home.social

#cve2026 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve2026, aggregated by home.social.

fetched live
  1. PaperCut confirmed active exploitation of two pre-authentication RCE vulnerabilities on August 27, 2026. Huntress found evidence in two customer environments and reproduced the full attack chain from scratch against a clean install. Unauthenticated attackers can execute arbitrary code on exposed servers with no credentials required.

    #PaperCut #PreAuthRCE #CVE2026 #ThreatIntelligence

    cyberworldops.eu/en/papercut-u

  2. PaperCut confirmed active exploitation of two pre-authentication RCE vulnerabilities on August 27, 2026. Huntress found evidence in two customer environments and reproduced the full attack chain from scratch against a clean install. Unauthenticated attackers can execute arbitrary code on exposed servers with no credentials required.

    #PaperCut #PreAuthRCE #CVE2026 #ThreatIntelligence

    cyberworldops.eu/en/papercut-u

  3. PaperCut confirmed active exploitation of two pre-authentication RCE vulnerabilities on August 27, 2026. Huntress found evidence in two customer environments and reproduced the full attack chain from scratch against a clean install. Unauthenticated attackers can execute arbitrary code on exposed servers with no credentials required.

    #PaperCut #PreAuthRCE #CVE2026 #ThreatIntelligence

    cyberworldops.eu/en/papercut-u

  4. CISA advisory ICSA-26-237-01 (rev. 1) discloses CVE-2026-75960 in Rently Smart Home firmware 20.1.0 and earlier. The vulnerability (CWE-522) allows extraction of PINs and Master PINs due to insufficiently protected credentials.

    #CISA #CVE2026 #SmartHomeSecurity #ICSAdvisory

    cyberworldops.eu/en/cisa-flaw-

  5. CISA advisory ICSA-26-237-01 (rev. 1) discloses CVE-2026-75960 in Rently Smart Home firmware 20.1.0 and earlier. The vulnerability (CWE-522) allows extraction of PINs and Master PINs due to insufficiently protected credentials.

    #CISA #CVE2026 #SmartHomeSecurity #ICSAdvisory

    cyberworldops.eu/en/cisa-flaw-

  6. Fallo en módulos DDR4/DDR5 sin bloqueo de escritura permite “inflar” memoria y saltarse protecciones en Windows (CVE-2026-23670). Microsoft ya publicó mitigaciones; Secure Boot ayuda. aidoo.news/noticia/65J81G

    #SeguridadHardware #DDR5 #USENIX #CVE2026 #MemoriaRAM

  7. CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

  8. CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

  9. CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

  10. CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

  11. CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

  12. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  13. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  14. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  15. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  16. CISA patched six vulnerabilities in Malcolm that could allow arbitrary code execution or denial of service. The flaws span file handling, RBAC enforcement via Nginx/OpenResty Lua, and compressed archive processing, with a CVSS v3 score of 8.8. Operators running versions below 26.06.1 or 26.07.0 should patch immediately.

    #CISAMalcolm #VulnerabilityDisclosure #NetworkSecurity #CVE2026

    cyberworldops.eu/en/six-vulner

  17. CISA patched six vulnerabilities in Malcolm that could allow arbitrary code execution or denial of service. The flaws span file handling, RBAC enforcement via Nginx/OpenResty Lua, and compressed archive processing, with a CVSS v3 score of 8.8. Operators running versions below 26.06.1 or 26.07.0 should patch immediately.

    #CISAMalcolm #VulnerabilityDisclosure #NetworkSecurity #CVE2026

    cyberworldops.eu/en/six-vulner

  18. CISA patched six vulnerabilities in Malcolm that could allow arbitrary code execution or denial of service. The flaws span file handling, RBAC enforcement via Nginx/OpenResty Lua, and compressed archive processing, with a CVSS v3 score of 8.8. Operators running versions below 26.06.1 or 26.07.0 should patch immediately.

