24h | 7d | 30d

Overview

  • 2100 Technology
  • Official Document Management System

17 Aug 2026
Published
17 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.94%

KEV

Description

Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CVE-2026-74845 (HIGH, CVSS 8.7): 2100 Technology Official Document Management System lets authenticated attackers upload dangerous files — risk of code execution. No patch yet. Limit upload rights & monitor files. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 5h ago

Overview

  • JetBrains
  • TeamCity

27 Jul 2026
Published
06 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
10.72%

Description

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture fallback
JetBrains TeamCity(オンプレミス版)におけるリモートコード実行につながる脆弱性(CVE-2026-63077)について #JPCERTCC (Aug 13) www.jpcert.or.jp/newsflash/20...
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Microsoft
  • Azure Kubernetes Service

09 Jun 2026
Published
14 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.34%

KEV

Description

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

Statistics

  • 2 Posts

Last activity: 3 hours ago

Bluesky

Profile picture fallback
From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193)
  • 0
  • 0
  • 1
  • 3h ago

Overview

  • Edimax
  • EW-7478APC

16 Aug 2026
Published
16 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.47%

KEV

Description

A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Statistics

  • 1 Post

Last activity: 15 hours ago

Fediverse

Profile picture fallback

CVE-2026-19961: CRITICAL buffer overflow in Edimax EW-7478APC v1.04 via /goform/formWlSiteSurvey (selSSID). Remote code execution is possible; no patch, public exploit exists. Isolate affected devices. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Fortinet
  • FortiManager

12 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
HIGH (7.3)
EPSS
0.59%

KEV

Description

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture fallback
Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468) rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Red Hat
  • Multicluster Engine for Kubernetes
  • multicluster-engine/cluster-curator-controller-rhel9

12 Aug 2026
Published
12 Aug 2026
Updated

CVSS
Pending
EPSS
0.37%

KEV

Description

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Red Hat fixes RHACM remote code execution flaws, including CVE-2026-72526 and CVE-2026-73268, both CVSS 9.9. See patch and mitigation steps.

securityonline.info/rhacm-remo

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Red Hat
  • Red Hat Advanced Cluster Management for Kubernetes 2
  • rhacm2/multicloud-integrations-rhel9

12 Aug 2026
Published
12 Aug 2026
Updated

CVSS
Pending
EPSS
0.30%

KEV

Description

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Red Hat fixes RHACM remote code execution flaws, including CVE-2026-72526 and CVE-2026-73268, both CVSS 9.9. See patch and mitigation steps.

securityonline.info/rhacm-remo

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Fortinet
  • FortiWeb

12 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.51%

KEV

Description

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture fallback
Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468) rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 0
  • 0
  • 16h ago
Showing 31 to 38 of 38 CVEs