24h | 7d | 30d

Overview

  • Fortinet
  • FortiMail

01 Oct 2026
Published
02 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.78%

Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Statistics

  • 17 Posts
  • 7 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Attackers exploit CVE-2026-104286, a 9.8 FortiMail vulnerability allowing unauthenticated file writes. CISA adds it to KEV. Apply the workaround.

securityonline.info/fortimail-

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback

🚨 NEW on CISA KEV — exploited in the wild

🛡 Fortinet FortiMail
Fortinet FortiMail Path Traversal Vulnerability
CVE: CVE-2026-104286 · patch by 2026-10-04

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

🔗 ninjasignal.ninja/intel/cve/CV
#cybersecurity #KEV #CVE #infosec

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a path traversal vulnerability that can be triggered through […]
U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

⚠️ CVE-2026-104286 (vulnerability.circl.lu/vuln/CV) — FortiMail, vulnérabilité critique et déjà exploitée comme 0-day.

S’il fallait encore des exemples sur le rythme auquel il faut désormais suivre les correctifs des équipements exposés : après Cisco, Citrix, Zimbra… voilà à nouveau FortiMail. 🙃

Sans authentification, un attaquant peut écrire des fichiers et exécuter du code via l’interface de gestion.

"Bien évidemment", il s’agit d’une bonne vieille traversée de chemin .../.../... :dumpster_fire_gif:

➡️ En attendant les versions corrigées : désactiver IBE ou restreindre strictement l’accès à l’interface d’administration.

🩹
👇 fortiguard.fortinet.com/psirt/

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

Critical Threat Advisory: CVE-2026-104286 Fortinet FortiMail

Immediate CISA KEV threat advisory for CVE-2026-104286 affecting Fortinet FortiMail. Includes behavioral workflow analysis, BOD 26-04 patch compliance guidance, and multi-vendor SOC detection queries....

thecybermind.co/t645

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

Critical Fortinet FortiMail Zero-Day (CVE-2026-104286) Actively Exploited: Unauthenticated File Write Flaw Exposes Email Security Gateways Worldwide

CVE-2026-104286 is an actively exploited FortiMail zero-day allowing unauthenticated arbitrary file writes. See affected versions, IOCs and fixes

thecybersecguru.com/exploits/f

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

🚨 Fortinet sounds the alarm over actively exploited FortiMail zero-day

「 The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform 」

theregister.com/security/2026/

#fortinet #fortimail #cybersecurity

  • 0
  • 0
  • 1
  • 2h ago

Bluesky

Profile picture fallback
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.
  • 3
  • 4
  • 1
  • 22h ago
Profile picture fallback
Fortinet、ゼロデイ攻撃で悪用されているFortiMailの重大な脆弱性について警告:CVE-2026-104286 | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47886/
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Fortinet disclosed CVE-2026-104286, a critical FortiMail flaw with a 9.8 CVSS score, actively exploited in zero-day attacks to write files and run unauthorized code. #Fortinet #FortiMail #CVE-2026-104286
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
CISA added Fortinet FortiMail path traversal and NULL byte flaw CVE-2026-104286 to KEV after active exploitation, enabling unauthenticated arbitrary file writes.
  • 0
  • 0
  • 1
  • 15h ago
Profile picture fallback
CVE-2026-104286 in FortiMail is actively exploited, enabling arbitrary file writes and potential code execution; CISA added it to KEV and urges rapid mitigation.
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) 🔗 Read more: www.helpnetsecurity.com/2026/10/02/f... #zeroday #vulnerability #cybersecurity
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
~Cybergcca~ CVE-2026-104286 is actively exploited; update affected FortiMail versions. - IOCs: CVE-2026-104286 - #CVE-2026-104286 #Fortinet #ThreatIntel
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Zimbra
  • Collaboration

13 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
11.74%

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Statistics

  • 5 Posts
  • 4 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Attackers have been #exploiting critical #Zimbra flaw to steal emails

#Hackers have been exploiting a critical #vulnerability in the #ZimbraCollaborationSuite in an attempt to obtain email backups and authentication credentials of #vulnerable organzations, #Microsoft has warned.

