Overview
- Red Hat
- Red Hat build of Keycloak 26.4
- rhbk/keycloak-operator-bundle
18 Aug 2026
Published
08 Sep 2026
Updated
CVSS
Pending
EPSS
3.18%
KEV
Description
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
Statistics
- 1 Post
Last activity: 3 hours ago
Fediverse
Two critical Siemens vulnerabilities (CVE-2026-18963, CVE-2026-50093) allow account takeover and root access. See affected versions and fixes.
#Siemens #CyberSecurity #ICS #OTSecurity #CVE #IndustrialEdge #Vulnerability #InfoSec
Overview
- mangroup
- dtale
15 Aug 2026
Published
17 Aug 2026
Updated
CVSS v4.0
MEDIUM (6.3)
EPSS
0.37%
KEV
Description
A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/auth.py of the component Login Endpoint. Such manipulation leads to improper restriction of excessive authentication attempts. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Siemens
- Siveillance Control Pro V3.0
08 Sep 2026
Published
08 Sep 2026
Updated
CVSS v3.1
CRITICAL (9.0)
EPSS
0.19%
KEV
Description
A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this vulnerability could allow an attacker to gain root access on the host system, potentially leading to a full compromise of the affected OIS environment.
Statistics
- 1 Post
Last activity: 3 hours ago
Fediverse
Two critical Siemens vulnerabilities (CVE-2026-18963, CVE-2026-50093) allow account takeover and root access. See affected versions and fixes.
#Siemens #CyberSecurity #ICS #OTSecurity #CVE #IndustrialEdge #Vulnerability #InfoSec
Overview
- N-able
- N-central
05 Sep 2026
Published
08 Sep 2026
Updated
CVSS v4.0
MEDIUM (6.9)
EPSS
0.29%
KEV
Description
A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4
Statistics
- 1 Post
- 2 Interactions
Last activity: 16 hours ago
Bluesky
Overview
Description
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Statistics
- 1 Post
- 2 Interactions
Last activity: 16 hours ago
Bluesky
Overview
- N-able
- N-central
05 Sep 2026
Published
08 Sep 2026
Updated
CVSS v4.0
HIGH (7.7)
EPSS
0.30%
KEV
Description
An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs
Statistics
- 1 Post
- 2 Interactions
Last activity: 16 hours ago
Bluesky
Overview
- Microsoft
- Windows 10 Version 1607
08 Sep 2026
Published
08 Sep 2026
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
Pending
KEV
Description
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
Statistics
- 1 Post
Last activity: Last hour
Overview
- Mikrotik
- RouterOS
05 Sep 2026
Published
09 Sep 2026
Updated
CVSS v4.0
CRITICAL (9.2)
EPSS
0.24%
KEV
Description
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)
Statistics
- 1 Post
Last activity: 12 hours ago