24h | 7d | 30d

Overview

  • GitLab
  • GitLab AI Gateway

02 Oct 2026
Published
02 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.94%

KEV

Description

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

Statistics

  • 4 Posts

Last activity: 7 hours ago

Fediverse

Profile picture fallback

GitLab AI Gateway vulnerability CVE-2026-90970 (CVSS 9.9) lets Duo Agent Platform users run commands. Upgrade self-hosted gateways now.

securityonline.info/gitlab-ai-

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to […]
CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

Critical GitLab AI Gateway vulnerability (CVE-2026-90970) enables remote code execution on self-hosted servers

GitLab CVE-2026-90970 is a critical 9.9 AI Gateway sandbox escape affecting self-hosted deployments. Check affected versions and patches

thecybersecguru.com/exploits/g

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
GitLab fixed CVE-2026-90970, a critical 9.9 AI Gateway flaw in self-hosted servers that could let logged-in Duo Agent Platform users run commands. Patched in 19.2.4, 19.3.2, and 19.4.1. #GitLab #CVE202690970 #DuoAgentPlatform
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

02 Oct 2026
Published
03 Oct 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.50%

KEV

Description

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Statistics

  • 5 Posts

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Es gibt mehrere #Sicherheits #Updates für #Microsoft #Exchange #Server, die gleich mehrere Schwachstellen, u.a. die Elevation of Privilege-Schwachstelle #CVE-2026-96940 schließen.

borncity.com/blog/2026/10/02/e

  • 0
  • 0
  • 1
  • 23h ago
Profile picture fallback

PSA: Exchange Server V2 Security Updates for September were published, additionally addressing CVE-2026-96940 eightwone.com/2026/10/03/v2-se #MSExchange

  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback

CVE-2026-96940 - Privilege Escalation in Microsoft Exchange Server from weak authorization. CVSS 8.8. Currently unpatched. Restrict network access now. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-969

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Fortinet
  • FortiMail

01 Oct 2026
Published
02 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.20%

Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Statistics

  • 4 Posts
  • 2 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

📰 Critical Fortinet FortiMail Zero-Day Exploited for RCE

Fortinet warns of critical zero-day (CVE-2026-104286) in FortiMail, actively exploited for RCE. CVSS 9.8. CISA added to KEV. Patches are pending, but urgent workarounds are available. #Fortinet #ZeroDay #CVE2026104286 #CyberSecurity

🔗 cyber.netsecops.io/articles/cr

  • 1
  • 0
  • 0
  • 2h ago
Profile picture fallback

🚨 Fortinet reports active exploitation of CVE-2026-104286, a critical path traversal vulnerability affecting FortiMail.

Censys observes roughly 2,800 Internet-exposed FortiMail hosts after excluding honeypots. This is an exposure count, not a confirmed-vulnerable count.

No fixed builds have been released as of October 2. Censys ARC covers affected versions, Fortinet’s current workarounds, indicators, and remediation guidance: censys.com/advisory/cve-2026-1

  • 0
  • 1
  • 0
  • 23h ago

Bluesky

Profile picture fallback
🚨 Fortinet reports CVE-2026-104286 is being exploited in the wild. Censys observes ~2,800 Internet-exposed FortiMail hosts, excluding honeypots. No fixed builds are available yet. Censys ARC advisory: https://bit.ly/4htjUkY
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
⚠️ FortiMail : Vulnérabilité critique (CVE-2026-104286). Risque d'accès complet à votre messagerie. 📧 Comment sécurisez-vous vos interfaces d'administration ? Découvrez notre analyse stratégique. 👇 [lire]
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
28 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.30%

Description

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

Statistics

  • 5 Posts
  • 13 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Citrix flags a NetScaler SAML authentication issue as patched NetScaler appliances reboot after CVE-2026-88771 attacks. Check your config.

securityonline.info/netscaler-

  • 1
  • 0
  • 0
  • 23h ago
Profile picture fallback

📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack

Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
Researchers at Mandiant and Google Threat Intelligence Group (GTIG) say that a critical memory overflow vulnerability in #Citrix NetScaler ADC and Citrix NetScaler Gateway (CVE-2026-88772, CVSS score 9.5) was exploited weeks before it was disclosed. www.theregister.com/security/202...
  • 1
  • 1
  • 0
  • 7h ago
Profile picture fallback
“This issue is understood to be separate from the vulnerabilities outlined below [CVE-2026-88771 and CVE-2026-88772].” www.cyber.gov.au/about-us/vie...
  • 1
  • 9
  • 0
  • 1h ago
Profile picture fallback
Bitget $388M Breach via Citrix NetScaler ADC Zero-Day Exploit https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772 https://flagthis.com/tldr/8192 ##Bitget ##ZeroDay ##LazarusGroup ##DataBreach ##Citrix
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.06%