The vulnerability, tracked as CVE-2026-73570, lets attackers remotely issue operating system commands without #authentication. Zimbra maintainer Synacor issued a patch on July 20, but didn’t disclose the vulnerability for more than three weeks after that. The security-focused #Shadowserver Foundation said last week that its scans found that 274 separate instances of the Zimbra Collaboration Suite had been compromised. The number of #servers running the software has fluctuated from 19,000 in the week following the patch to about 12,000 in the weeks following that. Currently, Shadowserver is tracking about 10,000 instances.
#privacy #security

arstechnica.com/security/2026/

  • 0
  • 1
  • 0
  • 22h ago

Bluesky

Profile picture fallback
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 | Microsoft Security Blog www.microsoft.com/en-us/securi...
  • 1
  • 2
  • 0
  • 11h ago
Profile picture fallback
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 - OS command injection vulnerability in the Zimbra Collaboration Suite SNMP notification path.
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • GitLab
  • GitLab AI Gateway

02 Oct 2026
Published
02 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
Pending

KEV

Description

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

Statistics

  • 4 Posts
  • 9 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Go hack more AI shit.
Go hack more Gitlab.

But most importantly, hack more Gitlab AI shit: db.gcve.eu/vuln/cve-2026-90970

  • 2
  • 3
  • 0
  • 5h ago
Profile picture fallback

Go hack more AI shit.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

  • 0
  • 4
  • 0
  • 5h ago

Bluesky

Profile picture fallback
A critical GitLab AI Gateway flaw (CVE-2026-90970) could let authorized users execute commands; fixed in versions 19.2.4, 19.3.2, and 19.4.1.
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
GitLab disclosed CVE-2026-90970, a critical AI Gateway RCE that can let authenticated users with basic privileges escape the sandbox and run arbitrary commands on self-hosted instances. #GitLab #CVE202690970 #AIGateway
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.06%

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Statistics

  • 4 Posts
  • 5 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

This Week in Security: ShinyHunters Won’t Dox the FBI, Pentagon Data Stolen, and OBS Vulnerable

404 Media reports that the ShinyHunters group who stole multiple terabytes of FBI employee data say they do not plan to release the data.

Known for ransomware and extortion of innumerable companies and government agencies, ShinyHunters used a zero-day vulnerability in Oracle PeopleSoft to compromise the employment site of the FBI and pivot into scraping the content of FBI AWS instances, claiming to have the full employment and health data of all FBI agents, employees, and spouses.

The hacker group took exception to an FBI press release that claimed that the group over-stated stolen data and that they directly harass victims and victim’s families. The group publicized the FBI data breach, demanding a retraction of the statements, and it was generally assumed that the group would follow their typical methods of releasing the data publicly if the demands were not met.

The group has told 404 media that they had always agreed internally to not release the stolen data, saying “This was all a marketing campaign to protect our business and actively combat disinformation”. Meanwhile the FBI continues the investigation, and Shiny Hunters may be hoping to defer some of the ire.

Pentagon Data Breach


A data breach at the Defense Manpower Data Center lasted for nine months before it was discovered, and allowed unknown attackers to exfiltrate information on military personnel.

The information stolen includes social security numbers and “operational specialty” data about where a service member is employed within the armed forces. The DMDC handles data on 60 million current and former service members, but the report does not specify the number impacted.

Currently the source of the attack is unknown; the attackers may be a typical data ransom or theft group, but information about service members could easily be used by foreign intelligence groups.

This is, of course, a different attack and leak of US government employee data, independent of the attack on the FBI.

OpenAI Hacked Australian Government Databases


The Australian Prime Minister, Anthony Albanase, has released a statement that OpenAI was involved in a hacking incident against the Australian government health services site.

This is independent of other incidents involving OpenAI agents hacking live Internet sites during testing; OpenAI says the hack was discovered on September 10, 2026, but the incident occurred in June of 2026, prior to the hack of the HuggingFace site.

