24h | 7d | 30d

Overview

  • MSI
  • Radix AXE6600

08 Aug 2026
Published
08 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture fallback

MSI Radix AXE6600 routers (v781521) affected by CRITICAL CVE-2026-71991 🛡️. OS command injection via TelnetSSH enables remote root access. Restrict Telnet, segment devices, monitor for vendor fixes. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • checkpoint
  • Security Management Server

03 Aug 2026
Published
05 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.99%

KEV

Description

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
📢 Check Point : faille critique d'authentification CVE-2026-18574 sur Security Management Server 📰 Source : Cyber Security News — Date : 4 août 2026 Check Point a publié des mises à jour de sécurité pour corriger une… 🟡 vérification factuelle moyenne #CheckPoint #AuthenticationBypass #Cyberveille
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • HKUDS
  • LightRAG

07 Aug 2026
Published
07 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.34%

KEV

Description

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge graph, cancel pipelines, clear caches, and consume LLM resources. This issue is mitigated in version 1.5.5rc1.

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture fallback

CVE-2026-61808 - Critical unauthenticated access in LightRAG API server. Full data breach, doc manipulation, LLM abuse. CVSS 9.8. Upgrade to 1.5.5rc1 immediately. #CVE #LightRAG #infosec

valtersit.com/cve/CVE-2026-618

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Niklas Portmann
  • Azure Based Remote Cache Plugin for Nx
  • nx-remotecache-azure

10 Jun 2025
Published
10 Jun 2025
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.20%

KEV

Description

A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remote cache (such as those using Amazon S3, Google Cloud Storage, or similar object storage) that allows any contributor with pull request privileges to inject compromised artifacts from an untrusted environment into trusted production environments without detection.  The vulnerability exploits a fundamental design flaw in the "first-to-cache wins" principle, where artifacts built in untrusted environments (feature branches, pull requests) can poison the cache used by trusted environments (protected branches, production deployments).  This attack bypasses all traditional security measures including encryption, access controls, and checksum validation because the poisoning occurs during the artifact construction phase, before any security measures are applied.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

This bothers me.

Nx v1 was released in 2018, yet nx.dev/blog/cve-2025-36852-cri (CREEP) was only discovered in 2025 (and is, disingenuously, described as a "race condition", which it is not - it's just inappropriate use of shared resources without trust boundaries).

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • thomaspoignant
  • scim-patch

07 Aug 2026
Published
07 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.25%

KEV

Description

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch, `Object.prototype.someProp` is set process-wide, affecting every plain object in the Node process. Any service that calls `scimPatch()` on attacker-controlled JSON (i.e. any SCIM endpoint accepting `PATCH` from an external IdP) is exploitable on a stock Node runtime. Version 0.9.1 contains a patch. A workaround is available. Calling `Object.freeze(Object.prototype)` (and the same on `Array.prototype`, `Function.prototype`) at process startup neutralizes this class of bug — assignment to a frozen prototype becomes a silent no-op in sloppy mode or a `TypeError` in strict mode. Node's `--frozen-intrinsics` flag does this for built-ins automatically.

Statistics

  • 1 Post

Last activity: Last hour

Fediverse

Profile picture fallback

CVE-2026-48170 - Critical prototype pollution in scim-patch <0.9.1. Attacker-controlled SCIM PATCH can pollute Object.prototype process-wide. CVSS 9.1. Unpatched - update immediately. #CVE #NodeJS #infosec

valtersit.com/cve/CVE-2026-481

  • 0
  • 0
  • 0
  • Last hour

Overview

  • SonicWall
  • SMA1000

14 Jul 2026
Published
04 Aug 2026
Updated

CVSS
Pending
EPSS
78.44%

Description

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Statistics

  • 1 Post

Last activity: 16 hours ago

Overview

  • SonicWall
  • SMA1000

14 Jul 2026
Published
04 Aug 2026
Updated

CVSS
Pending
EPSS
76.35%

Description

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Statistics

  • 1 Post

Last activity: 16 hours ago
Showing 21 to 27 of 27 CVEs