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Statistics

  • 5 Posts
  • 11 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Looking for additional Citrix NetScaler IOC? Sygnia has novel and credible indicators from CVE-2026-88771 exploitation (published 9/30):

sygnia.co/threat-reports-and-a

  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback

Citrix flags a NetScaler SAML authentication issue as patched NetScaler appliances reboot after CVE-2026-88771 attacks. Check your config.

securityonline.info/netscaler-

  • 1
  • 0
  • 0
  • 23h ago
Profile picture fallback

📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack

Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
“This issue is understood to be separate from the vulnerabilities outlined below [CVE-2026-88771 and CVE-2026-88772].” www.cyber.gov.au/about-us/vie...
  • 1
  • 9
  • 0
  • 1h ago
Profile picture fallback
Bitget $388M Breach via Citrix NetScaler ADC Zero-Day Exploit https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772 https://flagthis.com/tldr/8192 ##Bitget ##ZeroDay ##LazarusGroup ##DataBreach ##Citrix
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • MikroTik
  • RouterOS

02 Oct 2026
Published
03 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.94%

KEV

Description

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 13 hours ago

Fediverse

Profile picture fallback

Saturday morning RouterOS 9.8 :apartyblobcat:

db.gcve.eu/vuln/cve-2026-84411

  • 1
  • 1
  • 0
  • 14h ago
Profile picture fallback

CVE-2026-84411 (CRITICAL, CVSS 9.8) affects MikroTik RouterOS <7.24. Integer underflow in web mgmt lets unauth'd attackers exec root code or DoS via crafted HTTP. Restrict access & monitor now. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback

#Mikrotik #RouterOS has a RCE (CVSS Score 9.8) in ANY version before 7.24. Hallelujah!

cve.org/CVERecord?id=CVE-2026-…

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Fortra
  • BoKS Manager boks-server

01 Oct 2026
Published
01 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.27%

KEV

Description

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

Statistics

  • 2 Posts

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Fortra BoKS faces 3 CRITICAL vulns (CVE-2026-79901, - 79898, - 12627): auth bypass, command injection as root, and remote memory corruption. No active exploits seen. Patch now to secure privileged environments! radar.offseq.com/threat/fortra

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
Fortra patched 8 BoKS flaws, including 3 critical bugs that could enable auth bypass, command injection, and remote memory corruption in Manager deployments and exposed interfaces. #Fortra #BoKS #CVE202679901
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Digi International
  • IX Family

02 Oct 2026
Published
03 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.53%

KEV

Description

A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Fediverse

Profile picture fallback

Digi DAL OS vulnerability CVE-2026-75937 (CVSS 9.4) lets attackers run root commands on Digi Accelerated Linux devices. Patch now.

securityonline.info/digi-dal-o

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback

Digi IX Family devices hit by CRITICAL OS command injection (CVE-2026-75937, CVSS 9.4). Unauthenticated remote attackers can execute root commands via HTTP POST. Disable web admin interface to reduce risk. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Google
  • Chrome

02 Oct 2026
Published
03 Oct 2026
Updated

CVSS
Pending
EPSS
0.33%

KEV

Description

Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Statistics

  • 2 Posts
  • 5 Interactions

Last activity: 18 hours ago

Fediverse

Profile picture fallback

Google Chrome published an empty blog post as a security advisory on Thursday afternoon. They filled it out in the past day, but don't make it easy to grasp the severity of their bugs.

For example, "Critical CVE-2026-103628: Out of bounds write in WebGL." is actually a CVSSv3.1: 9.6 critical because it allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. You'd have to chase down those details yourself on cve.org or elsewhere.

chromereleases.googleblog.com/

  • 3
  • 2
  • 0
  • 18h ago
Profile picture fallback

Chrome security update: Chrome 154 fixes 11 flaws, including critical WebGL sandbox escape CVE-2026-103628. Update your browser now.

securityonline.info/chrome-sec

  • 0
  • 0
  • 0
  • 23h ago

Overview

  • Zammad GmbH
  • Zammad

30 Sep 2026
Published
03 Oct 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
1.40%

Description

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

Statistics

  • 2 Posts

Last activity: 17 hours ago

Fediverse

Profile picture fallback
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw, CVE-2026-102489, is a session hijacking vulnerability in Zammad that can lead to remote code execution as the […]
U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
  • 0
  • 0
  • 0
  • 22h ago

Bluesky

Profile picture fallback
~Cisa~ CISA reports active exploitation of Zammad session fixation and privilege management flaws; prioritize remediation. - IOCs: CVE-2026-102489, CVE-2026-102490 - #CVE-2026-102489 #CVE-2026-102490 #ThreatIntel
  • 0
  • 0
  • 0
  • 17h ago
Showing 1 to 10 of 53 CVEs