In the Hugging Face attack, AI agents were asked to complete a cyber security challenge and responded by finding and utilizing vulnerabilities to steal the solutions. A report by Translucence (an AI research lab) finds however that in this instance, the agents were tasked with non-cyber related research and opted to exploit not only the Australian health services site but also the University of New Mexico digital library and Data USA, a platform for collecting and visualizing US government data.

OpenAI says the review of the incident remains ongoing, and that no private patient data was compromised. The Australian government, obviously, has stronger opinions about how the incident occurred and the length of time before they were notified. If agents are defaulting to exploiting live Internet sites for normal queries, we’re likely to keep finding more stories like this.

Physical Attack Against MacOS Lockdown Mode


Researcher Kevin Kessler at glyph.sh discloses a new vulnerability in macOS that can allow keyboard attacks even when lockdown mode is enabled.

MacOS has built-in protection measures against malicious USB devices. Readers using macOS may have seen prompts to allow a USB device to connect the first time it is plugged in; additionally, new USB devices are ignored if a Mac has been locked for more than an hour.

In the extra-paranoid “Lockdown Mode”, macOS will also prevent connections to USB devices entirely while the device is locked. Lockdown mode also disables other operating system features that are suspected of being less secure, like custom web fonts, just-in-time compilation of JavaScript to native code, and direct messaging from unknown contacts. This attack defeats all of these protections.

Due to the architecture of USB, if a USB hub is connected to macOS and trusted, all devices plugged into that hub are automatically trusted. A composite USB device — a device that presents as multiple types of USB interfaces on a single connection — can identify as both a serial port and a keyboard in a single device.

Typically macOS would prompt the user that a new keyboard has been connected, but does not prompt the user when a new USB serial port device is connected to a trusted hub. Presenting as both a serial device and a keyboard, key presses are accepted automatically, with no user prompt.

Kessler demonstrates copying sensitive user data like SSH keys and cloud provider authentication tokens directly over the USB serial device, a trick which may bypass endpoint protection tools looking for copied files.

Apple told the researcher that the behavior is expected when a USB hub has been trusted, and that composite USB devices are outside the scope of the protection mechanisms. If so, perhaps it needs to be more clearly communicated to users the risk of trusting any USB hub or dock if an attacker could conceivably get physical access.

Spying with File Update Notifications


New attacks against the file notification systems of all major operating systems — Windows, macOS, Linux, and Android — will be shown at the November 2026 ACM security conference.

File notification systems are a crucial part of almost all modern operating systems, letting the UI and background services receive alerts that file content has changed, instead of constantly querying file modification times. Unfortunately, it seems like all of them have major issues and allow bypassing permissions and access restrictions.

The researchers call out Windows as the worst offender: it allows a notification to be set for any file modification, system wide, regardless of access permission or what user owns it. To be fair, it seems like Linux, macOS, and Android aren’t too far behind however.

On Linux, the inoti.fyi researchers discovered that while notifications can’t be set on files the user isn’t allowed to access, notifications can still be set on readable parent directories, and will still report changes to the files. Leveraging this oversight against the /dev/input directory, events are raised for every keystroke, and they reference decades of research on using keystroke timing to guess what was typed.

For Android, permission oversights allow one application to set notifications for the private storage of other applications. Normally, each application runs in a separate sandbox and has no insight into the behavior of other apps, using the Android file notification API, they demonstrate monitoring WhatsApp to log the exact time messages and photos are received.

The Windows vulnerability may be the most immediately severe, where the inoti.fyi team is able to monitor the cache and local storage directories of browsers. Browsers like Firefox create files with the name of the website; by monitoring the cache directories, it’s possible to monitor the websites loaded by any user on the system.

The team has been working with vendors to address the issues, however in most cases there are no fixes available yet.

OBS Streaming Platform Vulnerable


OBS is a popular tool for streamers, compositing multiple cameras, screen and video capture, and more. A large percentage of streamers on the Internet use OBS.

Orange Cyberdefense Switzerland reports vulnerabilities in OBS due to the embedded Chromium browser source. Chromium is the open-source engine behind Chrome, Opera, Microsoft Edge, Vivaldi, and many other browsers; OBS embeds the browser engine to allow embedded web content and web-based applications inside a stream.

