24h | 7d | 30d

Overview

  • Gitea
  • Gitea

26 Aug 2026
Published
26 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
84.55%

Description

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Statistics

  • 5 Posts
  • 10 Interactions

Last activity: 12 hours ago

Bluesky

Profile picture fallback
We are scanning/reporting Gitea instances vulnerable to CVE-2026-60004 (code injection), with 8393 IPs found vulnerable on 2026-08-27. This vulnerability is exploited in the wild and on US CISA KEV. Top affected: China, Germany, US Dashboard view: dashboard.shadowserver.org/statistics/c...
  • 4
  • 6
  • 0
  • 16h ago
Profile picture fallback
Over 8,300 Internet-exposed Gitea servers remain unpatched for CVE-2026-60004, a critical code injection flaw used for remote code execution and crypto-mining malware via the diffpatch API. #Gitea #CVE202660004 #CISA
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
📢 [VULN] CVE-2026-60004 : RCE critique de Gitea exploitée pour déployer des charges utiles semblables à des mineurs | SOC Prime Une vulnérabilité critique d’exécution de code à distance dans Gitea est passée de la divulgation à une exploitation active moins d’un m… #Vulnérabilité #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
IP data shared in Vulnerable HTTP reporting tagged 'cve-2026-60004': www.shadowserver.org/what-we-do/n... Patch Tracker: dashboard.shadowserver.org/statistics/c... Exploit code is public. Gitea advisory: blog.gitea.com/release-of-1... NVD entry: nvd.nist.gov/vuln/detail/... #CyberCivilDefense
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

📰 Critical cPanel Flaw Allows Hosting Customers to Gain Root Access

Critical cPanel vulnerability (CVE-2026-65643) allows any authenticated user to gain full root access on shared hosting servers by abusing the domain parking feature. Patches are available and must be applied immediately. #cPanel #Vulnerability #Cybe...

🔗 cyber.netsecops.io/articles/cr

  • 1
  • 0
  • 0
  • 13h ago
Profile picture fallback

⚠️ CRITICAL: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

A critical vulnerability in cPanel/WHM (CVE-2026-65643) allows authenticated hosting customers to escalate privileges to root on shared servers via domain parking and addon domain features. Any customer account can exploit this to achieve full server compromise. If your infrastructure runs cPanel/W…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
CVE-2026-65643 in cPanel/WHM domain parking and addon domains can allow authenticated users to create files and execute code as root.
  • 1
  • 0
  • 0
  • 18h ago

Overview

  • NetScaler
  • ADC

30 Jun 2026
Published
27 Aug 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
1.61%

Description

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Statistics

  • 4 Posts

Last activity: 13 hours ago

Fediverse

Profile picture fallback

Geopolitical tensions persist with US-Iran disputes over the Strait of Hormuz, while a devastating glacial collapse hits Nepal-Tibet. In technology, Nvidia forecasts a 70% revenue jump driven by AI demand, and SK Hynix breaks ground on a $4B US HBM plant in Indiana. Cybersecurity highlights CISA's urgent call to patch exploited Citrix NetScaler vulnerabilities (CVE-2026-8452) and a collective warning from over 100 companies, including OpenAI, on the need for urgent AI-powered cyber defenses against increasingly sophisticated AI threats.

#AnonNews_irc #Cybersecurity #AI

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback

CISA impone un parche urgente por un fallo crítico en Citrix NetScaler con explotación activa

CISA ha metido CVE-2026-8452 en su catálogo Known Exploited Vulnerabilities y obliga a las agencias federales de EEUU a parchear Citrix NetScaler antes del 29 de agosto de 2026. La falla, que empezó describiéndose como un problema de denegación de servicio

unaaldia.hispasec.com/cisa-imp

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

CISA urges immediate patching for a critical Citrix NetScaler vulnerability (CVE-2026-8452) actively exploited in the wild. The FBI and DOJ disrupted a China-linked hacking group (QTFY) targeting US critical infrastructure, including hospitals. Over 100 tech firms, including Microsoft and OpenAI, issued a joint warning about escalating AI-driven cyber threats, calling for enhanced defenses. In technology, Nvidia's strong earnings and 70% revenue growth forecast significantly boosted tech markets. Geopolitically, the US-Iran conflict persists, with Qatar initiating new mediation efforts.

#Cybersecurity #AnonNews_irc #News

  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback

📰 Public PoC for Critical Citrix NetScaler Pre-Auth RCE Released

A public PoC exploit is now available for a critical pre-auth RCE vulnerability (CVE-2026-8452) in Citrix NetScaler ADC & Gateway. No patch is available yet. Admins should monitor devices closely. #Citrix #RCE #PoC

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Pending

21 Nov 2023
Published
28 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
41.19%

Description

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

Statistics

  • 3 Posts

Last activity: 9 hours ago

Fediverse

Profile picture fallback

🚨 Critical Threat Intel: CVE-2023-49105 impacts ownCloud via improper authentication, enabling unauthenticated file access if signing-keys are missing. Review SIEM queries (Splunk, Sentinel, QRadar), API monitoring, and hardening steps: thecybermind.co/jily

