#cve2026 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cve2026, aggregated by home.social.
-
via @dotnet : .NET and .NET Framework September 2026 servicing releases updates
https://ift.tt/NOC0zZb
#NET #DotNET #NETCore #NETFramework #SecurityUpdates #September2026 #servicingupdates #CVE2026 #Vulnerability #SecurityFixes #DotNetSecurity #dotnetnews #Relea… -
PaperCut confirmed active exploitation of two pre-authentication RCE vulnerabilities on August 27, 2026. Huntress found evidence in two customer environments and reproduced the full attack chain from scratch against a clean install. Unauthenticated attackers can execute arbitrary code on exposed servers with no credentials required.
#PaperCut #PreAuthRCE #CVE2026 #ThreatIntelligence
https://cyberworldops.eu/en/papercut-under-attack-two-flaws-allow-pre-authentication-rce-race-to
-
CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: https://radar.offseq.com/threat/cve-2026-77651-cwe-506-embedded-malicious-code-in-droundy-arrayref-c761153d40c2552d #OffSeq #RustLang #CVE2026 #Infosec
-
CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. https://radar.offseq.com/threat/cve-2026-76590-stack-based-buffer-overflow-in-trendnet-tew-755ap-37978d53e46251c0 #OffSeq #Vuln #IoTSec #CVE2026
-
CISA patched six vulnerabilities in Malcolm that could allow arbitrary code execution or denial of service. The flaws span file handling, RBAC enforcement via Nginx/OpenResty Lua, and compressed archive processing, with a CVSS v3 score of 8.8. Operators running versions below 26.06.1 or 26.07.0 should patch immediately.
#CISAMalcolm #VulnerabilityDisclosure #NetworkSecurity #CVE2026
https://cyberworldops.eu/en/six-vulnerabilities-affect-cisa-malcolm-risk-of-arbitrary-code
-
A CVSS 10.0 unauthenticated arbitrary file read flaw in BigBlueButton path traversal exposes servers. Prevent attacks like CVE-2024-39302 and update now.
-
Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.
#ZeroDay #LegacyHive #PatchTuesday #CVE2026
https://cyberworldops.eu/en/microsoft-fixes-legacyhive-windows-zero-day-with-august-patches
-
Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.
#SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability
https://cyberworldops.eu/en/sharepoint-exploit-chain-enables-unauthenticated-rce
-
🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
https://github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated -
CVE-2026-67531 (CRITICAL): agentfront frontmcp <1.5.7 suffers a code injection flaw enabling remote code execution and theft of secrets. Upgrade to v1.5.7+ ASAP. https://radar.offseq.com/threat/cve-2026-67531-cwe-94-improper-control-of-generation-of-code-code-injection-in-agentfront-frontmcp-2c28d3d3312eb9f5 #OffSeq #Vulnerability #RCE #InfoSec #CVE2026
-
CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! https://radar.offseq.com/threat/cve-2026-12503-cwe-59-improper-link-resolution-before-file-access-link-following-in-loytec-lip-me20xc-acfbe89cb621dc0e #OffSeq #Vulnerability #ICS #Loytec #CVE2026
-
⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. https://thecybermind.co/mxq2
-
CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. https://radar.offseq.com/threat/cve-2026-11961-cwe-269-improper-privilege-manageme-20cb46cff61ded54 #OffSeq #WordPress #CVE2026
-
via @dotnet : .NET and .NET Framework July 2026 servicing releases updates
https://ift.tt/0YxwhW3
#dotnet #dotnetcore #dotnetframework #servicingupdates #July2026 #securityupdates #CVE2026 #CVE2026-47300 #CVE2026-47302 #CVE2026-47303 #CVE2026-47304 #CVE2026-5052… -
CVE-2026-12784 | HIGH severity in IM-Magic Partition Resizer ≤7.9.0: improper access controls in MDA_NTDRV.sys kernel driver. Local exploit is public. Restrict access or remove vulnerable versions. https://radar.offseq.com/threat/cve-2026-12784-improper-access-controls-in-im-magi-c8e575e26aa27402 #OffSeq #Vulnerability #SysSec #CVE2026
-
Notepad++ Zero-Click RCE via Path Traversal (CVE-2026-52884)
https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-p58x-r3c9-x9p6
#HackerNews #Notepad++ #ZeroClick #RCE #PathTraversal #CVE2026 #52884 #Cybersecurity
-
via @dotnet : .NET and .NET Framework June 2026 servicing releases updates
https://ift.tt/zfgkeIO
#dotnet #dotnet6 #dotnet7 #dotnet8 #dotnetcore #netservicing #updates #June2026 #securityupdates #CVE2026 #CVE2026-45591 #CVE2026-45491 #CVE2026-45490 #releaseNotes… -
🛑 HIGH: CVE-2026-10161 in TRENDnet TEW-432BRP (v3.10B20) — stack buffer overflow in formResetStatistic can be exploited remotely. No patch — device is EOL. Replace urgently! https://radar.offseq.com/threat/cve-2026-10161-stack-based-buffer-overflow-in-tren-3a604145 #OffSeq #Vuln #IoTSecurity #CVE2026 #Router
-
Researchers report "NGINX Rift" (CVE-2026-42945) is being probed and exploited days after disclosure — attackers are scanning exposed servers for the 18‑year bug. Patches released; teams urged to remediate. 🔍⚠️🛡️ #NGINX #infosec #CVE2026-42945 https://www.theregister.com/security/2026/05/18/nginx-rift-attackers-waste-no-time-targeting-exposed-servers/5241851