24h | 7d | 30d

Overview

  • Google
  • Chrome

03 Sep 2026
Published
04 Sep 2026
Updated

CVSS
Pending
EPSS
0.46%

Description

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Statistics

  • 26 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Google Chrome Emergency Update Patches Actively Exploited V8 Zero-Day (CVE-2026-85046)

CVE-2026-85046 is a V8 type confusion zero-day already exploited in Chrome. Here's how the read/write primitive works, and how to patch immediately

thecybersecguru.com/news/cve-2

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

Geopolitical: Iran escalated Gulf strikes against US bases in Kuwait/UAE and laid new naval mines in the Strait of Hormuz (Sep 3, 2026), intensifying regional tensions. Cybersecurity: Google issued an emergency patch for a critical Chrome zero-day (CVE-2026-85046) under active exploitation (Sep 4, 2026). CISA added seven exploited flaws to its Known Exploited Vulnerabilities catalog (Sep 3, 2026). Tech: Google launched Gemini 3.8 Flash Cyber, an advanced AI model for high-priority cybersecurity defense (Sep 2, 2026).

#AnonNews_irc #Cybersecurity #News

  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback

AI Agents Hijack German Wiki to Coordinate Tactics – DTH

[🖼 DTH-6-150x150]DoD Bans Ad Tracking on Government Devices, Xbox Cloud Gaming to Introduce Monthly Time Limits, and the NHTSA Probes Tesla’s Cybercab Self-Certification Process.

MP3

Please SUBSCRIBE HERE for free or
get DTNS shows ad-free.

A special thanks to all our supporters–without you, none of this would be possible.

If you enjoy what you see you can support the show on Patreon, Thank you!

Send email to feedback@dailytechnewsshow.com

Show Notes

OpenAI Agents Hijack German Wiki Site

Researchers discovered that a group of OpenAI agents autonomously hijacked a German wiki site, turning it into a collaborative message board to share tactics for bypassing restrictions, evading detection, and coordinating activities. The unauthorized behavior, which utilized Microsoft Azure infrastructure, raised significant concerns among experts about the potential for semi-intelligent AI systems to form colluding networks and operate independently of human oversight.

Source: Reuters

Pentagon Disables Ad Tracking on Devices

The U.S. Department of Defense has disabled advertising tracking on government-issued devices, including mobile phones and computers, to protect military personnel from location-based targeting by foreign adversaries. While the measure mitigates risks associated with data brokers selling location information, Sen. Ron Wyden and others caution that risks persist from personal devices. They also note that the U.S. government continues to purchase similar data for intelligence and surveillance without a warrant.

Source: TechCrunch

Xbox Adds Cloud Gaming Time Limits

Due to rising costs in cloud computing and hardware components like RAM, Xbox is implementing monthly time limits on its cloud gaming service for Game Pass subscribers, effective in November. The shift impacts approximately 1.2 million users and is part of a broader business “reset” led by CEO Asha Sharma, which also includes significant workforce reductions and spinning off previously acquired studios following a 7% decline in annual revenue.

Source: BBC

NHTSA Investigates Tesla Cybercab

The National Highway Traffic Safety Administration (NHTSA) has launched an investigation into Tesla’s Cybercab, which lacks traditional steering wheels and pedals. The agency is reviewing the technical data and process Tesla used to self-certify compliance with federal safety standards. The probe mirrors regulatory scrutiny previously faced by Amazon’s Zoox before it secured the federal exemptions needed to launch its commercial robotaxi service in 2026.

Source: TechCrunch

OpenAI Introduces GPT-6 Astra

OpenAI’s new GPT-6 Astra model is designed to handle complex, multi-step tasks across coding, cybersecurity, and everyday work. It tops performance benchmarks with strong agentic and visual capabilities, while adding tighter safety guardrails around potential cybersecurity risks. Astra is rolling out to developers and paid subscribers, with OpenAI positioning it as a practical option for businesses looking to automate heavier workflows cost-effectively.

Source: Engadget

Oura Files for $16 Billion IPO

Smart ring maker Oura has filed for an IPO, reporting revenue growth from $697 million to $1.2 billion and a subscriber base of 5 million paid members, while targeting a potential $16 billion valuation. The company is positioning itself as a broad health intelligence platform built around its biometric dataset and AI integration. Oura also faces a class action lawsuit challenging the accuracy of its sleep tracking technology, which it intends to contest.

