: fix CVE-2026-19654 https://github.com/NixOS/nixpkgs/pull/552242 https://tracker.security.nixos.org/issues/NIXPKGS-2026-2403 #security
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Palo Alto Networks
  • Prisma Access Agent

13 Aug 2026
Published
13 Aug 2026
Updated

CVSS v4.0
LOW (1.1)
EPSS
0.12%

KEV

Description

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture fallback
Paloaltoの脆弱性情報 「CVE-2026-0291 Prisma Access Agent: Authenticated Limited File Deletion on Linux (Severity: LOW)」が公開されました。 → https://security.paloaltonetworks.com/CVE-2026-0291
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Apache Software Foundation
  • Apache HTTP Server

08 Jun 2026
Published
05 Aug 2026
Updated

CVSS
Pending
EPSS
27.98%

KEV

Description

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
Fortinet patched eight flaws across FortiWeb, FortiManager, FortiClient, FortiOS, and FortiSIEM, including auth issues in FortiWeb and FortiManager. Guidance also issued on Apache HTTP Server CVE-2026-49975. #FortiWeb #FortiManager #ApacheHTTPServer
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Pending

28 Jan 2012
Published
06 Aug 2024
Updated

CVSS
Pending
EPSS
82.76%

KEV

Description

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

Statistics

  • 1 Post

Last activity: 22 hours ago

Fediverse

Profile picture fallback

En voulant comprendre pourquoi j'ai des verbes HTTP "\x16\x03\x01", je découvre la CVE-2012-0053 cve.org/CVERecord?id=CVE-2012- . OK, ban direct

  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Priority
  • Portal Generator addon to Priority ERP (developed by Soft Solutions)

13 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.3)
EPSS
0.32%

KEV

Description

CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control

Statistics

  • 1 Post

Last activity: 3 hours ago

Fediverse

Profile picture fallback

CVE-2026-59507 (CRITICAL, CVSS 9.3) impacts Priority ERP Portal Generator addon: hard-coded creds, info exposure, improper access control. No patch yet — restrict access & monitor systems. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 3h ago
Showing 41 to 50 of 64 CVEs