  • 0
  • 0
  • 0
  • 14h ago

Bluesky

Profile picture fallback
CISA added ownCloud CVE-2023-49105 to KEV after reports of weaponized exploitation targeting Philippine organizations, including a nuclear research body.
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
Hackers Exploit CVE-2023-49105 to Steal Nuclear Records From Philippine Research Agency https://gbhackers.com/cve-2023-49105-flaw-exploited/
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

11 Aug 2026
Published
28 Aug 2026
Updated

CVSS v3.1
HIGH (8.0)
EPSS
0.95%

KEV

Description

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Statistics

  • 1 Post
  • 28 Interactions

Last activity: 21 hours ago

Fediverse

Profile picture fallback

🚨 Für die kritische Schwachstelle CVE-2026-62911 in Microsoft Exchange wurde ein PoC-Exploit veröffentlicht, der die vollständige Übernahme von Systemen aus der Ferne ohne Authentifizierung ermöglicht. Der Hersteller veröffentlichte am 11.08. einen Patch. Aktuell sind jedoch noch rund 85% der on-premises Exchange-Server in Deutschland für diese Schwachstelle verwundbar. CERT-Bund benachrichtigt deutsche Netzbetreiber seit dem 14.08. regelmäßig zu noch verwundbaren Systemen in ihren Netzen.

  • 19
  • 9
  • 0
  • 21h ago

Overview

  • ServiceNow
  • ServiceNow AI Platform

27 Aug 2026
Published
29 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.38%

KEV

Description

ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 12 hours ago

Fediverse

Profile picture fallback

📰 ServiceNow Patches Three Critical CVSS 10.0 Flaws in AI Platform

ServiceNow patches three critical unauthenticated flaws (CVSS 10.0) in its AI Platform. The vulnerabilities (CVE-2026-18885, -18886, -74820) allow for RCE, privilege escalation, and SQL injection. Self-hosted customers must patch immediately. #Servic...

🔗 cyber.netsecops.io/articles/se

  • 1
  • 0
  • 0
  • 13h ago
Profile picture fallback

ServiceNow Patches Three CVSS 10.0 Vulnerabilities Allowing Unauthenticated Code Execution and SQL Injection

ServiceNow patched three CVSS 10.0 vulnerabilities allowing unauthenticated code execution, privilege escalation and SQL injection

thecybersecguru.com/news/servi

  • 0
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
ServiceNow patched three max-severity AI Platform flaws enabling code injection, SQL injection, and privilege escalation, plus a high-severity sandbox escape bug. #ServiceNow #CVE202618885 #CVE202618886
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Ebyte
  • Ebyte NE2-D11 Firmware

27 Aug 2026
Published
28 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.53%

KEV

Description

Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

🚨 Critical CVE-2026-73125 impacts Ebyte NE2-D11 devices

A critical missing-authentication vulnerability in the Ebyte NE2-D11 web management interface could allow a remote, unauthenticated attacker to access administrative functionality.

CVE-2026-73125 carries a CVSS 3.1 score of 9.8 and requires no privileges or user interaction. Successful exploitation could allow attackers to:

• Access sensitive configuration data
• Modify device settings
• Disrupt device availability

Affected firmware: FW-9167-0-11

Ebyte indicated a patch was under development, but CISA says it has not been informed of the patch's current availability. No confirmed active exploitation has been reported at this time.

CISA: cisa.gov/news-events/ics-advis

  • 1
  • 1
  • 0
  • 11h ago
Profile picture fallback

Critical Ebyte NA111-M vulnerabilities like CVE-2026-73125 could allow attackers to fully compromise the device. Review CISA guidance and mitigations.

securityonline.info/ebyte-na11

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Linux
  • Linux

04 Jul 2026
Published
28 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.51%

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Over 100 tech and cybersecurity firms, including OpenAI, issued a joint warning (Aug 27-28, 2026) regarding escalating AI-driven cyberattacks, urging global defense collaboration. Separately, Zeabur confirmed an environment variable leak on August 27, 2026, compromising user API keys for services like Claude and OpenRouter. CISA also added a critical Linux kernel privilege escalation vulnerability (CVE-2026-53362) to its exploited catalog.

#Cybersecurity #AI #TechNews

  • 0
  • 1
  • 0
  • 5h ago

Bluesky

Profile picture fallback
Agents exploited CVE-2026-53362 in an OpenAI environment to gain root access and move laterally after customizing a Linux kernel exploit.
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Unitree Robotics
  • G1 EDU

27 Aug 2026
Published
27 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.71%

KEV

Description

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers can publish DDS control messages to restart the bashrunner service, plant a malicious payload in its script execution directory via path traversal, and trigger execution of that payload as uid 0 through the bashrunner shell subprocess.

Statistics

  • 2 Posts

Last activity: 15 hours ago

Bluesky

Profile picture fallback
📢 UniBLEed : RCE root non authentifié sur robot humanoïde Unitree G1 via BLE (CVE-2026-76639/76640) Cet article constitue une analyse technique exhaustive (~85 min de lecture) de deux chaînes d'exploitation critiques… 🟡 vérification factuelle moyenne #UnitreeG1 #RobotHumanoïde #Cyberveille
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Two independent root RCE chains affect the Unitree G1 EDU, including a BLE path to root on the Locomotion PC, tracked as CVE-2026-76639 and CVE-2026-76640.
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 7 hours ago
Showing 1 to 10 of 44 CVEs