24h | 7d | 30d

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
28 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.30%

Description

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

Statistics

  • 25 Posts
  • 32 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

We've been continuously updating this post with the latest information—now including details on exploitation of CVE-2026-88772. And all relevant indicators have been added to our MISP feed.

ifin.network/t/multiple-citrix

  • 6
  • 5
  • 0
  • 7h ago
Profile picture fallback

We had first POC yes, but what about second POC? watchTowr breaks down CVE-2026-88772 and provides a "detection artifact generator"

labs.watchtowr.com/here-we-go-

  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback

Citrix says attackers are exploiting two critical NetScaler flaws. CVE-2026-88771 allows unauthenticated command execution and affects default configurations. CVE-2026-88772 can lead to remote code execution or denial of service when DTLS is enabled.

Both score 9.5 under CVSS 4.0. If you manage NetScaler, identify affected appliances and install the fixed builds.

support.citrix.com/external/ar
#Cybersecurity #NetScaler #Citrix

  • 1
  • 0
  • 0
  • 9h ago
Profile picture fallback

Mandiant and Google Threat Intelligence Group describe in-the-wild exploitation CVE-2026-88771 and CVE-2026-88772 against Citrix NetScaler ADC and NetScaler Gateway appliances globally. Indicators of compromise and YARA rules are included.

cloud.google.com/blog/topics/t

  • 0
  • 2
  • 0
  • 2h ago
Profile picture fallback

Two critical Citrix NetScaler zero-day flaws, rated 9.5 on CVSS 4.0, are under attack. See the fixed builds and how to respond.

meterpreter.org/citrix-netscal

  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback

Recent global developments highlight escalating cybersecurity risks and geopolitical tensions. AI-powered attacks are rapidly exploiting vulnerabilities, with threat actors leveraging agentic workflows for credential harvesting. In response, Nvidia has launched its Open Agent Safety Platform to manage rogue AI agents. Meanwhile, CISA has issued a critical warning regarding actively exploited Citrix NetScaler zero-day flaws (CVE-2026-88771, CVE-2026-88772).

On the geopolitical front, a new US-Saudi civilian nuclear pact has raised significant proliferation concerns, as Saudi Arabia has not ruled out developing nuclear weapons.

#Cybersecurity #AI #Geopolitics

  • 0
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.
  • 1
  • 5
  • 0
  • 4h ago
Profile picture fallback
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) - watchTowr Labs
  • 1
  • 0
  • 2
  • 8h ago
Profile picture fallback
watchTowr details a pre-auth memory overflow in Citrix NetScaler's DTLS handling, CVE-2026-88772, the second of eight CVEs Citrix patched in one advisory. The writeup walks the flaw; the "here we go again" framing is doing some work, since the patch itself already shipped.
  • 0
  • 1
  • 0
  • 5h ago
Profile picture fallback
~Watchtowr~ In-the-wild pre-auth DTLS overflow enables RCE or DoS; patch immediately. - IOCs: CVE-2026-88772 - #CVE-2026-88772 #Citrix #ThreatIntel
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) https://packetstorm.news/news/view/44294 #news
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) - Help Net Security www.helpnetsecurity.com/2026/09/28/c...
  • 0
  • 1
  • 0
  • 12h ago
Profile picture fallback
Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 were used to deploy web shells, tunneling malware, and steal credentials in attacks across North America and Europe. #Citrix #NorthAmerica #Europe
  • 0
  • 1
  • 0
  • Last hour
Profile picture fallback
Citrix NetScalerのCritical 脆弱性 2件がサイバー攻撃に悪用 CVE-2026-88771・CVE-2026-88772、未認証RCEの恐れ rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)(Citrix NetScalerのRCEゼロデイ、数週間にわたり世界規模で悪用) #HelpNetSecurity (Sep 28) www.helpnetsecurity.com/2026/09/28/c...
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
The latest update for #BitSight includes "CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation" and "Identity Risk: 5 Access Pathways Emerging Across #ThreatIntelligence". #Cybersecurity #RiskManagement https://opsmtrs.com/43KoF0t
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Citrix confirmed active exploitation of two NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, after nearly two days of unofficial warnings. The flaws can enable remote code execution. #Citrix #NetScaler #CISA
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
NetScaler ADCおよびNetScaler Gatewayの脆弱性について(CVE-2026-88771、CVE-2026-88772等) | 情報セキュリティ | IPA 独立行政法人 情報処理推進機構 https://www.ipa.go.jp/security/security-alert/2026/alert20260928.html
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild unit42.paloaltonetworks.com/netscaler-ze...
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
🚨 Two critical Citrix NetScaler zero-days are under active exploitation. CVE-2026-88771 & CVE-2026-88772 both score 9.5 — and attackers were active before patches arrived. Our guide 👇 basefortify.eu/posts/2026/0... #Citrix #NetScaler #CyberSecurity
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
~Spiderlabs~ Critical NetScaler flaws enable unauthenticated RCE and are actively exploited worldwide. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE202688771 #CVE202688772 #ThreatIntel
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
@mandiant.com Active exploitation enables root access, WHIPSHOT web shells and SLAPSHOT tunneling. - IOCs: CVE-2026-88772, CVE-2026-88771, WHIPSHOT - #CVE202688771 #CVE202688772 #ThreatIntel
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.06%

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Statistics

  • 23 Posts
  • 16 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Ah Citrix. My favourite VM access app….bane of my professional life.

labs.watchtowr.com/oh-look-the

(How are they even still in business???)

  • 1
  • 2
  • 0
  • 14h ago
Profile picture fallback

A timeline of Citrix NetScaler CVE-2026-88771, from the CVE reservation on Sep 10 to public disclosure on Sep 27, including the exploitation attempts GreyNoise observed on Sep 24.

🔗 Full analysis: greynoise.io/blog/swarming-aga

  • 1
  • 2
  • 0
  • 7h ago
Profile picture fallback

CVE-2026-88771: Detection Artifact Generator for Citrix NetScaler

GitHub: github.com/watchtowrlabs/watch

  • 0
  • 2
  • 0
  • 23h ago
Profile picture fallback

CVE-2026-88771 is a Citrix NetScaler command injection exploited in the wild. Details and a PoC are public. Patch NetScaler to 14.1-73.37 now.

securityonline.info/citrix-net

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

(CISA TS+SOC) CVE-2026-88771 – Citrix NetScaler Input Validation RCE Briefing

Active exploitation of CVE-2026-88771 in Citrix NetScaler requires immediate patch deployment and forensic triage. Review integrated TSUITE + SOC intelligence assets....

thecybermind.co/41l1

  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback

Citrix says attackers are exploiting two critical NetScaler flaws. CVE-2026-88771 allows unauthenticated command execution and affects default configurations. CVE-2026-88772 can lead to remote code execution or denial of service when DTLS is enabled.

Both score 9.5 under CVSS 4.0. If you manage NetScaler, identify affected appliances and install the fixed builds.

support.citrix.com/external/ar
#Cybersecurity #NetScaler #Citrix

  • 1
  • 0
  • 0
  • 9h ago
Profile picture fallback

Mandiant and Google Threat Intelligence Group describe in-the-wild exploitation CVE-2026-88771 and CVE-2026-88772 against Citrix NetScaler ADC and NetScaler Gateway appliances globally. Indicators of compromise and YARA rules are included.

cloud.google.com/blog/topics/t

  • 0
  • 2
  • 0
  • 2h ago
Profile picture fallback

Two critical Citrix NetScaler zero-day flaws, rated 9.5 on CVSS 4.0, are under attack. See the fixed builds and how to respond.

meterpreter.org/citrix-netscal

  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback

Recent global developments highlight escalating cybersecurity risks and geopolitical tensions. AI-powered attacks are rapidly exploiting vulnerabilities, with threat actors leveraging agentic workflows for credential harvesting. In response, Nvidia has launched its Open Agent Safety Platform to manage rogue AI agents. Meanwhile, CISA has issued a critical warning regarding actively exploited Citrix NetScaler zero-day flaws (CVE-2026-88771, CVE-2026-88772).

