24h | 7d | 30d

Overview

  • GestSup
  • GestSup

25 Sep 2026
Published
25 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.57%

KEV

Description

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.

Statistics

  • 1 Post

Last activity: 19 hours ago

Fediverse

Profile picture fallback

GestSup <3.2.61 is vulnerable to CRITICAL RCE (CVE-2026-100389) via IMAP connector. Attackers can send PHP attachments to monitored mailboxes, leading to system compromise. Upgrade to 3.2.61+ ASAP. radar.offseq.com/threat/gestsu

  • 0
  • 0
  • 0
  • 19h ago

Overview

  • checkpoint
  • Quantum Security Management

22 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
19.65%

Description

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture fallback

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-93616 – Check Point Multiple Products Path Traversal Vulnerability

Analyze the technical mechanics of CVE-2026-93616 with our Check Point TSUITE brief, covering management server path traversal, remote code execution, and endpoint hardening....

thecybermind.co/1yot

  • 0
  • 0
  • 0
  • 17h ago

Overview

  • themefic
  • Ultra Addons for Contact Form 7

26 Sep 2026
Published
26 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is only exploitable when the plugin's PDF Generator module is enabled, which is disabled by default.

Statistics

  • 1 Post

Last activity: 6 hours ago

Fediverse

Profile picture fallback

CVE-2026-82901: CRITICAL (CVSS 9.8) file upload vuln in Ultra Addons for Contact Form 7 (≤3.5.50). RCE risk if PDF Generator enabled (off by default). Disable/monitor plugin & watch for patches. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • IBM
  • Guardium Data Protection

18 Sep 2026
Published
19 Sep 2026
Updated

CVSS v3.1
HIGH (7.4)
EPSS
0.34%

KEV

Description

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

Statistics

  • 1 Post

Last activity: 18 hours ago

Fediverse

Profile picture fallback

CVE-2026-84036 IBM Guardium Data Protection 12.2 access control bypass, CVSS 7.4. Auth'd attacker can bypass security restrictions. No patch yet - restrict access now. valtersit.com/cve/CVE-2026-840 #CVE #infosec #IBM

  • 0
  • 0
  • 0
  • 18h ago

Overview

  • patriksimek
  • vm2

27 Sep 2026
Published
27 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
Pending

KEV

Description

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-string boundary. Untrusted guest code can therefore require the allowlisted module (e.g. `foo`) and then require the absolute path of a non-allowlisted sibling whose path merely shares the resolved prefix (e.g. `.../node_modules/foo2/index.js`); the sibling passes `isPathAllowedForModule` and is loaded through `hostRequire`, so its top-level code runs in the host process before the exports are wrapped with `vm.readonly`, resulting in a sandbox escape and arbitrary code execution in the host context.

Statistics

  • 1 Post

Last activity: Last hour

Fediverse

Profile picture fallback

CVE-2026-100721: CRITICAL auth bypass in vm2 <3.12.2's NodeVM external-module resolver. Sandbox escape & arbitrary code exec possible. Upgrade to 3.12.2+ ASAP. radar.offseq.com/threat/vm2-be

  • 0
  • 0
  • 0
  • Last hour

Overview

  • projectcapsule
  • capsule

18 Sep 2026
Published
21 Sep 2026
Updated

CVSS v3.1
MEDIUM (6.8)
EPSS
0.59%

KEV

Description

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnUpdate in internal/webhook/tenant/validation/hostname_regex.go reverses the new and old Tenant parameters and validates the previous AllowedHostnames.Regex instead of the submitted value. A cluster administrator can therefore store a malformed AllowedHostnames.Regex after the webhook accepts the update based on stale valid state. Subsequent Ingress creation or update reaches validate_hostnames.go, which evaluates the malformed pattern, ignores the regular-expression error, and treats every hostname as unmatched, blocking Ingress operations for the affected tenant until an administrator repairs the Tenant configuration. This issue is fixed in version 0.13.7.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

CVE-2026-61795 Capsule Kubernetes tenant webhook validates stale regex, letting admins store malformed AllowedHostnames.Regex. CVSS 6.8. No patch as of now. Review configs and lock down ingress. valtersit.com/cve/CVE-2026-617 #CVE #Kubernetes #infosec

  • 0
  • 0
  • 0
  • 11h ago
Showing 31 to 36 of 36 CVEs