#cve2026 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cve2026, aggregated by home.social.
-
CISA advisory ICSA-26-237-01 (rev. 1) discloses CVE-2026-75960 in Rently Smart Home firmware 20.1.0 and earlier. The vulnerability (CWE-522) allows extraction of PINs and Master PINs due to insufficiently protected credentials.
#CISA #CVE2026 #SmartHomeSecurity #ICSAdvisory
https://cyberworldops.eu/en/cisa-flaw-in-rently-smart-home-allows-retrieval-of-pins-and-master-pin
-
CISA advisory ICSA-26-237-01 (rev. 1) discloses CVE-2026-75960 in Rently Smart Home firmware 20.1.0 and earlier. The vulnerability (CWE-522) allows extraction of PINs and Master PINs due to insufficiently protected credentials.
#CISA #CVE2026 #SmartHomeSecurity #ICSAdvisory
https://cyberworldops.eu/en/cisa-flaw-in-rently-smart-home-allows-retrieval-of-pins-and-master-pin
-
Fallo en módulos DDR4/DDR5 sin bloqueo de escritura permite “inflar” memoria y saltarse protecciones en Windows (CVE-2026-23670). Microsoft ya publicó mitigaciones; Secure Boot ayuda. https://aidoo.news/noticia/65J81G
-
CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: https://radar.offseq.com/threat/cve-2026-77651-cwe-506-embedded-malicious-code-in-droundy-arrayref-c761153d40c2552d #OffSeq #RustLang #CVE2026 #Infosec
-
CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: https://radar.offseq.com/threat/cve-2026-77651-cwe-506-embedded-malicious-code-in-droundy-arrayref-c761153d40c2552d #OffSeq #RustLang #CVE2026 #Infosec
-
CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: https://radar.offseq.com/threat/cve-2026-77651-cwe-506-embedded-malicious-code-in-droundy-arrayref-c761153d40c2552d #OffSeq #RustLang #CVE2026 #Infosec
-
CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: https://radar.offseq.com/threat/cve-2026-77651-cwe-506-embedded-malicious-code-in-droundy-arrayref-c761153d40c2552d #OffSeq #RustLang #CVE2026 #Infosec
-
CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: https://radar.offseq.com/threat/cve-2026-77651-cwe-506-embedded-malicious-code-in-droundy-arrayref-c761153d40c2552d #OffSeq #RustLang #CVE2026 #Infosec
-
CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. https://radar.offseq.com/threat/cve-2026-76590-stack-based-buffer-overflow-in-trendnet-tew-755ap-37978d53e46251c0 #OffSeq #Vuln #IoTSec #CVE2026
-
CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. https://radar.offseq.com/threat/cve-2026-76590-stack-based-buffer-overflow-in-trendnet-tew-755ap-37978d53e46251c0 #OffSeq #Vuln #IoTSec #CVE2026
-
CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. https://radar.offseq.com/threat/cve-2026-76590-stack-based-buffer-overflow-in-trendnet-tew-755ap-37978d53e46251c0 #OffSeq #Vuln #IoTSec #CVE2026
-
CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. https://radar.offseq.com/threat/cve-2026-76590-stack-based-buffer-overflow-in-trendnet-tew-755ap-37978d53e46251c0 #OffSeq #Vuln #IoTSec #CVE2026
-
CISA patched six vulnerabilities in Malcolm that could allow arbitrary code execution or denial of service. The flaws span file handling, RBAC enforcement via Nginx/OpenResty Lua, and compressed archive processing, with a CVSS v3 score of 8.8. Operators running versions below 26.06.1 or 26.07.0 should patch immediately.
#CISAMalcolm #VulnerabilityDisclosure #NetworkSecurity #CVE2026
https://cyberworldops.eu/en/six-vulnerabilities-affect-cisa-malcolm-risk-of-arbitrary-code
-
CISA patched six vulnerabilities in Malcolm that could allow arbitrary code execution or denial of service. The flaws span file handling, RBAC enforcement via Nginx/OpenResty Lua, and compressed archive processing, with a CVSS v3 score of 8.8. Operators running versions below 26.06.1 or 26.07.0 should patch immediately.
#CISAMalcolm #VulnerabilityDisclosure #NetworkSecurity #CVE2026
https://cyberworldops.eu/en/six-vulnerabilities-affect-cisa-malcolm-risk-of-arbitrary-code
-
CISA patched six vulnerabilities in Malcolm that could allow arbitrary code execution or denial of service. The flaws span file handling, RBAC enforcement via Nginx/OpenResty Lua, and compressed archive processing, with a CVSS v3 score of 8.8. Operators running versions below 26.06.1 or 26.07.0 should patch immediately.
#CISAMalcolm #VulnerabilityDisclosure #NetworkSecurity #CVE2026
https://cyberworldops.eu/en/six-vulnerabilities-affect-cisa-malcolm-risk-of-arbitrary-code
-
A CVSS 10.0 unauthenticated arbitrary file read flaw in BigBlueButton path traversal exposes servers. Prevent attacks like CVE-2024-39302 and update now.
