Overview
Description
Statistics
- 1 Post
- 28 Interactions
Fediverse
Go hack more drone shit.
https://nvd.nist.gov/vuln/detail/cve-2026-78251
DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in /blackbox/upgrade/, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
Overview
Description
Statistics
- 3 Posts
Fediverse
Critical Next.js & libheif RCE Vulnerabilities: Inside the August 2026 AVIF Zero-Day Exploit Chain
Critical Next.js RCE vulnerabilities affect AVIF image optimization and Windows servers. Learn about libheif, GHSA-2xp9-vwfh-vxw4, CVE-2026-75604https://thecybersecguru.com/news/nextjs-rce-avif-libheif-cve-2026-75604/
#NextJS: Two Critical Vulnerabilities in NextJS allow unauthenticated #RCE: one through crafted AVIF images, another via path traversal on Windows (CVE-2026-75604).
Upgrade your NextJS immediately to v15.5.24 or 16.3.3!:
👇
https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html
Overview
- mcp-router
- mcp-router
Description
Statistics
- 1 Post
- 8 Interactions
Fediverse
Go hack more MCP shit.
https://nvd.nist.gov/vuln/detail/cve-2026-81094
The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP server it fronted, to anyone able to reach the port. Release 0.6.3 defaults the host to the loopback address and refuses to start without a token whenever the host it is given is not a loopback address; no earlier release carries either check.
Overview
- Spring
- Spring Security
Description
Statistics
- 1 Post
- 5 Interactions
Fediverse
wat
https://spring.io/security/cve-2026-59270
Spring Security's embedded UnboundID LDAP server (
UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.An attacker who could reach the LDAP listener port could authenticate using the well-known administrative bind DN, and then read or modify entries in the in-memory directory.
Overview
- WP Manage Ninja
- Fluent Boards Pro
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
CVE-2026-78276 - PHP Object Injection in Fluent Boards Pro <= 2.0.11. CVSS 7.2. Currently unpatched. Restrict access and mitigate now. #CVE #WordPress #infosec
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
⚠️💻 Mac flaw exploited
CVE-2026-65400 gives root access on exposed Macs; attackers deploy #Monero miners.
Overview
- Zbtlink
- L3_V2_8
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
Fucking LMAO
https://nvd.nist.gov/vuln/detail/cve-2026-74232
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.
Overview
- axew3
- WP w3all phpBB
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
CVE-2026-78293 - Unauthenticated XSS in WP w3all phpBB (<= 3.0.6). CVSS 7.1. Vulnerability is currently unpatched. Mitigate risk immediately. #CVE #WordPress #infosec
Overview
- Zbtlink
- WE1326
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
Bugdoor too?
https://nvd.nist.gov/vuln/detail/CVE-2026-74233
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.
Overview
- Konami
- Metal Gear Online 3
Description
Statistics
- 1 Post