Overview
- Birebirsoft Software and Technology Solutions
- Sufirmam
Description
Statistics
- 1 Post
Fediverse
π΄ CVE-2025-4319 - Critical (9.4)
Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Brute Force, Password Recovery Exploitation.This issu...
π https://www.thehackerwire.com/vulnerability/CVE-2025-4319/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
Description
Statistics
- 1 Post
Overview
- Fortinet
- FortiWeb
Description
Statistics
- 2 Posts
Fediverse
Arctic Wolf observes malicious configuration changes on Fortinet FortiGate devices via SSO accounts
Source: https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/
Arctic Wolf reports a new cluster of automated attacks observed from Jan. 15, 2026, involving unauthorized configuration changes on FortiGate firewalls. The activity includes creation of generic accounts for persistence, VPN access being granted to those accounts, and exfiltration of firewall configurations.
The campaign resembles activity Arctic Wolf disclosed in December 2025, which involved malicious SSO logins to administrator accounts followed by configuration changes and data exfiltration. Arctic Wolf has active detections in place and is alerting affected customers as additional cases are identified.
The activity follows Fortinetβs December advisory on two critical authentication bypass vulnerabilities, CVE-2025-59718 and CVE-2025-59719, which allow unauthenticated SSO access via crafted SAML messages when FortiCloud SSO is enabled. Affected products include FortiOS, FortiWeb, FortiProxy and FortiSwitchManager. It remains unclear whether the latest activity is fully mitigated by the existing patches.
Bluesky
Overview
Description
Statistics
- 1 Post
Fediverse
π΄ CVE-2026-1363 - Critical (9.8)
IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-Side Security vulnerability, allowing unauthenticated remote attackers to gain administrator privileges by manipulating the web front-end.
π https://www.thehackerwire.com/vulnerability/CVE-2026-1363/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
Description
Statistics
- 1 Post
Fediverse
π CVE-2026-0710 - High (8.4)
A flaw was found in SIPp. A remote attacker could exploit this by sending specially crafted Session Initiation Protocol (SIP) messages during an active call. This vulnerability, a NULL pointer dereference, can cause the application to crash, leadi...
π https://www.thehackerwire.com/vulnerability/CVE-2026-0710/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Microsoft
- Microsoft Account
Description
Statistics
- 2 Posts
Fediverse
π΄ CVE-2026-21264 - Critical (9.3)
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.
π https://www.thehackerwire.com/vulnerability/CVE-2026-21264/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Langflow
- Langflow
Description
Statistics
- 1 Post
Fediverse
π΄ CVE-2026-0770 - Critical (9.8)
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not r...
π https://www.thehackerwire.com/vulnerability/CVE-2026-0770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- github-kanban-mcp-server
- github-kanban-mcp-server
Description
Statistics
- 1 Post
Fediverse
π΄ CVE-2026-0756 - Critical (9.8)
github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of github-kanban-mcp-server. Authentication is not required to...
π https://www.thehackerwire.com/vulnerability/CVE-2026-0756/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
Description
Statistics
- 1 Post
Fediverse
π CVE-2025-69908 - High (7.5)
An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly accessible client-side JavaScript resource.
π https://www.thehackerwire.com/vulnerability/CVE-2025-69908/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Foundation Agents
- MetaGPT
Description
Statistics
- 1 Post
Fediverse
π΄ CVE-2026-0760 - Critical (9.8)
Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authe...
π https://www.thehackerwire.com/vulnerability/CVE-2026-0760/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack