24h | 7d | 30d

Overview

  • IBM
  • MQ Appliance

18 Sep 2026
Published
21 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.52%

KEV

Description

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 9 hours ago

Fediverse

Profile picture fallback

🚨 RAPID RESPONSE: IBM MQ Pre-Authentication RCE [CVE-2026-10747]

A critical heap buffer overflow in IBM MQ could allow remote code execution before authentication. CVSS: 10.0.

Censys ARC observes IBM MQ web consoles on 120 hosts and 149 web properties Internet-wide. These numbers indicate IBM MQ presence, not confirmed vulnerable systems.

IBM has released fixes for affected MQ Server and MQ Appliance versions. No public PoC or reported active exploitation is known at this time.

Read the full analysis for affected versions, Internet observations, and remediation guidance. censys.com/advisory/cve-2026-1

  • 1
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
🚨 CVE-2026-10747: A critical pre-auth RCE in IBM MQ carries a CVSS 10.0. Censys ARC observes IBM MQ consoles on 120 hosts Internet-wide. IBM has released fixes; no active exploitation is currently known. https://bit.ly/4jh5qWx
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Zyxel
  • GS1900-48HPv2 firmware

16 Jun 2026
Published
21 Sep 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.32%

Description

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Statistics

  • 3 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-7273 – Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

Analyze the technical mechanics of CVE-2026-7273 with our Zyxel TSUITE brief, covering stack-based buffer overflows, CGI command execution, and endpoint hardening....

thecybermind.co/tcs0

  • 0
  • 0
  • 1
  • 5h ago
Profile picture fallback

CISA warned of an exploited Zyxel switch vulnerability in GS1900 devices. Patch the Zyxel switch vulnerability now to prevent network compromise.

securityonline.info/exploited-

  • 0
  • 0
  • 0
  • Last hour

Overview

  • WebPros
  • cPanel

29 Apr 2026
Published
11 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
98.53%

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Hackers Take Advantage of cPanel Vulnerability CVE-2026-41940 to Install Mirai Malware #internet #cybersecurity

Hackers exploit cPanel CVE-2026-41940 to install Mirai malware, turning vulnerable servers into botnet launchpads. Patch promptly, disable Telnet, tighten remote access, and monitor for unusual activity. Read more: ift.tt/U3wYSdn

Source: ift.tt/U3wYSdn | Image: ift.tt/7rTWDaH

  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback

CVE-2026-41940 de cPanel para desplegar malware Mirai

blog.elhacker.net/2026/09/cve-

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Linux
  • Linux

25 Jun 2026
Published
19 Sep 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.28%

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: Last hour

Fediverse

Profile picture fallback

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53266 – Linux Kernel Out-of-Bounds Write Vulnerability

Analyze the executive impact of CVE-2026-53266 with our strategic Linux CSUITE brief, covering kernel out-of-bounds write risks, compliance assurance, and board-level risk communication....

thecybermind.co/n7ln

  • 0
  • 1
  • 0
  • 6h ago

Bluesky

Profile picture fallback
CISA added 3 exploited Linux kernel flaws to its KEV catalog: CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266. Risks include DoS, memory disclosure, crashes, and corruption. #LinuxKernel #CISA #CVEs
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
CISA reports active exploitation of 3 Linux kernel flaws, including CVE-2025-39964, a 14-year-old critical AF_ALG race condition. Red Hat and researchers also confirmed exploits for CVE-2025-39682 and CVE-2026-53266. #CISA #LinuxKernel #RedHat
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
CISA、Linux Kernelの脆弱性 CVE-2025-39964・CVE-2026-53266・CVE-2025-39682のサイバー攻撃での悪用を確認、KEVカタログに追加 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース #脆弱性
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Linux
  • Linux

13 Oct 2025
Published
19 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.79%

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

Statistics

  • 4 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2025-39964 – Linux Kernel Race Condition Vulnerability

Analyze the mechanics of CVE-2025-39964 with our technical Linux TSUITE brief, covering AF_ALG race conditions, CrowdStrike CQL queries, and endpoint hardening....

thecybermind.co/dxag

  • 0
  • 0
  • 0
  • 13h ago

Bluesky

Profile picture fallback
CISA added 3 exploited Linux kernel flaws to its KEV catalog: CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266. Risks include DoS, memory disclosure, crashes, and corruption. #LinuxKernel #CISA #CVEs
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
CISA reports active exploitation of 3 Linux kernel flaws, including CVE-2025-39964, a 14-year-old critical AF_ALG race condition. Red Hat and researchers also confirmed exploits for CVE-2025-39682 and CVE-2026-53266. #CISA #LinuxKernel #RedHat
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
CISA、Linux Kernelの脆弱性 CVE-2025-39964・CVE-2026-53266・CVE-2025-39682のサイバー攻撃での悪用を確認、KEVカタログに追加 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース #脆弱性
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Cisco
  • Cisco Secure Email

14 Sep 2026
Published
18 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.01%

Description

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Statistics

  • 1 Post
  • 8 Interactions

Last activity: 18 hours ago

Fediverse

Profile picture fallback

🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and…

Also tracked this week: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping · Check Point, Kaspersky, Tanium…

nexus8.8bitsecurity.com/entity

  • 2
  • 6
  • 0
  • 18h ago

Overview

  • Fortra
  • GoAnywhere MFT

18 Sep 2025
Published
04 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
99.80%

Description

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 11 hours ago

Bluesky

Profile picture fallback
Is This Bad? This Feels Bad. (GoAnywhere CVE-2025-10035) - watchTowr Labs
  • 0
  • 1
  • 0
  • 11h ago
Profile picture fallback
It Is Bad (Exploitation of Fortra GoAnywhere MFT CVE-2025-10035) - Part 2 - watchTowr Labs
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • GNU
  • inetutils

13 Mar 2026
Published
23 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
23.67%

KEV

Description

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

Statistics

  • 1 Post

Last activity: 7 hours ago

Fediverse

Profile picture fallback

We preserved a 1994 Telnet bug for thirty years because industrial downtime costs money, only to discover clean exploitation is too tedious to bother weaponizing.
labs.watchtowr.com/a-32-year-o

  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Ivanti
  • Endpoint Manager Mobile

13 May 2025
Published
26 Feb 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
86.52%

Description

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

Statistics

  • 2 Posts

Last activity: 11 hours ago

Fediverse

Profile picture fallback

🚨 In this week’s Threat Alert, we cover CVE-2025-4427, an authentication bypass in Ivanti Endpoint Manager Mobile (EPMM) that can be chained with CVE-2025-4428 for unauthenticated remote code execution. CrowdSec has observed 865 unique IP addresses sending requests matching the exploitation pattern since May 2025.

Read our latest article for the full analysis, protection recommendations, and more: crowdsec.net/vulntracking-repo

Keep your network informed. Like and share this post!

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
🚨 This week’s Threat Alert covers CVE-2025-4427, an Ivanti EPMM authentication bypass that can lead to unauthenticated RCE when chained with CVE-2025-4428. CrowdSec has observed 865 unique IPs matching the exploitation pattern since May 2025. Read more: www.crowdsec.net/vulntracking...
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Thinking Software Technology
  • EFence

14 Sep 2026
Published
14 Sep 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.34%

KEV

Description

EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CVE-2026-89180: SQLi in Thinking Software EFence lets unauthenticated attackers read database contents. CVSS 7.5, no patch yet. Apply mitigations now. valtersit.com/cve/CVE-2026-891 #CVE #infosec #SQLi

  • 0
  • 0
  • 0
  • 5h ago
Showing 1 to 10 of 46 CVEs