On the geopolitical front, a new US-Saudi civilian nuclear pact has raised significant proliferation concerns, as Saudi Arabia has not ruled out developing nuclear weapons.

#Cybersecurity #AI #Geopolitics

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

citrixInspector: Passively identify Citrix ADC / NetScaler ADC & Gateway builds and check for known vulnerabilities, including CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and KEV-listed CVE-2026-88771/88772.

GitHub: github.com/securekomodo/citrix

  • 0
  • 3
  • 0
  • 23h ago

Bluesky

Profile picture fallback
NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771) 📖 Read more: www.helpnetsecurity.com/2026/09/29/n... #CyberSecurity #CyberSecurityNews #CVE #0day #ZeroDay
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
Public PoC for CVE-2026-88771 is fueling mass exploitation of internet-facing Citrix NetScaler ADC and Gateway devices, with log poisoning, webshells, and over 100 victim orgs tracked. #Citrix #NetScaler #CVE202688771
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) - Help Net Security www.helpnetsecurity.com/2026/09/28/c...
  • 0
  • 1
  • 0
  • 12h ago
Profile picture fallback
Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 were used to deploy web shells, tunneling malware, and steal credentials in attacks across North America and Europe. #Citrix #NorthAmerica #Europe
  • 0
  • 1
  • 0
  • Last hour
Profile picture fallback
Citrix NetScalerのCritical 脆弱性 2件がサイバー攻撃に悪用 CVE-2026-88771・CVE-2026-88772、未認証RCEの恐れ rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)(Citrix NetScalerのRCEゼロデイ、数週間にわたり世界規模で悪用) #HelpNetSecurity (Sep 28) www.helpnetsecurity.com/2026/09/28/c...
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
The latest update for #BitSight includes "CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation" and "Identity Risk: 5 Access Pathways Emerging Across #ThreatIntelligence". #Cybersecurity #RiskManagement https://opsmtrs.com/43KoF0t
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Citrix confirmed active exploitation of two NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, after nearly two days of unofficial warnings. The flaws can enable remote code execution. #Citrix #NetScaler #CISA
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
NetScaler ADCおよびNetScaler Gatewayの脆弱性について(CVE-2026-88771、CVE-2026-88772等) | 情報セキュリティ | IPA 独立行政法人 情報処理推進機構 https://www.ipa.go.jp/security/security-alert/2026/alert20260928.html
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild unit42.paloaltonetworks.com/netscaler-ze...
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
🚨 Two critical Citrix NetScaler zero-days are under active exploitation. CVE-2026-88771 & CVE-2026-88772 both score 9.5 — and attackers were active before patches arrived. Our guide 👇 basefortify.eu/posts/2026/0... #Citrix #NetScaler #CyberSecurity
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
~Spiderlabs~ Critical NetScaler flaws enable unauthenticated RCE and are actively exploited worldwide. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE202688771 #CVE202688772 #ThreatIntel
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
@mandiant.com Active exploitation enables root access, WHIPSHOT web shells and SLAPSHOT tunneling. - IOCs: CVE-2026-88772, CVE-2026-88771, WHIPSHOT - #CVE202688771 #CVE202688772 #ThreatIntel
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Apple
  • iOS and iPadOS

28 Sep 2026
Published
29 Sep 2026
Updated

CVSS
Pending
EPSS
0.81%

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Statistics

  • 14 Posts
  • 11 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Apple Notfall-Update

Apple veröffentlicht Notfall-Flicken für sämtliche Systeme. In den neueren (27) werden "nur" zwei Fehler behoben, die mit dem Update-Paket vor zwei Wochen eingeführt wurden (ja, nicht nur Microsoft - Apple kann das auch). Dringender sind die Updates für alle älteren Systeme. In denen steckt die Sicherheittslücke CVE-2026-86950 im Grafiksystem, die bereits für Angriffe ausgenutzt wird (Zero-Day). Die Schwachstelle entsteht dadurch, dass passend präparierte Dateien jenseits der vorgesehenen Grenzen in den Arbeitsspeicher schreiben können. Da hatte wohl jemand bei der Programmierung "vergessen", eine entsprechende Prüfung einzubauen. Alle ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #apple #cybercrime #exploits #sicherheit #spionage #UnplugApple #UnplugTrump #zeroday

  • 3
  • 3
  • 0
  • 14h ago
Profile picture fallback

Apple released updates to patch a zero-day vulnerability tracked as CVE-2026-86950 linked to an extremely sophisticated attack.

