24h | 7d | 30d

Overview

  • checkpoint
  • Quantum Security Gateway

09 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103.

securityonline.info/checkpoint

  • 1
  • 0
  • 0
  • 14h ago
Profile picture fallback

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

community.checkpoint.com/t5/Ge

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 22 hours ago

Bluesky

Profile picture fallback
VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) URL: support.broadcom.com/web/ecx/supp... Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 9.3
  • 0
  • 1
  • 0
  • 22h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 22 hours ago

Bluesky

Profile picture fallback
VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) URL: support.broadcom.com/web/ecx/supp... Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 9.3
  • 0
  • 1
  • 0
  • 22h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 15 hours ago

Bluesky

Profile picture fallback
Schneider Electric, Siemens, and Aveva issued September Patch Tuesday advisories for ICS products, fixing critical flaws including CVE-2026-3869 in Modicon M580 and CVE-2026-31431 in the Linux kernel. #SchneiderElectric #Siemens #ICS
  • 0
  • 1
  • 0
  • 15h ago

Overview

  • SAP_SE
  • SAP NetWeaver (Message Server)

08 Sep 2026
Published
09 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.34%

KEV

Description

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.

Statistics

  • 1 Post

Last activity: 13 hours ago

Bluesky

Profile picture fallback
~Certeu~ Unauthenticated remote exploitation enables OS command execution; patch SAP Notes 3747649 and 3759472. - IOCs: CVE-2026-44756, CVE-2026-58240 - #CVE #SAP #ThreatIntel
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Amazon
  • ion-java

04 Sep 2026
Published
04 Sep 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.33%

KEV

Description

Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insufficient coverage of the GZIP auto-decompression opt-out introduced for CVE-2026-75936. To remediate this issue, users should upgrade to version 1.12.1.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

CVE-2026-85786: DoS via crafted compressed Ion data in Amazon ion-java <1.12.1. Expansion bomb bypasses GZIP opt-out (CVE-2026-75936). CVSS 7.5. Update to 1.12.1 now. valtersit.com/cve/CVE-2026-857 #CVE #infosec #AWS

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Amazon Ion
  • Amazon Ion Java

18 Aug 2026
Published
19 Aug 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.44%

KEV

Description

Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression. To remediate this issue, users should upgrade to version 1.12.0 and configure withGzipDecompressionEnabled(false) and/or set an explicit withMaximumBufferSize() when parsing untrusted input.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

CVE-2026-85786: DoS via crafted compressed Ion data in Amazon ion-java <1.12.1. Expansion bomb bypasses GZIP opt-out (CVE-2026-75936). CVSS 7.5. Update to 1.12.1 now. valtersit.com/cve/CVE-2026-857 #CVE #infosec #AWS

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Google
  • Chrome

03 Sep 2026
Published
06 Sep 2026
Updated

CVSS
Pending
EPSS
1.43%

Description

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Earlier this month, @volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). Volexity observed threat actors it tracks as UTA0560 and JungleBamboo using variations of the same exploits to deliver different malware implants. These implants ranged from a JScript backdoor (GRIMWEDGE) to a fake Google Gemini Chrome extension (LONGTALE).

Read the full analysis of the exploit chain and post-exploitation tradecraft here: volexity.com/blog/2026/09/09/m
 

  • 3
  • 2
  • 0
  • 11h ago

Overview

  • Ubiquiti Inc
  • UniFi Protect Application

26 Aug 2026
Published
26 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.94%

KEV

Description

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture fallback
~Arcticwolf~ Three unauthenticated UniFi flaws enable remote code execution or authentication bypass; patch immediately. - IOCs: CVE-2026-77537, CVE-2026-77550, CVE-2026-77554 - #CVE-2026-77537 #CVE-2026-77550 #ThreatIntel
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Google
  • Chrome

14 May 2026
Published
15 May 2026
Updated

CVSS
Pending
EPSS
0.21%

KEV

Description

Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

community.checkpoint.com/t5/Ge

  • 0
  • 0
  • 0
  • 9h ago
Showing 71 to 80 of 91 CVEs