-
A CVSS 10.0 unauthenticated arbitrary file read flaw in BigBlueButton path traversal exposes servers. Prevent attacks like CVE-2024-39302 and update now.
-
A CVSS 10.0 unauthenticated arbitrary file read flaw in BigBlueButton path traversal exposes servers. Prevent attacks like CVE-2024-39302 and update now.
-
The Dutch NCSC reports active exploitation of CVE-2026-65400, an authentication flaw in macOS Screen Sharing. Attackers leverage public exploit code to deploy Monero miners on systems exposing the built-in VNC service on TCP/5900. Organizations running macOS with screen sharing enabled should audit their perimeter exposure immediately.
#CVE2026 #ScreenSharing #MoneroMiner #MacOSSecurity
https://cyberworldops.eu/en/macos-screen-sharing-actively-exploited-monero-miner-installed-on
-
The Dutch NCSC reports active exploitation of CVE-2026-65400, an authentication flaw in macOS Screen Sharing. Attackers leverage public exploit code to deploy Monero miners on systems exposing the built-in VNC service on TCP/5900. Organizations running macOS with screen sharing enabled should audit their perimeter exposure immediately.
#CVE2026 #ScreenSharing #MoneroMiner #MacOSSecurity
https://cyberworldops.eu/en/macos-screen-sharing-actively-exploited-monero-miner-installed-on
-
Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.
#ZeroDay #LegacyHive #PatchTuesday #CVE2026
https://cyberworldops.eu/en/microsoft-fixes-legacyhive-windows-zero-day-with-august-patches
-
Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.
#ZeroDay #LegacyHive #PatchTuesday #CVE2026
https://cyberworldops.eu/en/microsoft-fixes-legacyhive-windows-zero-day-with-august-patches
-
Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.
#ZeroDay #LegacyHive #PatchTuesday #CVE2026
https://cyberworldops.eu/en/microsoft-fixes-legacyhive-windows-zero-day-with-august-patches
-
Rapid7 released a proof-of-concept for CVE-2026-55040, a critical SharePoint vulnerability, on August 12. Within hours, Defused observed the exploit weaponized against SharePoint honeypots. Microsoft patched the flaw in July, yet Shadowserver still reports over 8,500 exposed servers. Patching is no longer optional.
#SharePoint #CVE2026 #VulnerabilityManagement #PatchTuesday
https://cyberworldops.eu/en/sharepoint-proof-of-concept-for-critical-flaw-already-used-in-attacks
-
Rapid7 released a proof-of-concept for CVE-2026-55040, a critical SharePoint vulnerability, on August 12. Within hours, Defused observed the exploit weaponized against SharePoint honeypots. Microsoft patched the flaw in July, yet Shadowserver still reports over 8,500 exposed servers. Patching is no longer optional.
#SharePoint #CVE2026 #VulnerabilityManagement #PatchTuesday
https://cyberworldops.eu/en/sharepoint-proof-of-concept-for-critical-flaw-already-used-in-attacks
-
Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.
#SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability
https://cyberworldops.eu/en/sharepoint-exploit-chain-enables-unauthenticated-rce
-
Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.
#SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability
https://cyberworldops.eu/en/sharepoint-exploit-chain-enables-unauthenticated-rce
-
Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.
#SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability
https://cyberworldops.eu/en/sharepoint-exploit-chain-enables-unauthenticated-rce
-
🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
https://github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated -
🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
https://github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated -
🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
https://github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated -
🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
https://github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated -
🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
https://github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated -
CVE-2026-67531 (CRITICAL): agentfront frontmcp <1.5.7 suffers a code injection flaw enabling remote code execution and theft of secrets. Upgrade to v1.5.7+ ASAP. https://radar.offseq.com/threat/cve-2026-67531-cwe-94-improper-control-of-generation-of-code-code-injection-in-agentfront-frontmcp-2c28d3d3312eb9f5 #OffSeq #Vulnerability #RCE #InfoSec #CVE2026
-
CVE-2026-67531 (CRITICAL): agentfront frontmcp <1.5.7 suffers a code injection flaw enabling remote code execution and theft of secrets. Upgrade to v1.5.7+ ASAP. https://radar.offseq.com/threat/cve-2026-67531-cwe-94-improper-control-of-generation-of-code-code-injection-in-agentfront-frontmcp-2c28d3d3312eb9f5 #OffSeq #Vulnerability #RCE #InfoSec #CVE2026
-
CVE-2026-67531 (CRITICAL): agentfront frontmcp <1.5.7 suffers a code injection flaw enabling remote code execution and theft of secrets. Upgrade to v1.5.7+ ASAP. https://radar.offseq.com/threat/cve-2026-67531-cwe-94-improper-control-of-generation-of-code-code-injection-in-agentfront-frontmcp-2c28d3d3312eb9f5 #OffSeq #Vulnerability #RCE #InfoSec #CVE2026
