24h | 7d | 30d

Overview

  • Cisco
  • Cisco Secure Email

02 Sep 2026
Published
02 Sep 2026
Updated

CVSS v3.1
MEDIUM (5.9)
EPSS
0.15%

KEV

Description

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
Cisco Secure EmailにS/MIMEの脆弱性(CVE-2026-20354,CVE-2026-20355)、暗号化メールの平文取得につながる可能性 IP電話のDoSも公表 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
📢 [VULN] Une VM pour prendre le contrôle de votre PC : patchez VMware Workstation et Fusion - CVE-2026-59346 CVE-2026-59347 Vous utilisez VMware Workstation Pro ou VMware Fusion ? Passez par la case maintenance. #Vulnérabilité #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Red Hat
  • Red Hat Enterprise Linux 10
  • ipa

07 Sep 2026
Published
07 Sep 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Patch the critical FreeIPA CVE-2026-76578 immediately. This FreeIPA vulnerability allows complete, unauthenticated administrative access to your servers.

securityonline.info/freeipa-cv

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Mikrotik
  • RouterOS

05 Sep 2026
Published
07 Sep 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.46%

KEV

Description

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-67281) MikroTik RouterOS Unauthenticated File Read via WebFig" and "Emerging Threat: (CVE-2026-81891) elFinder Remote Code Execution via ZIP Extraction MIME Bypass". #cybersecurity https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Studio-42
  • elFinder

31 Aug 2026
Published
01 Sep 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.53%

KEV

Description

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent from mime.types, the staticMimeMap entries that map them to text/x-php are not applied, and allowPutMime() permits extraction even when uploadDeny blocks text/x-php. An attacker with ZIP upload permission can extract PHP-executable files into a web-accessible files/ directory and achieve remote code execution when the server executes those extensions. This issue is fixed in version 2.1.70.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-67281) MikroTik RouterOS Unauthenticated File Read via WebFig" and "Emerging Threat: (CVE-2026-81891) elFinder Remote Code Execution via ZIP Extraction MIME Bypass". #cybersecurity https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Red Hat
  • Red Hat Enterprise Linux 10
  • ipa

20 Aug 2026
Published
27 Aug 2026
Updated

CVSS
Pending
EPSS
0.27%

KEV

Description

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Patch the critical FreeIPA CVE-2026-76578 immediately. This FreeIPA vulnerability allows complete, unauthenticated administrative access to your servers.

securityonline.info/freeipa-cv

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Cisco
  • Cisco Secure Email

02 Sep 2026
Published
02 Sep 2026
Updated

CVSS v3.1
MEDIUM (5.9)
EPSS
0.15%

KEV

Description

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
Cisco Secure EmailにS/MIMEの脆弱性(CVE-2026-20354,CVE-2026-20355)、暗号化メールの平文取得につながる可能性 IP電話のDoSも公表 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
📢 [VULN] Une VM pour prendre le contrôle de votre PC : patchez VMware Workstation et Fusion - CVE-2026-59346 CVE-2026-59347 Vous utilisez VMware Workstation Pro ou VMware Fusion ? Passez par la case maintenance. #Vulnérabilité #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • jfrog
  • artifactory

28 Aug 2026
Published
03 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
7.67%

Description

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Statistics

  • 1 Post

Last activity: 11 hours ago

Bluesky

Profile picture fallback
~Checkpoint~ Critical zero-days hit SonicWall and JFrog; AI attacks and data breaches expand. - IOCs: CVE-2026-83548, CVE-2026-83549, CVE-2026-82329 - #CVE #Ransomware #ThreatIntel
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Mikrotik
  • RouterOS

05 Sep 2026
Published
05 Sep 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.44%

KEV

Description

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Statistics

  • 1 Post

Last activity: 4 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 4h ago
Showing 41 to 50 of 50 CVEs