Streamers often have an embedded display of the chat associated with their stream, encouraging audience participation. These embeds usually use a browser window to stylize the chats and embed images, which exposes them to whatever the content of the chat message is. Astute readers may already guess how this is a problem.

In a typical browser, each tab is isolated in an independent sandbox, preventing it from interacting with other tabs or the browser itself, but in the OBS embedded browsers, sandboxes are disabled. OBS also used a two-year-old Chromium engine that contained a publicly known and patched bug in the V8 JavaScript engine. The bug had already been exploited in the wild by North Korean hackers, but the impact was limited thanks to the sandbox mechanism isolating each tab. With no sandbox, malicious HTML and JavaScript rendered by a web view could directly execute code on the system, taking over the OBS instance or the whole system.

The researchers at Orange have worked with OBS to update the embedded Chromium version, but also offer the advice that untrusted HTML should be avoided whenever possible: No OBS widget should ever render user or chat content as HTML.

DIVD Hacked


DIVD, the Dutch Institute for Vulnerability Disclosure, announced that they were the victims of a recent hack themselves.

DIVD says that the attackers got in through two previously unknown bugs in the Zammad help desk software, and that the attackers appear to be AI agents. Within seconds, attackers hijacked Zammad sessions, gained code execution, and then gained root access to the system. DIVD says the attackers immediately began to exfiltrate data from the impacted systems, but were blocked from accessing other government systems.

The Institute is using this as a teaching moment, not only releasing an advisory for the Zammad system, but making a candid LinkedIn post discussing the incident and the responses: “So what do hackers do when they get hacked? Handle it the way we think it should be handled. That is open, transparent and honest, even if it sucks.”

Enterprise Networking Vulnerabilities


Major vulnerabilities have been found exploited in the wild for both Cisco Catalyst SD-WAN and Citrix Netscaler enterprise devices. A relatively bland Cisco announcement discloses that all versions of the Cisco Catalyst SD-WAN Manager allow unauthenticated, remote, admin access. (!)

The Citrix Netscaler article, on the other hand, comes from the team at watchTowr. Anyone who has been reading for the past months should know that a post from watchTowr is a guaranteed good read. Not only are the vulnerabilities in Netscaler plentiful and severe, but they were widely known and exploited before Citrix finally released a vulnerability statement.

The Netscaler vulnerabilities include arbitrary commands from unauthenticated users, remote code execution and denial of service attacks against the VPN server, multiple memory overflows, and predictable random generation in some situations.

WatchTower digs into the firmware changes for more details, so if seeing how Perl is still used in 2026 enterprise equipment tickles your fancy, be sure to give them a read.

hackaday.com/2026/10/02/this-w…
RE: 404media.co/.ghost/activitypub…

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

🚨 Reports of NetScaler Incidents After Latest Patch Raise Concerns Over Continued Exploitation

Multiple Citrix administrators are reporting suspicious activity affecting NetScaler appliances even after updating to version 14.1-73.37.

The reports surfaced on Reddit, where one administrator said multiple customers experienced incidents that caused externally accessible NetScaler appliances to repeatedly reboot.

Other administrators reported similar behavior on newly rebuilt appliances, including systems where Enhanced ISN Generation had already been enabled. Several affected organizations said they collected forensic data and opened cases with Citrix.

It is currently unclear whether the activity represents successful exploitation of a new or existing vulnerability, residual compromise, vulnerability scanning, or an issue with the updated firmware.

The reports come days after Citrix disclosed active exploitation of CVE-2026-88771 and CVE-2026-88772, two critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway.

