home.social

#cve2026 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve2026, aggregated by home.social.

fetched live
  1. PaperCut confirmed active exploitation of two pre-authentication RCE vulnerabilities on August 27, 2026. Huntress found evidence in two customer environments and reproduced the full attack chain from scratch against a clean install. Unauthenticated attackers can execute arbitrary code on exposed servers with no credentials required.

    #PaperCut #PreAuthRCE #CVE2026 #ThreatIntelligence

    cyberworldops.eu/en/papercut-u

  2. CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

  3. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  4. CISA patched six vulnerabilities in Malcolm that could allow arbitrary code execution or denial of service. The flaws span file handling, RBAC enforcement via Nginx/OpenResty Lua, and compressed archive processing, with a CVSS v3 score of 8.8. Operators running versions below 26.06.1 or 26.07.0 should patch immediately.

    #CISAMalcolm #VulnerabilityDisclosure #NetworkSecurity #CVE2026

    cyberworldops.eu/en/six-vulner

  5. Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.

    #ZeroDay #LegacyHive #PatchTuesday #CVE2026

    cyberworldops.eu/en/microsoft-

  6. Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

    #SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability

    cyberworldops.eu/en/sharepoint

  7. 🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
    github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated

  8. CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Loytec #CVE2026

  9. ⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. thecybermind.co/mxq2

    #CyberSecurity #InfoSec #Fortinet #ThreatIntel #CVE2026

  10. CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026

  11. CVE-2026-12784 | HIGH severity in IM-Magic Partition Resizer ≤7.9.0: improper access controls in MDA_NTDRV.sys kernel driver. Local exploit is public. Restrict access or remove vulnerable versions. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #SysSec #CVE2026

  12. 🛑 HIGH: CVE-2026-10161 in TRENDnet TEW-432BRP (v3.10B20) — stack buffer overflow in formResetStatistic can be exploited remotely. No patch — device is EOL. Replace urgently! radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #CVE2026 #Router

  13. Researchers report "NGINX Rift" (CVE-2026-42945) is being probed and exploited days after disclosure — attackers are scanning exposed servers for the 18‑year bug. Patches released; teams urged to remediate. 🔍⚠️🛡️ #NGINX #infosec #CVE2026-42945 theregister.com/security/2026/