24h | 7d | 30d

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 21 hours ago

Fediverse

Profile picture fallback

three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

patched in 4.14.6.

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

  • 1
  • 0
  • 0
  • 21h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 21 hours ago

Fediverse

Profile picture fallback

three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

patched in 4.14.6.

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

  • 1
  • 0
  • 0
  • 21h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 21 hours ago

Fediverse

Profile picture fallback

three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

patched in 4.14.6.

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

  • 1
  • 0
  • 0
  • 21h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

14 May 2026
Published
19 Jun 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
70.31%

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
~Recordedfuture~ Insikt Group identified 85 high-impact vulnerabilities in July 2026, a 44% increase, with 57 enabling RCE and 26 in CISA's KEV catalog. - IOCs: CVE-2026-0770, CVE-2018-0802, CVE-2026-42897 - #CVE #ThreatIntel #VulnManagement
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Microsoft Corporation
  • Equation Editor

10 Jan 2018
Published
21 Oct 2025
Updated

CVSS
Pending
EPSS
87.42%

Description

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
~Recordedfuture~ Insikt Group identified 85 high-impact vulnerabilities in July 2026, a 44% increase, with 57 enabling RCE and 26 in CISA's KEV catalog. - IOCs: CVE-2026-0770, CVE-2018-0802, CVE-2026-42897 - #CVE #ThreatIntel #VulnManagement
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Langflow
  • Langflow

23 Jan 2026
Published
22 Jul 2026
Updated

CVSS v3.0
CRITICAL (9.8)
EPSS
56.27%

Description

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
~Recordedfuture~ Insikt Group identified 85 high-impact vulnerabilities in July 2026, a 44% increase, with 57 enabling RCE and 26 in CISA's KEV catalog. - IOCs: CVE-2026-0770, CVE-2018-0802, CVE-2026-42897 - #CVE #ThreatIntel #VulnManagement
  • 0
  • 0
  • 0
  • 15h ago
Showing 41 to 46 of 46 CVEs