Source: SecurityWeek
securityweek.com/apple-patches

#TechPolicy #Apple #Meta

  • 2
  • 0
  • 0
  • 14h ago
Profile picture fallback

Apple patched an exploited Apple zero-day vulnerability. Learn how this Apple zero-day vulnerability impacts devices and install emergency updates now.

securityonline.info/exploited-

  • 1
  • 0
  • 0
  • 22h ago
Profile picture fallback

Learn about the critical CVE-2026-86950 zero-day vulnerability patched in iOS 26.7.1. Discover how this CoreGraphics flaw could lead to malicious code execution.

securityexpress.info/apple-pat

  • 1
  • 0
  • 0
  • 19h ago
Profile picture fallback

Apple kiadott frissítést egy CoreGraphics-ben lévő CVE-2026-86950 out-of-bounds memóriaírás hibára, amit célzott támadásoknál kihasználhattak. Mely eszközeid érintettek; telepítetted már a javítást? Ne halogasd, olvasd el a részleteket:

linuxmint.hu/hir/2026/09/celzo

#Apple #iOS #iPadOS #macOS #CVE-2026-86950 #CoreGraphics #sebezhetőség #biztonságifrissítés #kibervédelem #NKI

  • 1
  • 0
  • 0
  • 3h ago
Profile picture fallback
Apple patched zero-day CVE-2026-86950 in CoreGraphics, exploited in sophisticated targeted attacks against specific iOS users. Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to […]
Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

Apple squashes zero-day bug exploited in ”extremely sophisticated” attack (CVE-2026-86950) – Help Net Security macken.xyz/2026/09/apple-squas

  • 0
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
Apple has patched CVE-2026-86950 in CoreGraphics, fixing an out-of-bounds write that could enable code execution. Apple says it may have been exploited in targeted attacks against specific individuals. #Apple #CoreGraphics #CVE202686950
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
SANS ISC Diaryの要確認記事「Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950)」が公開されました。 → https://isc.sans.edu/diary/rss/33376
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
CVE-2026-86950 in CoreGraphics was patched by Apple to prevent arbitrary code execution from crafted files, with possible zero-click delivery via previews.
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
Apple patched CVE-2026-86950, a CoreGraphics zero-day on iOS and macOS that may have enabled code execution in highly targeted attacks. Meta's security team reported the issue. #Apple #CoreGraphics #Meta
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950) 📖 Read more: www.helpnetsecurity.com/2026/09/29/a... #cybersecurity #cybersecuritynews #Apple #0day #iOS #iPad #macOS
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Apple patched CVE-2026-86950, an actively exploited Core Graphics zero-day in iOS and macOS that could allow code execution via a malicious file. Fixes are in iOS 26.7.1, iPadOS 26.7.1, and macOS Tahoe 26.7.1. #Apple #CoreGraphics
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
~Cybergcca~ Apple CVE-2026-86950 is exploited in the wild; patch affected Apple devices and other listed products. - IOCs: CVE-2026-86950, CVE-2026-101891, CVE-2026-86102 - #Apple #CVE #ThreatIntel
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Oracle Corporation
  • PeopleSoft Enterprise PeopleTools

11 Jun 2026
Published
04 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
9.44%

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Statistics

  • 5 Posts
  • 2 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

ShinyHunters PeopleSoft attacks are back. A one-letter WAF bypass lets the group exploit CVE-2026-35273 and plant web shells on unpatched servers.

securityonline.info/shinyhunte

  • 1
  • 1
  • 0
  • 10h ago
Profile picture fallback

Discover how ShinyHunters uses URL encoding to bypass WAF defenses, aggressively exploiting the critical CVE-2026-35273 Oracle PeopleSoft vulnerability.

meterpreter.org/shinyhunters-o

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
Mandiant says ShinyHunters is exploiting Oracle PeopleSoft CVE-2026-35273 via workarounds, hitting unpatched systems across education, healthcare, tech, and government, and deploying web shells. #ShinyHunters #Oracle #PeopleSoft
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Google’s warning comes four months after the hacking group was seen exploiting a zero-day vulnerability in PeopleSoft, tracked as CVE-2026-35273, to gain remote code execution without authentication. www.securityweek.com/google-warns...
  • 0
  • 0
  • 1
  • 11h ago

Overview

  • Apple
  • iOS and iPadOS

11 Feb 2026
Published
02 Apr 2026
Updated

CVSS
Pending
EPSS
1.34%

Description

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.