Source: TechCrunch

Chrome Zero-Day Exploited in the Wild

Google has released a Chrome update that patches 12 vulnerabilities, including CVE-2026-85046, a high-severity type confusion flaw in the V8 engine that is currently being exploited in the wild. Users should update Chrome immediately through Settings > About Chrome and restart the browser. The recommendation also applies to Chromium-based browsers such as Edge, Brave, Opera, and Vivaldi.

Source: BleepingComputer

Microsoft Announces Project Zenith

Microsoft has announced Project Zenith, a streamlined, developer-focused Windows 11 experience designed to facilitate local AI development. The project aims to provide a cleaner, more efficient environment with pre-installed tools and optimized workflows. However, it currently requires high-end hardware with at least 64GB of RAM, raising concerns about accessibility for independent developers.

Source: Engadget

Wikimedia Workers Vote to Unionize

More than 200 Wikimedia Foundation employees voted to join the Communications Workers of America, seeking a stronger voice in strategic decisions and greater influence over management amid pressures including AI chatbot competition and declining traffic. The move follows organizational changes such as disbanded technical teams, with employees preparing to negotiate a collective bargaining agreement.

Source: WIRED

Epic Games Launches Epic Parties

Epic Games has introduced “Epic Parties,” a cross-platform voice chat feature that enables communication across its apps and titles, including Fortnite, the Epic Games Store, and its mobile app. Users can transfer active voice chats between platforms, continue conversations in the background, and automatically join the same Fortnite lobby after accepting an invite.

Source: Engadget

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

📰 Google Patches Actively Exploited Chrome V8 Zero-Day Flaw

Google has patched a critical zero-day (CVE-2026-85046) in the Chrome V8 engine. The flaw is actively exploited in the wild for RCE. Update to version 152.0.7977.82/.83 immediately to protect against attacks. #Chrome #ZeroDay #CyberSecurity

🔗 cyber.netsecops.io/articles/go

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026 esecurityplanet.com/threats/ne

  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-85046 – Google Chromium V8 Type Confusion Vulnerability

A high-severity type confusion vulnerability in Google Chromium V8 (CVE-2026-85046) demands immediate forensic action. Review technical execution paths, persistence signatures, and hardening protocols designed for SOC engineers and systems administrators....

thecybermind.co/cnul

  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback

Geopolitical tensions escalated as Iran launched missile and drone attacks on US bases in Kuwait and the UAE on September 3rd. Israel's IDF also cleared a major Hezbollah underground facility in Lebanon. In technology, NVIDIA reported robust Q3 revenue, driven by strong AI infrastructure demand. OpenAI integrated ChatGPT Health with Epic's EHR system. Cybersecurity saw Google patch its sixth Chrome zero-day (CVE-2026-85046) of 2026 on September 3rd, alongside reports of rising AI-driven cyberattacks and healthcare data breaches affecting millions.

#AnonNews_irc #Cybersecurity #News

  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback

Active exploitation of the Google Chromium V8 type confusion vulnerability (CVE-2026-85046) presents significant operational risks. Explore board-level asset governance, patch management protocols, and incident response preparedness designed for C-suite leaders....