The latest post-patch activity has not yet been confirmed by Citrix as exploitation.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

Source: reddit.com/r/Citrix/comments/1

  • 2
  • 3
  • 0
  • 4h ago
Profile picture fallback

⚠️ CRITICAL: Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

NetScaler ADC and Gateway instances are being actively exploited via CVE-2026-88771 and CVE-2026-88772 to achieve root access and deploy web shells. Government and finance organizations have been targeted since early September, with attackers moving laterally post-compromise. State-sponsored actors…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
I'm seeing Sliver being deployed onto netscalers #netscaler #exploit #cve #catalinwhenwillyou-repostmyawesomeposts #cve202688771
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • checkpoint
  • Quantum Security Management

22 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
19.65%

Description

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CVE-2026-93616 Check Point Management Server path traversal and file upload, unauth RCE, CVSS 9.8. Patch under review, so isolate exposed servers now. valtersit.com/cve/CVE-2026-936 #CVE #infosec #CheckPoint

  • 0
  • 0
  • 0
  • 5h ago

Bluesky

Profile picture fallback
As promised, here's our walkthrough of CVE-2026-93616, an unauthenticated root RCE affecting Check Point Security Management and Multi-Domain Management servers! bishopfox.com/blog/weaponi...
  • 0
  • 1
  • 0
  • 22h ago

Overview

  • Apple
  • iOS and iPadOS

28 Sep 2026
Published
01 Oct 2026
Updated

CVSS
Pending
EPSS
1.24%

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Statistics

  • 2 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

How to detect the Apple iOS/macOS recent 0-day CVE-2026-86950 in PDF files?
I developed a python tool for that, based on the PoC published two days ago:
decalage.info/CVE-2026-86950/

  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
Apple、標的型攻撃で悪用されたCoreGraphicsのゼロデイ脆弱性を修正(CVE-2026-86950) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47861/
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • Oracle Corporation
  • PeopleSoft Enterprise PeopleTools

11 Jun 2026
Published
04 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
9.44%

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Statistics

  • 2 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

The ShinyHunters extortion gang is bypassing Web Application Firewall (WAF) rules by using URL-encoding tricks to exploit the Oracle PeopleSoft CVE-2026-35273 vulnerability. Mandiant urges organizations to apply the official security update rather than relying on WAF blocks, as attackers continue to deploy web shells and malware to steal sensitive data.
bleepingcomputer.com/news/secu

  • 0
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
Des attaquants contournent les WAF pour exploiter une faille critique Oracle #PeopleSoft (CVE-2026-35273) et déployer des web shells, ciblant plusieurs secteurs mondialement. 🚨 #CyberSecurity #calimeg
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Cisco
  • Cisco Catalyst SD-WAN Manager

30 Sep 2026
Published
01 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.58%

Description

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Fediverse

Profile picture fallback

Recent geopolitical news indicates Russia initiated a winter strike campaign targeting Ukraine's energy infrastructure on September 30. In cybersecurity, CISA added a critical Cisco Catalyst SD-WAN Manager authentication bypass flaw (CVE-2026-76504) to its Known Exploited Vulnerabilities catalog on September 30. On the technology front, Chinese hackers were reported to be impersonating AI experts to target US policy minds on October 1. Additionally, the NSA announced new post-quantum cryptography measures to safeguard national security systems on October 1.

#AnonNews_irc #Cybersecurity #News

  • 0
  • 0
  • 0
  • 22h ago

Bluesky

Profile picture fallback
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability (CVE-2026-76504) #patchmanagement
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Bluesky

Profile picture fallback
Dell patched 6 critical flaws in Container Storage Modules for Kubernetes, including max-severity bugs that could expose admin credentials and enable full takeover. Update to version 1.18.0+ fast. #DellCSM #Kubernetes #CVE202663688
  • 0
  • 1
  • 0
  • 4h ago

Overview

  • Red Hat
  • Red Hat Directory Server 11
  • 389-ds-base

01 Oct 2026
Published
02 Oct 2026
Updated

CVSS
Pending
EPSS
0.38%

KEV

Description

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.

Statistics

  • 2 Posts

Last activity: 18 hours ago

Fediverse

Profile picture fallback

Red Hat Directory Server 11: CVE-2026-86345 (CRITICAL, CVSS 9) allows on-path attackers to inject LDAP messages post-StartTLS, risking auth bypass. Restrict access, check Red Hat advisory radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback

A 9.9 Foreman RCE flaw, CVE-2026-96658, lets low-privileged users run commands on Red Hat Satellite. A Viewer bug leaks root passwords.

securityonline.info/foreman-rc

  • 0
  • 0
  • 0
  • 18h ago
Showing 1 to 10 of 76 CVEs