24h | 7d | 30d

Overview

  • servmask
  • All-in-One WP Migration and Backup

25 Aug 2026
Published
27 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.54%

KEV

Description

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This can be leveraged to obtain the ai1wm_secret_key when a site administrator performs an archive restore and achieve remote code execution once able to leverage the ai1wm_secret_key value.

Statistics

  • 4 Posts
  • 2 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

「WordPressバックアッププラグインの欠陥により、数百万のサイトが乗っ取り攻撃の危険にさらされる 」: #BLEEPINGCOMPUTER

「WordPress用プラグイン「All-in-One WP Migration and Backup」に存在するSQLインジェクションの脆弱性により、認証されていない攻撃者がリモートでコードを実行し、影響を受けるウェブサイトを乗っ取ることができる可能性があります。

このプラグインは、データベース、メディア、テーマ、プラグインなどを含むウェブサイト全体を、サーバー間またはドメイン間でバックアップ、エクスポート、インポート、移動するために使用されます。

このセキュリティ上の脆弱性はCVE-2026-19949として追跡されており、深刻度スコアは高となっています。この脆弱性はセキュリティ研究者のジャック・テイラー氏によって発見され、8月中旬にDefiant社のサイバーセキュリティ部門であるWordfenceを通じて報告されました。 」

bleepingcomputer.com/news/secu

#prattohome

  • 2
  • 0
  • 0
  • 22h ago
Profile picture fallback

Critical WordPress vulnerability exposes 3.2 million sites to remote code execution via All-in-One WP Migration

CVE-2026-19949 is a second-order SQL injection in All-in-One WP Migration and Backup that leads to unauthenticated RCE. Full exploit chain and fix

thecybersecguru.com/news/cve-2

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
CVE-2026-19949 enables unauthenticated attackers to obtain a restore secret key and trigger remote code execution via crafted archive imports.
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
CVE-2026-19949 in All-in-One WP Migration and Backup may affect 3.2M WordPress sites. A second-order SQL injection in archive restore could enable RCE via trackbacks; only 35% are patched to 7.110. #WordPress #CVE202619949 #SQLInjection
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

11 Aug 2026
Published
03 Sep 2026
Updated

CVSS v3.1
HIGH (8.0)
EPSS
1.32%

KEV

Description

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Nearly 22,000 internet-facing Exchange servers remain unpatched against CVE-2026-62911, an authentication bypass that can hijack every user's mailbox.

meterpreter.org/exchange-cve-2

  • 0
  • 0
  • 0
  • 19h ago

Bluesky

Profile picture fallback
Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation. www.helpnetsecurity.com/2026/09/02/m...
  • 0
  • 1
  • 0
  • 16h ago
Profile picture fallback
Install the latest Microsoft Exchange security patches immediately to mitigate CVE-2026-62911, which enables full system access on unpatched Exchange servers.
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Sangoma
  • Switchvox SMB Edition

17 Jul 2026
Published
03 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
11.84%

Description

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Statistics

  • 3 Posts

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Sangoma Switchvox Flaw Under Attack: 4,000 VoIP Systems Exposed esecurityplanet.com/threats/ne

  • 0
  • 0
  • 0
  • 5h ago

Bluesky

Profile picture fallback
Critical Unauthenticated SQL Injection in Sangoma Switchvox Enables RCE https://xploitzone.com/cve-2026-9586-sangoma-switchvox-exploit https://flagthis.com/tldr/6921 ##SQLInjection ##RCE ##VoIP ##CVE-2026-9586 ##Sangoma
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
~Cisa~ CISA added seven actively exploited vulnerabilities to its KEV Catalog and urges rapid remediation. - IOCs: CVE-2026-9586, CVE-2026-49869, CVE-2026-83549 - #CVE #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Elementor
  • Elementor Pro