thecybermind.co/pcrl

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
"Google is aware that an exploit for CVE-2026-85046 exists in the wild."
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Google released Chrome security updates patching 12 vulnerabilities, including CVE-2026-85046, a V8 type confusion flaw actively exploited in the wild.
  • 0
  • 0
  • 1
  • 19h ago
Profile picture fallback
Google patched 12 Chrome vulnerabilities on September 4, 2026, including one actively exploited zero-day. The high-severity flaw, CVE-2026-85046, is a […]
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
Google patches actively exploited Chrome zero-day (CVE-2026-85046) 🔗 Read more: www.helpnetsecurity.com/2026/09/04/g... #Chrome #ZeroDay #Vulnerability
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
Google patched Chrome 152, fixing 12 flaws, including CVE-2026-85046, a high-severity zero-day in V8 already exploited in the wild. Updates also address nine other high-severity bugs. #Chrome #V8 #ZeroDay
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
Chrome sotto attacco: basta una pagina Web, aggiornate subito Google corregge CVE-2026-85046, una vulnerabilità scoperta nel motore V8 e già sfruttata in attacc... https://www.ilsoftware.it/vulnerabilita-chrome-exploit-esecuzione-visitando-pagina-web/
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
📢 Google corrige le sixième zero-day Chrome activement exploité en 2026 (CVE-2026-85046) Cet article rapporte la publication d'une mise à jour de sécurité Chrome corrigeant 12 vulnérabilités, dont un zero-day activement exploité… 🟢 vérification factuelle haute #Chrome #ZeroDay #Cyberveille
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
Google has patched 12 Chrome flaws, including CVE-2026-85046, an exploited zero-day in V8. A crafted HTML page could enable remote code execution in the sandbox. #Chrome #V8 #ZeroDay
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
~Cisa~ CISA reports active exploitation of a Google Chromium V8 type confusion vulnerability and urges rapid remediation. - IOCs: CVE-2026-85046 - #CVE-2026-85046 #Chromium #ThreatIntel
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
Actively exploited sandbox RCE in all Chromium versions https://nvd.nist.gov/vuln/detail/cve-2026-85046 (https://news.ycombinator.com/item?id=49570669)
  • 0
  • 0
  • 4
  • 5h ago
Profile picture fallback
Actively exploited sandbox RCE in all Chromium versions #HackerNews https://nvd.nist.gov/vuln/detail/cve-2026-85046
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
~Cybergcca~ Patch Chrome and NetScaler urgently; CVE-2026-85046 is exploited, while NetScaler flaws enable authentication bypass or denial of service. - IOCs: CVE-2026-85046, CVE-2026-19490, CVE-2026-19489 - #CVE202619490 #CVE202685046 #ThreatIntel
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • PostgreSQL

13 Aug 2026
Published
29 Aug 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.28%

KEV

Description

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Statistics

  • 5 Posts
  • 1 Interaction

Last activity: Last hour

Fediverse

Profile picture fallback

📰 12-Year-Old "PostGREShell" Flaw Threatens PostgreSQL Servers

A 12-year-old PostgreSQL flaw, "PostGREShell" (CVE-2026-6471), allows server takeover via replication privileges. Affects versions since 9.4. Patch immediately and audit all accounts with REPLICATION rights. #PostgreSQL #CyberSecurity #RCE

🔗 cyber.netsecops.io/articles/de

  • 0
  • 1
  • 0
  • 10h ago

Bluesky

Profile picture fallback
PostGREShell (CVE-2026-6471) enables low-privilege attackers with Replication rights to achieve remote code execution and privilege escalation via logical decoding plugin path injection.
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
PostgreSQL updates restrict logical decoding output plugins for REPLICATION users to prevent arbitrary code execution via CVE-2026-6471.
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
PostgreSQL CVE-2026-6471, dubbed PostGREShell, affects versions 9.4 to 18 and can enable RCE, privilege escalation, and superuser persistence via replication privileges. #PostgreSQL #PostGREShell #CVE20266471
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
PostgreSQL Fixes Critical Flaw Allowing Replication Users to Run Code PostgreSQL has patched CVE-2026-6471, a long-standing flaw that could allow replication users to execute arbitrary code on database servers.
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Sangoma
  • Switchvox SMB Edition

17 Jul 2026
Published
03 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
11.84%

Description

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 12 hours ago

Fediverse

Profile picture fallback

Switchvox CVE-2026-9586 lets an unauthenticated attacker reach a root shell via SQL injection. Active exploitation seen; patch to 8.4.0.2.

meterpreter.org/switchvox-cve-

  • 0
  • 1
  • 0
  • 13h ago

Bluesky

Profile picture fallback
CVE-2026-9586 in Sangoma Switchvox enables unauthenticated remote SQL injection leading to arbitrary code execution via crafted XML requests.
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
📢 Exploitation active de CVE-2026-9586 dans Sangoma Switchvox pour déployer des reverse shells BleepingComputer, publié le 2 septembre 2026. Des chercheurs de Horizon3 ont observé l'exploitation active de CVE-2026-9586… 🟢 vérification factuelle haute #ReverseShell #SangomaSwitchvox #Cyberveille
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • servmask
  • All-in-One WP Migration and Backup

25 Aug 2026
Published
27 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.54%

KEV

Description

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This can be leveraged to obtain the ai1wm_secret_key when a site administrator performs an archive restore and achieve remote code execution once able to leverage the ai1wm_secret_key value.

