home.social

#cve2026 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve2026, aggregated by home.social.

fetched live
  1. CISA advisory ICSA-26-237-01 (rev. 1) discloses CVE-2026-75960 in Rently Smart Home firmware 20.1.0 and earlier. The vulnerability (CWE-522) allows extraction of PINs and Master PINs due to insufficiently protected credentials.

    #CISA #CVE2026 #SmartHomeSecurity #ICSAdvisory

    cyberworldops.eu/en/cisa-flaw-

  2. CISA advisory ICSA-26-237-01 (rev. 1) discloses CVE-2026-75960 in Rently Smart Home firmware 20.1.0 and earlier. The vulnerability (CWE-522) allows extraction of PINs and Master PINs due to insufficiently protected credentials.

    #CISA #CVE2026 #SmartHomeSecurity #ICSAdvisory

    cyberworldops.eu/en/cisa-flaw-

  3. Fallo en módulos DDR4/DDR5 sin bloqueo de escritura permite “inflar” memoria y saltarse protecciones en Windows (CVE-2026-23670). Microsoft ya publicó mitigaciones; Secure Boot ayuda. aidoo.news/noticia/65J81G

    #SeguridadHardware #DDR5 #USENIX #CVE2026 #MemoriaRAM

  4. CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

  5. CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

  6. CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

  7. CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

  8. CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

  9. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  10. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  11. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  12. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  13. CISA patched six vulnerabilities in Malcolm that could allow arbitrary code execution or denial of service. The flaws span file handling, RBAC enforcement via Nginx/OpenResty Lua, and compressed archive processing, with a CVSS v3 score of 8.8. Operators running versions below 26.06.1 or 26.07.0 should patch immediately.

    #CISAMalcolm #VulnerabilityDisclosure #NetworkSecurity #CVE2026

    cyberworldops.eu/en/six-vulner

  14. CISA patched six vulnerabilities in Malcolm that could allow arbitrary code execution or denial of service. The flaws span file handling, RBAC enforcement via Nginx/OpenResty Lua, and compressed archive processing, with a CVSS v3 score of 8.8. Operators running versions below 26.06.1 or 26.07.0 should patch immediately.

    #CISAMalcolm #VulnerabilityDisclosure #NetworkSecurity #CVE2026

    cyberworldops.eu/en/six-vulner

  15. CISA patched six vulnerabilities in Malcolm that could allow arbitrary code execution or denial of service. The flaws span file handling, RBAC enforcement via Nginx/OpenResty Lua, and compressed archive processing, with a CVSS v3 score of 8.8. Operators running versions below 26.06.1 or 26.07.0 should patch immediately.

    #CISAMalcolm #VulnerabilityDisclosure #NetworkSecurity #CVE2026

    cyberworldops.eu/en/six-vulner

  16. The Dutch NCSC reports active exploitation of CVE-2026-65400, an authentication flaw in macOS Screen Sharing. Attackers leverage public exploit code to deploy Monero miners on systems exposing the built-in VNC service on TCP/5900. Organizations running macOS with screen sharing enabled should audit their perimeter exposure immediately.

    #CVE2026 #ScreenSharing #MoneroMiner #MacOSSecurity

    cyberworldops.eu/en/macos-scre

  17. The Dutch NCSC reports active exploitation of CVE-2026-65400, an authentication flaw in macOS Screen Sharing. Attackers leverage public exploit code to deploy Monero miners on systems exposing the built-in VNC service on TCP/5900. Organizations running macOS with screen sharing enabled should audit their perimeter exposure immediately.

    #CVE2026 #ScreenSharing #MoneroMiner #MacOSSecurity

    cyberworldops.eu/en/macos-scre

  18. Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.

    #ZeroDay #LegacyHive #PatchTuesday #CVE2026

    cyberworldops.eu/en/microsoft-

  19. Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.

    #ZeroDay #LegacyHive #PatchTuesday #CVE2026

    cyberworldops.eu/en/microsoft-

  20. Microsoft patched the zero-day LegacyHive (CVE-2026-62832) in the August 2026 Patch Tuesday cycle, after it remained unpatched following July's updates. Researcher Nightmare Eclipse released a PoC exploit shortly after the July patches, sparking controversy over Microsoft's bug bounty and disclosure practices.

