#cve2026 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cve2026, aggregated by home.social.
-
CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! https://radar.offseq.com/threat/cve-2026-12503-cwe-59-improper-link-resolution-before-file-access-link-following-in-loytec-lip-me20xc-acfbe89cb621dc0e #OffSeq #Vulnerability #ICS #Loytec #CVE2026
-
CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. https://radar.offseq.com/threat/cve-2026-11961-cwe-269-improper-privilege-manageme-20cb46cff61ded54 #OffSeq #WordPress #CVE2026
-
via @dotnet : .NET and .NET Framework July 2026 servicing releases updates
https://ift.tt/0YxwhW3
#dotnet #dotnetcore #dotnetframework #servicingupdates #July2026 #securityupdates #CVE2026 #CVE2026-47300 #CVE2026-47302 #CVE2026-47303 #CVE2026-47304 #CVE2026-5052… -
via @dotnet : .NET and .NET Framework July 2026 servicing releases updates
https://ift.tt/0YxwhW3
#dotnet #dotnetcore #dotnetframework #servicingupdates #July2026 #securityupdates #CVE2026 #CVE2026-47300 #CVE2026-47302 #CVE2026-47303 #CVE2026-47304 #CVE2026-5052… -
June 2026 marked a pivotal shift in cybersecurity, with a record wave of critical zero-days and 15 devastating flaws targeting HTTP.sys, cloud nodes, and critical assets. Dive deep into the full CVE technical analysis on our blog:
https://denizhalil.com/2026/07/03/june-2026-cybersecurity-analysis/ 🛡️🔒
-
CVE-2026-12784 | HIGH severity in IM-Magic Partition Resizer ≤7.9.0: improper access controls in MDA_NTDRV.sys kernel driver. Local exploit is public. Restrict access or remove vulnerable versions. https://radar.offseq.com/threat/cve-2026-12784-improper-access-controls-in-im-magi-c8e575e26aa27402 #OffSeq #Vulnerability #SysSec #CVE2026
-
Notepad++ Zero-Click RCE via Path Traversal (CVE-2026-52884)
https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-p58x-r3c9-x9p6
#HackerNews #Notepad++ #ZeroClick #RCE #PathTraversal #CVE2026 #52884 #Cybersecurity
-
Notepad++ Zero-Click RCE via Path Traversal (CVE-2026-52884)
https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-p58x-r3c9-x9p6
#HackerNews #Notepad++ #ZeroClick #RCE #PathTraversal #CVE2026 #52884 #Cybersecurity
-
via @dotnet : .NET and .NET Framework June 2026 servicing releases updates
https://ift.tt/zfgkeIO
#dotnet #dotnet6 #dotnet7 #dotnet8 #dotnetcore #netservicing #updates #June2026 #securityupdates #CVE2026 #CVE2026-45591 #CVE2026-45491 #CVE2026-45490 #releaseNotes… -
via @dotnet : .NET and .NET Framework June 2026 servicing releases updates
https://ift.tt/zfgkeIO
#dotnet #dotnet6 #dotnet7 #dotnet8 #dotnetcore #netservicing #updates #June2026 #securityupdates #CVE2026 #CVE2026-45591 #CVE2026-45491 #CVE2026-45490 #releaseNotes… -
🛑 HIGH: CVE-2026-10161 in TRENDnet TEW-432BRP (v3.10B20) — stack buffer overflow in formResetStatistic can be exploited remotely. No patch — device is EOL. Replace urgently! https://radar.offseq.com/threat/cve-2026-10161-stack-based-buffer-overflow-in-tren-3a604145 #OffSeq #Vuln #IoTSecurity #CVE2026 #Router
-
Researchers report "NGINX Rift" (CVE-2026-42945) is being probed and exploited days after disclosure — attackers are scanning exposed servers for the 18‑year bug. Patches released; teams urged to remediate. 🔍⚠️🛡️ #NGINX #infosec #CVE2026-42945 https://www.theregister.com/security/2026/05/18/nginx-rift-attackers-waste-no-time-targeting-exposed-servers/5241851