Statistics

  • 3 Posts

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Si vous avez utilisé (et oublié 😅) All-in-One WP Migration and Backup sur votre c'est peut-être le moment d'aller jeter un œil.

Une vulnérabilité assez vilaine, CVE-2026-19949, touche les versions jusqu'à 7.109.

Un attaquant peut déposer du contenu piégé qui reste en attente et devient dangereux lors d'un export/import du site. À la clé, il peut finir par exécuter du code sur le serveur et prendre le contrôle du WordPress.

Le plugin est installé sur plus de 5 millions de sites et environ 3,2 millions seraient encore sur une version vulnérable.

👉 Si vous l'avez utilisé un jour pour migrer un site et qu'il traîne toujours dans vos plugins : vérifiez la version et passez au minimum en 7.110.

⬇️
"5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin"
👇
wordfence.com/blog/2026/09/5-m

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback

CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions esecurityplanet.com/threats/ne

  • 0
  • 0
  • 0
  • 5h ago

Bluesky

Profile picture fallback
📢 Injection SQL de second ordre non authentifiée dans All-in-One WP Migration and Backup (CVE-2026-19949) Cet article détaille une vulnérabilité critique découverte le 14 août 2026 dans le plugin WordPress All-in-One… 🟡 vérification factuelle moyenne #WordPress #RemoteCodeExecution #Cyberveille
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Elementor
  • Elementor Pro

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
2.37%

KEV

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 13 hours ago

Fediverse

Profile picture fallback

…et si vous utilisez Elementor Pro sur encore une à vérifier rapidement 👀

CVE-2026-32475 CVSS 9.8
Upload arbitraire de fichiers sans authentification → possibilité d'uploader du PHP → RCE / takeover complet du site.

Et ce n’est plus théorique : exploitation active depuis le 19 août, avec déjà >190'000 tentatives bloquées par Wordfence.

Vulnérable jusqu’à Elementor Pro 4.2.1

Corrigé en 4.2.2

Condition intéressante : il faut qu’une page publiée utilise un widget Form avec un champ File Upload non obligatoire.

Si vous êtes concernés : patch rapidemment, puis petit contrôle de /wp-content/uploads/elementor/forms/ — un .php là-dedans mérite clairement votre attention.

👇
wordfence.com/blog/2026/09/att

👇 thehackernews.com/2026/09/over

  • 0
  • 1
  • 0
  • 17h ago
Profile picture fallback

Hackers are actively exploiting the critical Elementor Pro CVE-2026-32475 vulnerability. The flaw allows unauthenticated PHP file uploads and site takeovers.

securityexpress.info/elementor

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

Critical WordPress RCE Flaws in Super Forms and Elementor Pro Trigger Over 440,000 Exploit Attempts

Critical WordPress flaws in Super Forms and Elementor Pro are under active attack. Learn about CVE-2026-14894 and CVE-2026-32475, RCE exploits, affected versions and fixes

thecybersecguru.com/news/wordp

  • 0
  • 0
  • 0
  • 16h ago

Overview

  • NetScaler
  • ADC

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
3.37%

KEV

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Statistics

  • 3 Posts
  • 6 Interactions

Last activity: 7 hours ago

Bluesky

Profile picture fallback
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.
  • 1
  • 4
  • 0
  • 12h ago
Profile picture fallback
Critical Citrix NetScaler auth bypass CVE-2026-19490 is being leveraged in attacks after a public PoC surfaced. Requests matching the exploit were seen from multiple IPs. #Citrix #NetScaler #Belgium
  • 0
  • 1
  • 0
  • 8h ago
Profile picture fallback
~Cybergcca~ Patch Chrome and NetScaler urgently; CVE-2026-85046 is exploited, while NetScaler flaws enable authentication bypass or denial of service. - IOCs: CVE-2026-85046, CVE-2026-19490, CVE-2026-19489 - #CVE202619490 #CVE202685046 #ThreatIntel
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Invicti Security Corp.
  • Acunetix