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
2.37%

KEV

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Statistics

  • 2 Posts
  • 4 Interactions

Last activity: 7 hours ago

Bluesky

Profile picture fallback
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server.
  • 2
  • 2
  • 0
  • 12h ago
Profile picture fallback
Critical Elementor Pro flaw, CVE-2026-32475, is being exploited to upload webshells and run commands on WordPress sites. Affects 4.2.1 and earlier. #ElementorPro #WordPress #CVE202632475
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Zimbra
  • Collaboration

13 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
32.38%

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Statistics

  • 2 Posts
  • 7 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback

RE: red.fox.yt/@coltofox/117171580

This is finally resolved as of 2:20am last night after hours of migrating 18 domains, 34 mailboxes, 196 aliases, 1 distribution list, and 6 forwarders from Zimbra ZCS FOSS to mailcow. I'll note my technical journey down below if you're interested.

:blobfoxcomfycomputer:

This has been ongoing effort since the compromise last Friday with investigations into some solutions.

I thought about building Zimbra from source then stopped myself from the nightmare of management overhead of maintaining that.

So I looked at the directly compatible platform, Carbonio. I spun up a Rocky 10 VM to replace this (Rocky 9 is EOL next year so can't do that). I managed to get Carbonio EL9 installed on Rocky 10 but couldn't get the post-install script to run since it required Perl 5.32 when EL10 ships with Perl 5.40. I tried installing EL9 Perl but there were too many dependencies, then I tried Perlbrew but it would keep trying the system one regardless of the symlinks I'd try -- even tried using the system one but it didn't budge either.

So dependency hell kicked in and I thought, well maybe they have a docker container. So I installed docker on the Rocky 10 VM, got that all setup. But then I look at the Docker Hub page and while an image does exist, there is zero documentation anywhere and the last image was 8 months ago. So I lost confidence there.

Through the investigation on this journey of migrating away off of Zimbra Open Source I kept seeing references to mailcow. So I tried a demo of mailcow to grasp the platform. The demo didn't really convince me to like it, I still prefer the UI Zimbra had (especially the admin UI) but it seemed it could almost do everything I needed.

So I eventually got the mailcow docker containers up and running. The migration was a lot of busywork since I didn't really want to touch the old Zimbra Database.

I migrated every mailbox one-by-one, creating the accounts all from scratch then did the (imap)sync afterward. The aliases were a bit easier, I could grep a zmprov command on the old server to query a user then paste them into mailcow in bulk.

Then there was DNS... For the public BIND servers I could sed the MX and SRV records to the new hostname but I still had to enter and split up 18 DKIM records. Had to manually update some Cloudflare domains, then also all of the internal (split) DNS records too.

Then there was TLS... So I haven't completely finished this yet, but it's enough for mail transport. I can't use mailcow-acme because it doesn't support RFC 2136 so I had to look into manual certificates (still ACME, but OS level). Then I had to find out how I could handle 18 different domains in SNI instead of 1 giant certificate. Turned out this was possible, and I've configured the default domain (that the hostname uses). I still need to configure the other 17 domains but the groundwork is there for when I get around configuring all those autoconfig/autodiscover certs.

With that out of the way, the main migration completed. Some systems recognised the new server as the same one after I put in the CNAME from old to new. Some didn't and I'm gradually fixing those as I find them (stricter auth requirements, etc).

One thing I will say I like about mailcow is Exchange ActiveSync. Zimbra always kept that as a paid feature. This finally enables me to have push notifications and proper calendar sync. I noticed there was a note last year from the SOGO team that they planned to remove ActiveSync, I'm so glad they reversed that decision.

After almost a week with almost no email I see how important this server actually is. I installed Zimbra ZCS roughly 5 years ago to exit Google Workspace and I'm still glad I did.

Having control over the data directly is empowering to not have some big corporation feeding it into their AI models with a force opt-in approach (i.e. Google) or alternatives with questionable political views (i.e. Proton). Keep email decentralised!