    #ZeroDay #LegacyHive #PatchTuesday #CVE2026

    cyberworldops.eu/en/microsoft-

  21. Rapid7 released a proof-of-concept for CVE-2026-55040, a critical SharePoint vulnerability, on August 12. Within hours, Defused observed the exploit weaponized against SharePoint honeypots. Microsoft patched the flaw in July, yet Shadowserver still reports over 8,500 exposed servers. Patching is no longer optional.

    #SharePoint #CVE2026 #VulnerabilityManagement #PatchTuesday

    cyberworldops.eu/en/sharepoint

  22. Rapid7 released a proof-of-concept for CVE-2026-55040, a critical SharePoint vulnerability, on August 12. Within hours, Defused observed the exploit weaponized against SharePoint honeypots. Microsoft patched the flaw in July, yet Shadowserver still reports over 8,500 exposed servers. Patching is no longer optional.

    #SharePoint #CVE2026 #VulnerabilityManagement #PatchTuesday

    cyberworldops.eu/en/sharepoint

  23. Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

    #SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability

    cyberworldops.eu/en/sharepoint

  24. Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

    #SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability

    cyberworldops.eu/en/sharepoint

  25. Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

    #SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability

    cyberworldops.eu/en/sharepoint

  26. 🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
    github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated

  27. 🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
    github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated

  28. 🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
    github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated

  29. 🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
    github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated

  30. 🎉 Ah, yet another CVE! The thrilling tale of "Zapscape" is as exciting as watching paint dry, with #GitHub promising to stop leaks before they start 🔒. With a catchy name like CVE-2026-64561, it’s sure to stay in our nightmares forever. 🙄
    github.com/V4bel/Zapscape #CVE2026 #Zapscape #cybersecurity #vulnerabilities #technews #HackerNews #ngated

  31. CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Loytec #CVE2026

  32. CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Loytec #CVE2026

  33. CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Loytec #CVE2026

  34. CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Loytec #CVE2026

  35. ⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. thecybermind.co/mxq2

    #CyberSecurity #InfoSec #Fortinet #ThreatIntel #CVE2026

  36. ⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. thecybermind.co/mxq2

    #CyberSecurity #InfoSec #Fortinet #ThreatIntel #CVE2026

  37. ⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. thecybermind.co/mxq2

    #CyberSecurity #InfoSec #Fortinet #ThreatIntel #CVE2026

  38. ⚠️ CRITICAL THREAT: CVE-2026-58644 targets Microsoft SharePoint via deserialization. Active exploitation is verified. Is your perimeter secured? Get the forensic detection queries and hardening playbooks you need to defend your infrastructure now. thecybermind.co/9pxn

    #CyberSecurity #InfoSec #SharePoint #CVE2026

  39. ⚠️ CRITICAL THREAT: CVE-2026-58644 targets Microsoft SharePoint via deserialization. Active exploitation is verified. Is your perimeter secured? Get the forensic detection queries and hardening playbooks you need to defend your infrastructure now. thecybermind.co/9pxn

    #CyberSecurity #InfoSec #SharePoint #CVE2026

  40. CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026

  41. CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026

  42. CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026

  43. CVE-2026-11961 (CRITICAL): User Registration & Membership plugin (pre-5.2.3) allows unauthenticated users to assign arbitrary membership tiers, including admin, during signup. Disable or restrict registration until fixed. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026

  44. June 2026 marked a pivotal shift in cybersecurity, with a record wave of critical zero-days and 15 devastating flaws targeting HTTP.sys, cloud nodes, and critical assets. Dive deep into the full CVE technical analysis on our blog:

    denizhalil.com/2026/07/03/june 🛡️🔒

    #VulnerabilityAnalysis #CyberSecurity #InfoSec #CVE2026

  45. June 2026 marked a pivotal shift in cybersecurity, with a record wave of critical zero-days and 15 devastating flaws targeting HTTP.sys, cloud nodes, and critical assets. Dive deep into the full CVE technical analysis on our blog:

    denizhalil.com/2026/07/03/june 🛡️🔒

    #VulnerabilityAnalysis #CyberSecurity #InfoSec #CVE2026