24h | 7d | 30d

Overview

  • Oracle Corporation
  • PeopleSoft Enterprise PeopleTools

11 Jun 2026
Published
04 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
9.44%

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Statistics

  • 7 Posts
  • 6 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

🚨 ShinyHunters resumes mass exploitation of critical Oracle PeopleSoft flaw using simple WAF bypass.

Mandiant and Google Threat Intelligence Group have identified renewed mass exploitation of CVE-2026-35273 by UNC6240, also known as ShinyHunters.
⠀
The critical vulnerability allows unauthenticated remote code execution in Oracle PeopleSoft PeopleTools and carries a CVSS score of 9.8.

Oracle released an emergency patch on June 10.
⠀
The new campaign targets organizations that attempted to mitigate the flaw using web application firewall rules but did not install the patch.

ShinyHunters bypassed rules blocking the vulnerable /PSEMHUB/ endpoint by encoding a single character and sending requests to /%50SEMHUB/.
⠀
Google says web shells were deployed on dozens of systems worldwide across:

• Higher education
• Technology
• IT services
• Healthcare
• Agriculture
• Transportation
• Government
⠀
The actors deployed web shells, the SIDEEYE backdoor, Neo-reGeorg tunneling tools and MeshAgent for persistent remote access.

Around one-quarter of the observed commands executed with root or SYSTEM privileges.
⠀
Organizations running PeopleSoft should patch immediately, disable or remove the Environment Management Hub where possible and investigate encoded variants of /PSEMHUB/ in access logs.

WAF rules alone are not sufficient.

  • 1
  • 2
  • 0
  • 21h ago

Bluesky

Profile picture fallback
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
  • 0
  • 3
  • 0
  • 2h ago
Profile picture fallback
Renewed exploitation of Oracle PeopleSoft CVE-2026-35273 enables unauthenticated remote code execution, with attackers bypassing WAF protections and deploying web shells across global sectors.
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
@mandiant.com UNC6240 bypasses WAFs to exploit PeopleSoft and deploy web shells, MeshAgent, and SIDEEYE. - IOCs: 5[.]199[.]162[.]157, 162[.]219[.]30[.]165, winmanage-me[.]network - #CVE202635273 #ShinyHunters #ThreatIntel
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
ShinyHunters resumed mass exploitation of Oracle PeopleSoft CVE-2026-35273, bypassing WAF rules with a percent-encoded path and deploying web shells, Neo-ReGeorg tunnels, and MeshAgent across multiple sectors. #ShinyHunters #OraclePeopleSoft #UNC6240
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
Google warns of renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft by ShinyHunters-linked group UNC6240 Attackers bypass WAF rules using […]
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
ShinyHunters is using URL encoding to bypass WAF rules and keep exploiting Oracle PeopleSoft CVE-2026-35273, deploying web shells and backdoors against education, healthcare, and government targets. #ShinyHunters #OraclePeopleSoft #UNC6240
  • 0
  • 0
  • 0
  • Last hour

Overview

  • WordPress
  • WordPress

22 Sep 2026
Published
26 Sep 2026
Updated

CVSS
Pending
EPSS
18.17%

Description

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 11 hours ago

Fediverse

Profile picture fallback

WordPress 7.1.1に更新したばかりでもCVE-2026-87902への対応が必要です。
7.1.1で修正されたClick2Shellとは別のWordPressコアの脆弱性です。
未ログインの第三者が細工したpagenameを送ることで条件次第でテーマ外のPHPファイルをテンプレートとして読み込ませられます。
コード実行にはテーマの構造や悪用できるPHPファイル、PHP設定など追加の条件があります。
「ダッシュボード」→「更新」で7.1系は7.1.2、旧系列は対応する修正版が適用済みか確認を。
公開当日から攻撃リクエストが観測されています。更新前の影響が気になる場合はアクセスログや不審なPHPファイルも調べてください。
chunlog.jp/wordpress-7-1-2-cve
#WordPress #PHP #セキュリティ

  • 0
  • 1
  • 0
  • 11h ago
Profile picture fallback
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a WordPress Core flaw, tracked as CVE-2026-87902 (CVSS score of 9.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-87902 allows an unauthenticated attacker to make the get_page_template() function include a readable local […]
U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • OpenClaw
  • OpenClaw

26 Sep 2026
Published
26 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.0)
EPSS
0.17%

KEV

Description

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by iOS system trust can serve a replacement Control UI page; opening the Terminal or a session Dashboard then allows that page to read the injected Gateway token or password. The stolen credential can grant operator access, including reading sensitive Gateway state and invoking host-capable tools. This issue is fixed in 2026.8.11.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 15 hours ago