Anyway, I'm happy I have email again now. Thanks for reading! :blobfoxheart:

#Zimbra #mailcow #email #server #selfhosting #cve202673570

  • 1
  • 5
  • 0
  • 13h ago
Profile picture fallback

spent a bit'o time dealing with CVE-2026-73570 couple of days ago

about 6 hours

scraped thru as much as I could, found no real concerns aside from bad actors hitting my hosts so hard, they filled my available storage & crashed'em

(i log stuff, esp dns, excessively)

added bunch of /8s, /12s, etc to my drop firewall rules, blah blah

spent time disabling snmp (nothing 's' about it) on my zimbra instance, so it starts clean

all good
so far

funny
about same timeframe as outlook debacle

huh

  • 0
  • 1
  • 0
  • 12h ago

Overview

  • Cisco
  • Cisco NX-OS Software

02 Sep 2026
Published
03 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.53%

KEV

Description

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with&nbsp;root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 6 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco released patches for CVE-2026-20212, a critical unauthenticated remote code execution vulnerability in Nexus 9000 switches (10 Silicon One-based models). Attackers can exploit this via TCP ports 43210 and 43211 to execute commands as root. If you run affected Nexus 9000 hardware, this is imme…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 1
  • 0
  • 6h ago

Bluesky

Profile picture fallback
Cisco has patched CVE-2026-20212, a critical Nexus 9000 flaw affecting 10 Silicon One switch models that could let unauthenticated remote attackers run code as root via TCP 43210 and 43211. #Cisco #Nexus9000 #IOSXR
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • jfrog
  • artifactory

28 Aug 2026
Published
03 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
7.67%

Description

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Statistics

  • 2 Posts

Last activity: 7 hours ago

Bluesky

Profile picture fallback
Attackers Exploit CVE-2026-82329 to Forge JFrog Artifactory Admin Tokens #CriticalVulnerability #CyberSecurity #JFrogArtifactory
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
Artifactory's phantom join key CVE-2026-82329: administrators with no credentials #patchmanagement
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • AWS
  • @amazon-codecatalyst/blueprints.blueprint

03 Sep 2026
Published
03 Sep 2026
Updated

CVSS v3.1
HIGH (8.0)
EPSS
Pending

KEV

Description

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry in a crafted .ownership-file. Version 0.3.156 removes shell interpretation of the owner field, running the command directly rather than through a shell, and rejects values outside an allowlisted command form. This eliminates shell metacharacter command injection. To remediate this issue, users should upgrade to version 0.3.156 or later. No action is required for use of the Amazon CodeCatalyst service. Resynthesis runs in an isolated per-project environment with scoped credentials, and the service applies server-side validation there that rejects [local] merge strategy commands outside a restricted allowlisted form, including for blueprint versions published before 0.3.156.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

CVE-2026-85012 - Command Injection in AWS codecatalyst-blueprints. Arbitrary command execution via crafted .ownership-file. CVSS 8.0. Update to v0.3.156 now. #CVE #AWS #infosec

valtersit.com/cve/CVE-2026-850

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK #patchmanagement
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-59346, a critical VMware Workstation vulnerability, lets an attacker escape a guest VM and execute code on the host. Broadcom rates it 9.3 CVSS.

securityonline.info/vmware-cve

  • 1
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
なんか、vmxnet3の脆弱性やばそう --- VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) → https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38288
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Cisco
  • Cisco Secure Email

02 Sep 2026
Published
02 Sep 2026
Updated

CVSS v3.1
MEDIUM (5.9)
EPSS
0.15%

KEV

Description

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

Statistics

  • 2 Posts

Last activity: 13 hours ago

Fediverse

Profile picture fallback

A public announcement exists for the Cisco Secure Email vulnerability pair in S/MIME decryption, plus a Cisco phone SIP denial-of-service flaw.

securityonline.info/cisco-secu

  • 0
  • 0
  • 0
  • 13h ago

Bluesky

Profile picture fallback
Two medium-severity Secure Email S/MIME decryption vulnerabilities (CVE-2026-20354, CVE-2026-20355) could enable MitM attackers to obtain plaintext from encrypted email traffic.
  • 0
  • 0
  • 0
  • 17h ago
Showing 1 to 10 of 59 CVEs