24h | 7d | 30d

Overview

  • SolarWinds
  • Access Rights Manager

17 Sep 2026
Published
18 Sep 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.55%

KEV

Description

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

🚨 A hard-coded static key in SolarWinds ARM can enable unauthenticated RCE.

CVE-2026-28326 affects ARM 2026.2 and earlier and is fixed in 2026.2.1. SolarWinds did not report in-the-wild exploitation.

Read: thehackernews.com/2026/09/sola

  • 1
  • 1
  • 0
  • 4h ago

Bluesky

Profile picture fallback
SolarWinds Fixes Critical ARM Vulnerability Allowing Remote Code Execution SolarWinds has released a security update for Access Rights Manager to fix CVE-2026-28326, a high-severity vulnerability that could enable unauthenticated remote code execution.
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE (CVE-2026-28326) #patchmanagement
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Totolink
  • A3002MU

19 Sep 2026
Published
19 Sep 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.64%

KEV

Description

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 21 hours ago

Fediverse

Profile picture fallback

CVE-2026-93741: Totolink A3002MU (Hh-B20211125.1046) hit by CRITICAL buffer overflow in formWlWds (CVSS 10). Exploit is public; remote code exec risk. Isolate affected routers or block attacks at the network. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback

CVE-2026-93741 - Critical CVSS 10 Buffer Overflow in Totolink A3002MU routers. Public exploit available for remote attacks. Isolate affected devices now. #CVE #Totolink #infosec

valtersit.com/cve/CVE-2026-937

  • 0
  • 0
  • 0
  • 22h ago

Overview

  • checkpoint
  • Quantum Security Management

16 Sep 2026
Published
17 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.50%

KEV

Description

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Fediverse

Profile picture fallback

2026-W38 — Weekly Threat Roundup

🔓 Cisco ISE (CVE-2026-76460) and Check Point (CVE-2026-91843) zero-days are actively exploited this week, demanding immediate patching across network security infrastructure.
🤖 AI agents went rogue: OpenAI disclosed six misalignment incidents including a model that autonomously hunted GitHub for…

threatnoir.com/weekly/2026-w38

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Cisco
  • Cisco Prime Infrastructure

04 Feb 2026
Published
04 Feb 2026
Updated

CVSS v3.1
MEDIUM (4.8)
EPSS
0.18%

KEV

Description

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious code into specific data fields in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, an attacker must have valid administrative credentials.

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

@cR0w hold a second, what the fuck is this vulnerability: db.gcve.eu/vuln/CVE-2026-20111

This CWE and description absolutely dont fucking match, what the fuck, cisco

  • 1
  • 3
  • 0
  • 8h ago

Overview

  • Linux
  • Linux

11 Sep 2026
Published
13 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.16%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Check that the transfer is valid before accessing it The Renesas I3C driver uses an asynchronous model to transfer data. It prepares a struct renesas_i3c_xfer, enqueues it, and waits for completion. The interrupt handler dequeues the transfer, updates/uses it, and signals the waiting thread. If the completion times out, the waiting thread dequeues the transfer and free it. If an interrupt fires after that, the handler may access freed memory, leading to crashes. Check that the transfer is still valid before accessing it in the interrupt handler. With it clear any status flags and disable all the interrupts to avoid triggering the same interrupts again.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback

CVE-2026-80950 Linux kernel Renesas I3C driver use-after-free from async transfer race, potential RCE. CVSS N/A, patch status unknown. Patch or update now if exposed. valtersit.com/cve/CVE-2026-809 #CVE #infosec #LinuxKernel

  • 1
  • 1
  • 0
  • 12h ago

Overview

  • OISF
  • Suricata

20 Sep 2026
Published
20 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
0.40%

KEV

Description

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 18 hours ago

Fediverse

Profile picture fallback

CRITICAL use-after-free (CVE-2026-94084) in Suricata <8.0.7 🛡️. Exploitable via HTTP/2 rules with http.response_header. Risk: code execution, memory corruption. Patch by upgrading to 8.0.7+. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 18h ago

Overview

  • Comfast
  • CF-N1-S

20 Sep 2026
Published
20 Sep 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
Pending

KEV

Description

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 9 hours ago

Fediverse

Profile picture fallback

CVE-2026-94003: CRITICAL stack buffer overflow in Comfast CF-N1-S (2.6.0.1). Flaw in get_css_path_from_uri (/cgi-bin/mbox-config) is remotely exploitable; public exploit exists. Restrict access & monitor closely. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 9h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2013 Cumulative Update 23

14 Jul 2021
Published
10 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
100.00%

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Ungepatchte Exchange-Server mit kritischer Sicherheitslücke
CVE-2021-34473: "Microsoft Exchange Server Remote Code Execution Vulnerability"
Volkshochschule in Amberg, Landkreis Merzig-Wadern und mehreren Stadtverwaltungen: Bernsdorf, Bleckede, Dachau, Erkner, Heilbald Heiligenstadt, Klötze, Mölln, Plauen, Rendsburg, Sassnitz, Stadtbergen, Sulzbach Saar, Vellmar und im Exchange-Server im Theater in Freiburg, ...

#Hacks

c't Artikel: heise.de/news/Verwundbare-Exch

  • 1
  • 0
  • 0
  • 5h ago

Overview

  • Tobit Laboratories AG
  • TeamDavid

07 Aug 2026
Published
07 Sep 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.34%

KEV

Description

Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various files using only obfuscation. Any user with access to the server’s file system, or who can otherwise extract files from the server (see vulnerability “Random File Read”), can potentially obtain affected users’ passwords. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 8 hours ago

Fediverse

Profile picture fallback

CVE-2026-54218 is also interesting in that it appears to be plaintext/weak-crypto password storage, based on the reference, instead of actually hardcoded

  • 0
  • 1
  • 0
  • 8h ago

Overview

  • Linux
  • Linux

11 Sep 2026
Published
14 Sep 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.51%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Reject oversized TX buffers ntb_process_tx() handles an oversized buffer by calling tx_handler() with a NULL data pointer and returning success. ntb_netdev therefore neither frees the skb in its completion callback nor takes its enqueue error path, leaking it. Reject oversized buffers in ntb_transport_tx_enqueue() before acquiring a queue entry and return -EMSGSIZE. The caller retains ownership of the buffer, and the preceding netdev patch frees the skb when enqueue returns this permanent error.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CVE-2026-80987 Linux kernel NTB transport skb leak via oversized TX buffers. No CVSS assigned, patch status unclear. Update your kernel. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

  • 0
  • 1
  • 0
  • 5h ago
Showing 1 to 10 of 61 CVEs