-
Researchers report "NGINX Rift" (CVE-2026-42945) is being probed and exploited days after disclosure — attackers are scanning exposed servers for the 18‑year bug. Patches released; teams urged to remediate. 🔍⚠️🛡️ #NGINX #infosec #CVE2026-42945 https://www.theregister.com/security/2026/05/18/nginx-rift-attackers-waste-no-time-targeting-exposed-servers/5241851
-
🌟 Oh no, another CVE just dropped! 🙄 It's a good thing we have an endless supply of version numbers and cryptic abbreviations to keep us entertained while the "experts" scramble to patch their precious AI toys. 🤖 Just sit back and watch as the "critical severity" takes a leisurely stroll through insecure headers, because who needs proper input validation in 2026 anyway? 😂
https://badhost.org/ #CVE2026 #AIsecurity #inputvalidation #cybersecurity #vulnerabilities #HackerNews #ngated -
🌟 Oh no, another CVE just dropped! 🙄 It's a good thing we have an endless supply of version numbers and cryptic abbreviations to keep us entertained while the "experts" scramble to patch their precious AI toys. 🤖 Just sit back and watch as the "critical severity" takes a leisurely stroll through insecure headers, because who needs proper input validation in 2026 anyway? 😂
https://badhost.org/ #CVE2026 #AIsecurity #inputvalidation #cybersecurity #vulnerabilities #HackerNews #ngated -
"Dirty Frag" (CVE-2026-43284): The Second Linux Root Exploit in Eight Days
https://www.copahost.com/blog/dirty-frag-cve-2026-43284/
#HackerNews #DirtyFrag #CVE2026 #Linux #Exploit #Cybersecurity #Vulnerability #RootAccess
-
"Dirty Frag" (CVE-2026-43284): The Second Linux Root Exploit in Eight Days
https://www.copahost.com/blog/dirty-frag-cve-2026-43284/
#HackerNews #DirtyFrag #CVE2026 #Linux #Exploit #Cybersecurity #Vulnerability #RootAccess
-
🚨 CVE-2026-31431 ("Copy Fail")
A Linux kernel flaw enabling reliable root privilege escalation from local access.
🔍 Affects most systems since ~2017
⚠️ High impact, stealthy exploitation
🛠️ Fix: Patch immediately & restrict AF_ALG if unused
🛡️ Mitigated in RELIANOID EE 8.6 and CE 7.10
👉 Technical troubleshooting guide: https://www.relianoid.com/resources/knowledge-base/troubleshooting/cve-2026-31431-linux-kernel-copy-fail-vulnerability/
#CyberSecurity #Linux #CVE2026 #InfoSec #DevSecOps -
The Internet Is Falling Down- CPanel/WHM Authentication Bypass CVE-2026-41940
#HackerNews #CPanel #WHM #Security #Vulnerability #Authentication #Bypass #CVE2026-41940 #Cybersecurity
-
The Internet Is Falling Down- CPanel/WHM Authentication Bypass CVE-2026-41940
#HackerNews #CPanel #WHM #Security #Vulnerability #Authentication #Bypass #CVE2026-41940 #Cybersecurity
-
Die Entdecker nennen die Lücke "Copy Fail": Ein 732-Byte-Python-Exploit erlaubt lokalen Root-Zugriff auf viele Linux-Distributionen seit 2017. CVE-2026-31431 (CVSS 7.8). Update-Kernel dringend empfohlen; Workarounds: algif_aead blacklisten / seccomp. 🔓🐧⚠️ #Linux #Cybersecurity #CVE2026-31431 https://www.heise.de/news/Copy-Fail-Linux-root-in-allen-grossen-Distributionen-mit-732-Byte-Python-11277590.html
1/2 Fix bellow
-
Die Entdecker nennen die Lücke "Copy Fail": Ein 732-Byte-Python-Exploit erlaubt lokalen Root-Zugriff auf viele Linux-Distributionen seit 2017. CVE-2026-31431 (CVSS 7.8). Update-Kernel dringend empfohlen; Workarounds: algif_aead blacklisten / seccomp. 🔓🐧⚠️ #Linux #Cybersecurity #CVE2026-31431 https://www.heise.de/news/Copy-Fail-Linux-root-in-allen-grossen-Distributionen-mit-732-Byte-Python-11277590.html
