home.social

#vulnerability — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vulnerability, aggregated by home.social.

fetched live
  1. 🟠 CVE-2026-17220 - High (8.2)

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  2. 🟠 CVE-2026-17220 - High (8.2)

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  3. 🟠 CVE-2026-17197 - High (8.1)

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  4. 🟠 CVE-2026-17197 - High (8.1)

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  5. 🟠 CVE-2026-72777 - High (8.6)

    Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostna...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  6. 🟠 CVE-2026-72777 - High (8.6)

    Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostna...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  7. 🟠 CVE-2026-73482 - High (8.1)

    phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSR...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  8. 🟠 CVE-2026-73482 - High (8.1)

    phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSR...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  9. 🔴 CVE-2026-73653 - Critical (9.4)

    Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  10. 🔴 CVE-2026-73653 - Critical (9.4)

    Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  11. 🟠 CVE-2026-73650 - High (8.2)

    SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can ...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  12. 🟠 CVE-2026-73650 - High (8.2)

    SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can ...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  13. Siemens Patches Critical RCE Flaws in Industrial IoT, Networking and Video Management Systems

    Siemens addressed multiple critical vulnerabilities, including a CVSS 10.0 flaw in SIMATIC IoT2050 devices and a CVSS 9.1 flaw in Siveillance Video Management Servers.

    **If you run Siemens SIMATIC IoT2050, Siveillance Video Management Servers, or RUGGEDCOM APE1808, first make sure these devices are isolated from the internet and reachable only from trusted networks. Then update each one to the latest Siemens version right away - especially the IoT2050 with Node-RED, where anyone on the network can currently take full control without a password.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  14. Siemens Patches Critical RCE Flaws in Industrial IoT, Networking and Video Management Systems

    Siemens addressed multiple critical vulnerabilities, including a CVSS 10.0 flaw in SIMATIC IoT2050 devices and a CVSS 9.1 flaw in Siveillance Video Management Servers.

    **If you run Siemens SIMATIC IoT2050, Siveillance Video Management Servers, or RUGGEDCOM APE1808, first make sure these devices are isolated from the internet and reachable only from trusted networks. Then update each one to the latest Siemens version right away - especially the IoT2050 with Node-RED, where anyone on the network can currently take full control without a password.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  15. This is a subtle and interesting #security #vulnerability in the #Perl module HTML::FormHandler.

    An attacker submits two values for the same field, e.g. "u=a&u=b" in Catalyst the form parameter's value is an array reference instead of a string.

    HTML::FormHandler sees this as the wrong type, but includes the value in the error message, which it then feeds to Locale::Maketext to translate into different languages.

    Since the value is an array ref, it's converted to a string ["a","b"] which is a Locale::Maketext template that can run the method "a" on the argument "b".

    lists.security.metacpan.org/cv

  16. This is a subtle and interesting #security #vulnerability in the #Perl module HTML::FormHandler.

    An attacker submits two values for the same field, e.g. "u=a&u=b" in Catalyst the form parameter's value is an array reference instead of a string.

    HTML::FormHandler sees this as the wrong type, but includes the value in the error message, which it then feeds to Locale::Maketext to translate into different languages.

    Since the value is an array ref, it's converted to a string ["a","b"] which is a Locale::Maketext template that can run the method "a" on the argument "b".

    lists.security.metacpan.org/cv

  17. Phoenix Contact Patches Critical Buffer Overflow in PLCnext Firmware

    Phoenix Contact addressed three vulnerabilities in PLCnext firmware, including a critical buffer overflow (CVE-2025-41769) that allows unauthenticated remote code execution. The update also fixes denial-of-service and SQL injection flaws affecting various industrial controllers.

    **If you run Phoenix Contact PLCnext controllers, first make sure these devices are isolated from the internet and reachable only from trusted networks. Then update the firmware to version 2026.0.3 on every compatible device. For the obsolete EPC 1502 and EPC 1522, which will never be patched, take them off the network or replace them with supported hardware.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  18. Phoenix Contact Patches Critical Buffer Overflow in PLCnext Firmware

    Phoenix Contact addressed three vulnerabilities in PLCnext firmware, including a critical buffer overflow (CVE-2025-41769) that allows unauthenticated remote code execution. The update also fixes denial-of-service and SQL injection flaws affecting various industrial controllers.

    **If you run Phoenix Contact PLCnext controllers, first make sure these devices are isolated from the internet and reachable only from trusted networks. Then update the firmware to version 2026.0.3 on every compatible device. For the obsolete EPC 1502 and EPC 1522, which will never be patched, take them off the network or replace them with supported hardware.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  19. 🟠 CVE-2026-73515 - High (8.1)

    PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string l...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  20. 🟠 CVE-2026-73515 - High (8.1)

    PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string l...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  21. 🟠 CVE-2026-73514 - High (8.8)

    The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() t...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  22. 🟠 CVE-2026-73514 - High (8.8)

    The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() t...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  23. 🟠 CVE-2026-73570 - High (8.9)

    A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notificati...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  24. 🟠 CVE-2026-73570 - High (8.9)

    A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notificati...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  25. New.

    "Today VulnCheck is disclosing CVE-2026-14863, an OS command injection to remote code execution in FileRun, a commercial self-hosted file manager. It is being disclosed in accordance with VulnCheck's coordinated vulnerability disclosure policy."