Statistics

  • 4 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Tracked as CVE-2026-20700, this flaw stems from an out-of-bounds write weakness discovered by Meta Product Security in CoreGraphics. bleepingcomputer.com/news/secu

  • 0
  • 0
  • 1
  • 11h ago

Bluesky

Profile picture fallback
Apple patched CVE-2026-20700, a CoreGraphics zero-day used in targeted attacks on iPhone, iPad, and Mac devices. The flaw could allow code execution via crafted files. #Apple #CoreGraphics #iOS
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Apple patched CVE-2026-20700, a CoreGraphics flaw that attackers used against specific individuals, in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. A crafted file could let an attacker run code on the device.
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts
  • 9 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Podman 6.1.3 and v5.8.8 have both been released and are making their way to Fedora and other distros. These releases address CVE-2026-94603. Details: github.com/podman-container-to, github.com/podman-container-to #podman #opensource

  • 1
  • 4
  • 0
  • 5h ago

Bluesky

Profile picture fallback
Podman 6.1.3 and v5.8.8 have both been released and are making their way to Fedora and other distros. These releases address CVE-2026-94603. Details: github.com/podman-conta..., github.com/podman-conta... #podman #opensource
  • 1
  • 3
  • 0
  • 5h ago

Overview

  • Apple
  • macOS

14 Sep 2026
Published
15 Sep 2026
Updated

CVSS
Pending
EPSS
0.13%

KEV

Description

A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Fediverse

Profile picture fallback
[RSS] CVE-2026-43783: Repair Permissions - Get Root: LPE via DesktopServicesHelper in macOS 26.5

https://ptswarm.com/blog/cve-2026-43783-repair-permissions-get-root-lpe-via-desktopserviceshelper-in-macos-26-5/
  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
[RSS] CVE-2026-43783: Repair Permissions - Get Root: LPE via DesktopServicesHelper in macOS 26.5 ptswarm.com -> Original->
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

A critical MikroTik RouterOS vulnerability, CVE-2026-84411 (CVSS 9.8), lets unauthenticated attackers run code as root. Update RouterOS now.

securityonline.info/mikrotik-r

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
~Cisa~ Unauthenticated crafted requests enable root RCE or DoS; update to 7.23+. - IOCs: CVE-2026-84411 - #CVE202684411 #RouterOS #ThreatIntel
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Microsoft Corporation
  • Office/WordPad

12 Apr 2017
Published
21 Oct 2025
Updated

CVSS
Pending
EPSS
99.50%

Description

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."

Statistics

  • 2 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
~Asec~ CVE-2017-0199-laced XLS attachments use HTA and PowerShell to deliver Remcos RAT. - IOCs: 172[.]245[.]209[.]133, muddy-sound-e0cd[.]nodetectonn[.]workers[.]dev, blessedongrace[.]duckdns[.]org:19700 - #Phishing #Remcos #ThreatIntel
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
Phishing emails posing as project material requests trick victims into opening a malicious XLS file, triggering CVE-2017-0199, a hidden loader chain, and Remcos RAT for data theft. #CVE2017 #RemcosRAT #Korea
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Python Software Foundation
  • CPython

29 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
MEDIUM (5.9)
EPSS
Pending

KEV

Description

The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms.

Statistics

  • 2 Posts
  • 8 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

CPython was just assigned a delightfully placeholder-looking CVE number for a recent (undelightful) advisory: CVE-2026-12345 😆

  • 2
  • 6
  • 0
  • 3h ago
Showing 1 to 10 of 1,401 CVEs