    #CISAMalcolm #VulnerabilityDisclosure #NetworkSecurity #CVE2026

    cyberworldops.eu/en/six-vulner

  19. The Dutch NCSC reports active exploitation of CVE-2026-65400, an authentication flaw in macOS Screen Sharing. Attackers leverage public exploit code to deploy Monero miners on systems exposing the built-in VNC service on TCP/5900. Organizations running macOS with screen sharing enabled should audit their perimeter exposure immediately.

    #CVE2026 #ScreenSharing #MoneroMiner #MacOSSecurity

    cyberworldops.eu/en/macos-scre

  20. The Dutch NCSC reports active exploitation of CVE-2026-65400, an authentication flaw in macOS Screen Sharing. Attackers leverage public exploit code to deploy Monero miners on systems exposing the built-in VNC service on TCP/5900. Organizations running macOS with screen sharing enabled should audit their perimeter exposure immediately.

    #CVE2026 #ScreenSharing #MoneroMiner #MacOSSecurity

    cyberworldops.eu/en/macos-scre

  21. Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.

    #ZeroDay #LegacyHive #PatchTuesday #CVE2026

    cyberworldops.eu/en/microsoft-

  22. Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.

    #ZeroDay #LegacyHive #PatchTuesday #CVE2026

    cyberworldops.eu/en/microsoft-

  23. Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.

    #ZeroDay #LegacyHive #PatchTuesday #CVE2026

    cyberworldops.eu/en/microsoft-

  24. Rapid7 released a proof-of-concept for CVE-2026-55040, a critical SharePoint vulnerability, on August 12. Within hours, Defused observed the exploit weaponized against SharePoint honeypots. Microsoft patched the flaw in July, yet Shadowserver still reports over 8,500 exposed servers. Patching is no longer optional.

    #SharePoint #CVE2026 #VulnerabilityManagement #PatchTuesday

    cyberworldops.eu/en/sharepoint

  25. Rapid7 released a proof-of-concept for CVE-2026-55040, a critical SharePoint vulnerability, on August 12. Within hours, Defused observed the exploit weaponized against SharePoint honeypots. Microsoft patched the flaw in July, yet Shadowserver still reports over 8,500 exposed servers. Patching is no longer optional.

    #SharePoint #CVE2026 #VulnerabilityManagement #PatchTuesday

    cyberworldops.eu/en/sharepoint

  26. Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

    #SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability

    cyberworldops.eu/en/sharepoint

  27. Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

    #SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability

    cyberworldops.eu/en/sharepoint

  28. Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

    #SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability

    cyberworldops.eu/en/sharepoint

  29. 🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
    github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated

  30. 🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
    github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated

  31. 🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
    github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated

  32. 🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
    github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated

  33. 🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
    github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated

  34. CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Loytec #CVE2026

  35. CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Loytec #CVE2026

  36. CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Loytec #CVE2026

  37. CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Loytec #CVE2026

  38. ⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. thecybermind.co/mxq2

    #CyberSecurity #InfoSec #Fortinet #ThreatIntel #CVE2026

  39. ⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. thecybermind.co/mxq2

    #CyberSecurity #InfoSec #Fortinet #ThreatIntel #CVE2026

  40. ⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. thecybermind.co/mxq2

    #CyberSecurity #InfoSec #Fortinet #ThreatIntel #CVE2026

  41. ⚠️ CRITICAL THREAT: CVE-2026-58644 targets Microsoft SharePoint via deserialization. Active exploitation is verified. Is your perimeter secured? Get the forensic detection queries and hardening playbooks you need to defend your infrastructure now. thecybermind.co/9pxn

    #CyberSecurity #InfoSec #SharePoint #CVE2026

  42. ⚠️ CRITICAL THREAT: CVE-2026-58644 targets Microsoft SharePoint via deserialization. Active exploitation is verified. Is your perimeter secured? Get the forensic detection queries and hardening playbooks you need to defend your infrastructure now. thecybermind.co/9pxn

    #CyberSecurity #InfoSec #SharePoint #CVE2026

  43. CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026

  44. CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026

  45. CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026

  46. CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026