24h | 7d | 30d

Overview

  • NetScaler
  • ADC

30 Jun 2026
Published
27 Aug 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
1.01%

Description

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Statistics

  • 1 Post
  • 19 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

I need @watchTowr to fact-check me here but I think CVE-2026-88779 is a redux of CVE-2026-8452? At least based on this mitigation Citrix support are giving out, somebody posted it on their blog. deyda.net/index.php/de/2026/08

The 8452 patch locked SAML PrefixList to 512 byte or below string. But I think CVE-2026-88779 may be more than 15 items in PrefixList, space-separated, to trigger a vuln. Assuming Citrix support gave out the right mitigation.

  • 3
  • 16
  • 0
  • 10h ago

Overview

  • Perfoce
  • P4 (Helix Core)
  • P4Search

05 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.42%

KEV

Description

Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 8 hours ago

Overview

  • Perforce
  • P4 (Helix Core)
  • P4Search

05 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
0.35%

KEV

Description

P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 8 hours ago

Overview

  • Perforce
  • P4 (Helix Core)
  • P4Search

05 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
0.36%

KEV

Description

Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 8 hours ago

Overview

  • Zammad GmbH
  • Zammad

30 Sep 2026
Published
05 Oct 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
1.40%

Description

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture fallback

Two Zammad zero-day flaws let attackers go from session hijack to root in seconds at DIVD. See the CVEs, affected versions, and fixes.

meterpreter.org/zammad-zero-da

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

08 Jul 2025
Published
13 Feb 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
100.00%

Description

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
Warlockランサムウェアが引き続きToolShell悪用、重要インフラに攻撃を拡大(CVE-2025-49704、CVE-2025-49706) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47913/
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
28 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.30%

Description

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture fallback
NetScaler ADCおよびNetScaler Gatewayにおける複数の脆弱性(CVE-2026-88771、CVE-2026-88772等)に関する注意喚起 #JPCERTCC (Oct 2) www.jpcert.or.jp/at/2026/at26...
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • MediaTek, Inc.
  • MediaTek chipset

05 Oct 2026
Published
05 Oct 2026
Updated

CVSS
Pending
EPSS
0.23%

KEV

Description

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778993; Issue ID: MSV-8898.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture fallback

MediaTek security bulletin for October 2026 fixes 31 flaws, including critical MediaTek modem vulnerability CVE-2026-20519. Update now.

securityonline.info/mediatek-s

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

08 Jul 2025
Published
04 Aug 2026
Updated

CVSS v3.1
MEDIUM (6.5)
EPSS
99.08%

Description

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
Warlockランサムウェアが引き続きToolShell悪用、重要インフラに攻撃を拡大(CVE-2025-49704、CVE-2025-49706) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47913/
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • MediaTek, Inc.
  • MediaTek chipset

05 Oct 2026
Published
05 Oct 2026
Updated

CVSS
Pending
EPSS
0.23%

KEV

Description

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778988; Issue ID: MSV-8897.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture fallback

MediaTek security bulletin for October 2026 fixes 31 flaws, including critical MediaTek modem vulnerability CVE-2026-20519. Update now.

securityonline.info/mediatek-s

  • 0
  • 0
  • 0
  • 12h ago
Showing 51 to 60 of 66 CVEs