-
CVE-2026-67531 (CRITICAL): agentfront frontmcp <1.5.7 suffers a code injection flaw enabling remote code execution and theft of secrets. Upgrade to v1.5.7+ ASAP. https://radar.offseq.com/threat/cve-2026-67531-cwe-94-improper-control-of-generation-of-code-code-injection-in-agentfront-frontmcp-2c28d3d3312eb9f5 #OffSeq #Vulnerability #RCE #InfoSec #CVE2026
-
CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! https://radar.offseq.com/threat/cve-2026-12503-cwe-59-improper-link-resolution-before-file-access-link-following-in-loytec-lip-me20xc-acfbe89cb621dc0e #OffSeq #Vulnerability #ICS #Loytec #CVE2026
-
CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! https://radar.offseq.com/threat/cve-2026-12503-cwe-59-improper-link-resolution-before-file-access-link-following-in-loytec-lip-me20xc-acfbe89cb621dc0e #OffSeq #Vulnerability #ICS #Loytec #CVE2026
-
CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! https://radar.offseq.com/threat/cve-2026-12503-cwe-59-improper-link-resolution-before-file-access-link-following-in-loytec-lip-me20xc-acfbe89cb621dc0e #OffSeq #Vulnerability #ICS #Loytec #CVE2026
-
CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! https://radar.offseq.com/threat/cve-2026-12503-cwe-59-improper-link-resolution-before-file-access-link-following-in-loytec-lip-me20xc-acfbe89cb621dc0e #OffSeq #Vulnerability #ICS #Loytec #CVE2026
-
⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. https://thecybermind.co/mxq2
-
⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. https://thecybermind.co/mxq2
-
⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. https://thecybermind.co/mxq2
-
⚠️ CRITICAL THREAT: CVE-2026-58644 targets Microsoft SharePoint via deserialization. Active exploitation is verified. Is your perimeter secured? Get the forensic detection queries and hardening playbooks you need to defend your infrastructure now. https://thecybermind.co/9pxn
-
⚠️ CRITICAL THREAT: CVE-2026-58644 targets Microsoft SharePoint via deserialization. Active exploitation is verified. Is your perimeter secured? Get the forensic detection queries and hardening playbooks you need to defend your infrastructure now. https://thecybermind.co/9pxn
-
CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. https://radar.offseq.com/threat/cve-2026-11961-cwe-269-improper-privilege-manageme-20cb46cff61ded54 #OffSeq #WordPress #CVE2026
-
CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. https://radar.offseq.com/threat/cve-2026-11961-cwe-269-improper-privilege-manageme-20cb46cff61ded54 #OffSeq #WordPress #CVE2026
-
CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. https://radar.offseq.com/threat/cve-2026-11961-cwe-269-improper-privilege-manageme-20cb46cff61ded54 #OffSeq #WordPress #CVE2026
-
CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. https://radar.offseq.com/threat/cve-2026-11961-cwe-269-improper-privilege-manageme-20cb46cff61ded54 #OffSeq #WordPress #CVE2026
-
via @dotnet : .NET and .NET Framework July 2026 servicing releases updates
https://ift.tt/0YxwhW3
#dotnet #dotnetcore #dotnetframework #servicingupdates #July2026 #securityupdates #CVE2026 #CVE2026-47300 #CVE2026-47302 #CVE2026-47303 #CVE2026-47304 #CVE2026-5052… -
via @dotnet : .NET and .NET Framework July 2026 servicing releases updates
https://ift.tt/0YxwhW3
#dotnet #dotnetcore #dotnetframework #servicingupdates #July2026 #securityupdates #CVE2026 #CVE2026-47300 #CVE2026-47302 #CVE2026-47303 #CVE2026-47304 #CVE2026-5052… -
via @dotnet : .NET and .NET Framework July 2026 servicing releases updates
https://ift.tt/0YxwhW3
#dotnet #dotnetcore #dotnetframework #servicingupdates #July2026 #securityupdates #CVE2026 #CVE2026-47300 #CVE2026-47302 #CVE2026-47303 #CVE2026-47304 #CVE2026-5052… -
via @dotnet : .NET and .NET Framework July 2026 servicing releases updates
https://ift.tt/0YxwhW3
#dotnet #dotnetcore #dotnetframework #servicingupdates #July2026 #securityupdates #CVE2026 #CVE2026-47300 #CVE2026-47302 #CVE2026-47303 #CVE2026-47304 #CVE2026-5052… -
via @dotnet : .NET and .NET Framework July 2026 servicing releases updates
https://ift.tt/0YxwhW3
#dotnet #dotnetcore #dotnetframework #servicingupdates #July2026 #securityupdates #CVE2026 #CVE2026-47300 #CVE2026-47302 #CVE2026-47303 #CVE2026-47304 #CVE2026-5052… -
June 2026 marked a pivotal shift in cybersecurity, with a record wave of critical zero-days and 15 devastating flaws targeting HTTP.sys, cloud nodes, and critical assets. Dive deep into the full CVE technical analysis on our blog:
https://denizhalil.com/2026/07/03/june-2026-cybersecurity-analysis/ 🛡️🔒
-
June 2026 marked a pivotal shift in cybersecurity, with a record wave of critical zero-days and 15 devastating flaws targeting HTTP.sys, cloud nodes, and critical assets. Dive deep into the full CVE technical analysis on our blog:
https://denizhalil.com/2026/07/03/june-2026-cybersecurity-analysis/ 🛡️🔒