1/2 Fix bellow
-
via @dotnet : .NET and .NET Framework April 2026 servicing releases updates
https://ift.tt/wyUxFph
#DotNet #NET #NETCore #NETFramework #April2026 #ServicingUpdate #SecurityUpdate #CVE2026 #CVE2026-23666 #CVE2026-26171 #CVE2026-32178 #CVE2026-32203 #CVE2026-32226… -
via @dotnet : .NET and .NET Framework April 2026 servicing releases updates
https://ift.tt/wyUxFph
#DotNet #NET #NETCore #NETFramework #April2026 #ServicingUpdate #SecurityUpdate #CVE2026 #CVE2026-23666 #CVE2026-26171 #CVE2026-32178 #CVE2026-32203 #CVE2026-32226… -
via @dotnet : .NET and .NET Framework March 2026 servicing releases updates
https://ift.tt/hg0cdb3
#dotnet #dotnetcore #dotnetframework #servicingupdates #securityupdates #CVE2026 #CVE2026-26130 #CVE2026-26127 #CVE2026-26131 #ASP.NETCore #EntityFrameworkCore #Ru… -
via @dotnet : .NET and .NET Framework March 2026 servicing releases updates
https://ift.tt/hg0cdb3
#dotnet #dotnetcore #dotnetframework #servicingupdates #securityupdates #CVE2026 #CVE2026-26130 #CVE2026-26127 #CVE2026-26131 #ASP.NETCore #EntityFrameworkCore #Ru… -
CVE-2026-21902 represents a high-impact infrastructure exposure.
Affected platform: Junos OS Evolved on PTX series routers.
Attack vector: Unauthenticated network access.
Privilege level: Root execution.
Service: On-Box Anomaly Detection, enabled by default.Strategic risk:
• Traffic interception capability
• Policy manipulation
• Controller redirection
• Lateral pivoting
• Long-term foothold persistence
Although no exploitation has been observed, historically, high-performance routing infrastructure is a prime target due to its control-plane visibility and network centrality.Recommended actions:
– Immediate patch validation
– Control-plane traffic monitoring
– Service exposure review
– Network segmentation validation
– Threat hunting for anomalous routing behavior
Are infrastructure devices integrated into your continuous detection engineering pipeline?Source: https://www.securityweek.com/juniper-networks-ptx-routers-affected-by-critical-vulnerability/
Engage below.
Follow TechNadu for high-signal vulnerability intelligence.
Repost to strengthen security awareness.#Infosec #CVE2026 #Juniper #RouterSecurity #CriticalInfrastructure #ThreatModeling #DetectionEngineering #NetworkDefense #ZeroTrustArchitecture #CyberRisk #SecurityOperations #VulnerabilityManagement
-
CVE-2026-2550 (CRITICAL): EFM iptime A6004MX (fw 14.18.2) allows unauthenticated uploads via /cgi/timepro.cgi — enabling full device compromise. No patch yet. Block access & monitor for malicious activity. https://radar.offseq.com/threat/cve-2026-2550-unrestricted-upload-in-efm-iptime-a6-a8baac0d #OffSeq #Vuln #RouterSecurity #CVE2026
-
Google has patched a high-severity Chrome WebView vulnerability tracked as CVE-2026-0628, caused by insufficient policy enforcement in the tag component.
The flaw could allow attackers to bypass security controls in applications embedding WebView, increasing risk across desktop and mobile ecosystems.
Full Article :
https://www.technadu.com/google-patches-high-severity-chrome-webview-flaw-cve-2026-0628-in-the-tag-component/617762/#ChromeSecurity #WebView #CVE2026 #Infosec #ApplicationSecurity