Fediverse

Profile picture fallback

CVE-2026-100551: OpenClaw for iOS (>=2026.7.1, <2026.8.11) has a CRITICAL vuln in Control UI WebViews — TLS pins not enforced. Attackers can steal Gateway creds if they can redirect traffic. Patch to 2026.8.11 ASAP! radar.offseq.com/threat/opencl

  • 1
  • 0
  • 0
  • 15h ago

Overview

  • Wikimedia Foundation
  • Mediawiki - ExternalData Extension

25 Sep 2026
Published
25 Sep 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.95%

KEV

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 12 hours ago

Fediverse

Profile picture fallback

Mediawiki ExternalData Extension <3.7 has a CRITICAL OS Command Injection vuln (CVE-2026-100382). Unauthenticated attackers could run arbitrary OS commands. No exploits yet. Restrict access, monitor activity. radar.offseq.com/threat/improp

  • 0
  • 1
  • 0
  • 12h ago
Profile picture fallback

CVE-2026-100382 (CRITICAL, CVSS 10): Wikimedia Mediawiki ExternalData Extension (<3.7) suffers OS Command Injection. Remote, unauthenticated code execution is possible. Restrict access & monitor systems. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 21h ago

Overview

  • SolarWinds
  • Access Rights Manager

17 Sep 2026
Published
18 Sep 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.69%

KEV

Description

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

Statistics

  • 2 Posts

Last activity: 1 hour ago

Bluesky

Profile picture fallback
Master Key Included: Detecting SolarWinds ARM CVE-2026-28326
  • 0
  • 0
  • 1
  • 1h ago

Overview

  • IBM
  • Guardium Data Protection

18 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
1.32%

KEV

Description

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges.

Statistics

  • 1 Post

Last activity: 20 hours ago

Fediverse

Profile picture fallback

CVE-2026-81669 IBM Guardium Data Protection 12.2 command injection via create csr wildcard CLI, alias input. Auth privileged CLI user gets root RCE. CVSS 7.2, unpatched. Restrict CLI access now. valtersit.com/cve/CVE-2026-816 #CVE #infosec #IBM

  • 0
  • 0
  • 0
  • 20h ago

Overview

  • openclaw
  • msteams

26 Sep 2026
Published
26 Sep 2026
Updated

CVSS v4.0
HIGH (7.1)
EPSS
0.21%

KEV

Description

OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a steered agent with access to a channel read action can therefore retrieve content or metadata from channels or rooms excluded by the operator's read policy; the practical impact depends on the permissions held by the connected bot account. The issue is fixed in 2026.8.1.

Statistics

  • 1 Post

Last activity: 18 hours ago

Fediverse

Profile picture fallback

CVE-2026-100582 (HIGH): openclaw msteams <2026.8.1 has a missing authorization flaw — low-trust users can bypass channel read allowlists and access restricted data. Patch to 2026.8.1 ASAP. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 18h ago

Overview

  • IBM
  • MQ for HPE NonStop

18 Sep 2026
Published
22 Sep 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.44%

KEV

Description

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.

Statistics

  • 1 Post

Last activity: 6 hours ago

Fediverse

Profile picture fallback

CVE-2026-11727: IBM MQ C client DoS, possible RCE, via unvalidated queue manager responses. CVSS 8.1, unpatched. Apply mitigations now. valtersit.com/cve/CVE-2026-117 #CVE #infosec #IBM

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • IBM
  • Guardium Data Protection

18 Sep 2026
Published
19 Sep 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.63%

KEV

Description

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CVE-2026-84108: IBM Guardium Data Protection 12.2 RCE via improper input neutralization. CVSS 8.1, unpatched. Patch now. valtersit.com/cve/CVE-2026-841 #CVE #infosec #IBM

  • 0
  • 0
  • 0
  • 5h ago

Overview

  • OISF
  • suricata

18 Sep 2026
Published
21 Sep 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.63%

KEV

Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame contents instead of clearing the internal buffer. Multiple DATA frames with the EndOfStream flag set can grow the buffer to its 65 KiB limit while causing all prior contents to be processed again, producing quadratic CPU complexity, degraded packet processing, loss of monitoring visibility, or denial of service. This issue is fixed in version 8.0.6.

Statistics

  • 1 Post

Last activity: 8 hours ago

Fediverse

Profile picture fallback

CVE-2026-71418: Suricata DoS, CVSS 7.5. DNS-over-HTTP/2 buffer flaw causes quadratic CPU use, degrading packet processing. Unpatched as of now - update immediately. valtersit.com/cve/CVE-2026-714 #CVE #Suricata #infosec

  • 0
  • 0
  • 0
  • 8h ago
Showing 1 to 10 of 39 CVEs