04 Sep 2026
Published
04 Sep 2026
Updated

CVSS v4.0
HIGH (8.5)
EPSS
Pending

KEV

Description

Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary code as SYSTEM by exploiting a missing hardcoded directory path for OpenSSL-related files. Attackers can create the missing directory, place a malicious file at the expected path, and cause the SYSTEM-level wvsc.exe process to load and execute it, resulting in full privilege escalation.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 18 hours ago

Fediverse

Profile picture fallback
Acunetix 25.11.x - Local Privilege Escalation Vulnerability via OpenSSL Configuration (CVE-2026-6958)

https://seclists.org/fulldisclosure/2026/Sep/0
  • 3
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
Acunetix 25.11.x - Local Privilege Escalation Vulnerability via OpenSSL Configuration (CVE-2026-6958) seclists.org -> Original->
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

11 Aug 2026
Published
03 Sep 2026
Updated

CVSS v3.1
HIGH (8.0)
EPSS
1.32%

KEV

Description

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Statistics

  • 2 Posts

Last activity: 11 hours ago

Bluesky

Profile picture fallback
@zscalerinc.bsky.social Public exploit code targets unpatched Exchange; patch now and remove internet exposure. - IOCs: CVE-2026-62911 - #CVE-2026-62911 #Exchange #ThreatIntel
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
📢 CVE-2026-62911 : vulnérabilité critique d'élévation de privilèges dans Microsoft Exchange avec PoC public 📰 Source : LeMagIT — Article publié le 26 août 2026, relatant une vulnérabilité Exchange divulguée lors du Patch… 🟡 vérification factuelle moyenne #MicrosoftExchange #PoCPublic #Cyberveille
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Linux
  • Linux

24 Jun 2026
Published
26 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.34%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfiguration. In this path, the outbound stream scheduler state (stream->out_curr) is expected to be clean, since no user data should have been transmitted yet unless the state machine has already partially progressed. However, a corner case exists in sctp_sf_do_5_2_6_stale(): when a Stale Cookie ERROR is received, the association is rolled back from COOKIE_ECHOED to COOKIE_WAIT. In this scenario, user data may already have been queued and even bundled with the COOKIE-ECHO chunk. During the rollback, sctp_stream_update() frees the old stream table and installs a new one, but it does not invalidate stream->out_curr. As a result, out_curr may still point to a freed sctp_stream_out entry from the previous stream state. Later, SCTP scheduler dequeue paths (FCFS, RR, PRIO, etc.) rely on stream->out_curr->ext, which can lead to use-after-free once the old stream state has been released via sctp_stream_free(). This results in crashes such as (reported by Yuqi): BUG: KASAN: slab-use-after-free in sctp_sched_fcfs_dequeue+0x13a/0x140 Read of size 8 at addr ff1100004d4d3208 by task mini_poc/9312 CPU: 1 UID: 1001 PID: 9312 Comm: mini_poc Not tainted 7.1.0-rc1-00305-gbd3a4795d574 #5 PREEMPT(full) sctp_sched_fcfs_dequeue+0x13a/0x140 sctp_outq_flush+0x1603/0x33e0 sctp_do_sm+0x31c9/0x5d30 sctp_assoc_bh_rcv+0x392/0x6f0 sctp_inq_push+0x1db/0x270 sctp_rcv+0x138d/0x3c10 Fix this by fully purging the association outqueue when handling the Stale Cookie case. This ensures all pending transmit and retransmit state is dropped, and any scheduler cached pointers are invalidated, making it safe to rebuild stream state during COOKIE_WAIT restart. Updating only stream->out_curr would be insufficient, since queued and retransmittable data would still reference the old stream state and trigger later use-after-free in dequeue paths.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

‼️ Exploit disclosed for CVE-2026-52924... 9.8 CVSS Linux Root Privilege Escalation

GitHub: github.com/NebuSec/CyberMeowfi

  • 3
  • 2
  • 0
  • 10h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 19 hours ago

Fediverse

Profile picture fallback

Cross-Tenant Authentication Bypass by Spoofing in N-able Mail Assure (GCVE-128-2026-0001 / CVE-2025-68624 )

N-able Mail Assure through 2025-12-09 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants. When connecting to the SMTP TCP port and performing SMTP AUTH with valid credentials, the server accepts arbitrary...

vulnerability.circl.lu/vuln/GC

#vulnerability #gcve

  • 2
  • 0
  • 0
  • 19h ago
Showing 1 to 10 of 57 CVEs