    "The motivation was deliberate. Open-source codebases are getting shredded by AI-assisted auditing, where every researcher and their LLM greps the same GitHub repos and finds the same bugs."

    Vulncheck: FileRun: When Your File Manager Runs Your Files vulncheck.com/blog/filerun-thu @vulncheck #infosec #opensource #vulnerability

  26. New.

    "Today VulnCheck is disclosing CVE-2026-14863, an OS command injection to remote code execution in FileRun, a commercial self-hosted file manager. It is being disclosed in accordance with VulnCheck's coordinated vulnerability disclosure policy."

    "The motivation was deliberate. Open-source codebases are getting shredded by AI-assisted auditing, where every researcher and their LLM greps the same GitHub repos and finds the same bugs."

    Vulncheck: FileRun: When Your File Manager Runs Your Files vulncheck.com/blog/filerun-thu @vulncheck #infosec #opensource #vulnerability

  27. There are several updates from Broadcom addressing a long list of vulnerabilities, one of them critical support.broadcom.com/web/ecx/s #Broadcom

    Yesterday:

    CISA:

    CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts cisa.gov/news-events/news/cisa #CISA

    Palo Alto: CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering security.paloaltonetworks.com/ #infosec #vulnerability

  28. There are several updates from Broadcom addressing a long list of vulnerabilities, one of them critical support.broadcom.com/web/ecx/s #Broadcom

    Yesterday:

    CISA:

    CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts cisa.gov/news-events/news/cisa #CISA

    Palo Alto: CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering security.paloaltonetworks.com/ #infosec #vulnerability

  29. 📊 EUVD Daily CVSS Summary

    🟡 Average Score: 6.41/10 (Medium)
    📈 Vulnerabilities: 105
    ⬇️ Min: 2.3 | ⬆️ Max: 8.8

    📅 Date: 2026-08-12

    #cybersecurity #infosec #euvd #cvss #vulnerability

  30. 📊 EUVD Daily CVSS Summary

    🟡 Average Score: 6.41/10 (Medium)
    📈 Vulnerabilities: 105
    ⬇️ Min: 2.3 | ⬆️ Max: 8.8

    📅 Date: 2026-08-12

    #cybersecurity #infosec #euvd #cvss #vulnerability

  31. 🟠 CVE-2026-49478 - High (8.7)

    Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowin...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  32. 🟠 CVE-2026-49478 - High (8.7)

    Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowin...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  33. 🔴 CVE-2026-49827 - Critical (9.8)

    WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execu...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  34. 🔴 CVE-2026-49827 - Critical (9.8)

    WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execu...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  35. 🟠 CVE-2026-6464 - High (8.1)

    Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates th...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  36. 🟠 CVE-2026-6464 - High (8.1)

    Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates th...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  37. Quanovate Tech Patches Critical Vulnerabilities in Mira Hormone Monitor and Android App

    Quanovate Tech patched eight vulnerabilities in the Mira Hormone Monitor and Android app that allowed attackers to take over accounts and manipulate sensitive reproductive health data. The flaws included weak cloud authentication and hard-coded credentials that could lead to failed fertility treatments or data theft.

    **If you use the Mira Hormone Monitor, immediately update the app to iOS v3.5.18 or Android v4.5.18 and let the firmware update to 01.07.01.53 install when the device connects, and keep Bluetooth off when you aren't actively using the monitor.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  38. Quanovate Tech Patches Critical Vulnerabilities in Mira Hormone Monitor and Android App

    Quanovate Tech patched eight vulnerabilities in the Mira Hormone Monitor and Android app that allowed attackers to take over accounts and manipulate sensitive reproductive health data. The flaws included weak cloud authentication and hard-coded credentials that could lead to failed fertility treatments or data theft.

    **If you use the Mira Hormone Monitor, immediately update the app to iOS v3.5.18 or Android v4.5.18 and let the firmware update to 01.07.01.53 install when the device connects, and keep Bluetooth off when you aren't actively using the monitor.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  39. 🟠 CVE-2026-12263 - High (8.8)

    Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  40. 🟠 CVE-2026-12263 - High (8.8)

    Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  41. 📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310.

    Listen/Read: hackread.com/apt-exploits-crit

    #CyberSecurity #VMware #vCenter #APT #Vulnerability

  42. 📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310.

    Listen/Read: hackread.com/apt-exploits-crit

    #CyberSecurity #VMware #vCenter #APT #Vulnerability

  43. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  44. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  45. A #supplychainattack on the #opensource tool #LiteLLM exposed #terabytes of #credentials belonging to over 2,500 organisations, including Microsoft, Amazon, and Cisco. The attack, attributed to the group TeamPCP, exploited a #vulnerability in the #vulnerabilityscanner #Trivy and compromised versions of LiteLLM, KICS, and the Telnyx Python SDK. Security firms CloudSEK and Hudson Rock urge affected organisations to rotate credentials. arstechnica.com/security/2026/ #tech #news #ainews

  46. A #supplychainattack on the #opensource tool #LiteLLM exposed #terabytes of #credentials belonging to over 2,500 organisations, including Microsoft, Amazon, and Cisco. The attack, attributed to the group TeamPCP, exploited a #vulnerability in the #vulnerabilityscanner #Trivy and compromised versions of LiteLLM, KICS, and the Telnyx Python SDK. Security firms CloudSEK and Hudson Rock urge affected organisations to rotate credentials. arstechnica.com/security/2026/ #tech #news #ainews