Overview
- FlowiseAI
- Flowise
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
The Spread Operator Is an Allowlist With Nothing In It: CVE-2026-69258 in Flowise | HackerNoon
https://hackernoon.com/the-spread-operator-is-an-allowlist-with-nothing-in-it-cve-2026-69258-in-flowise?utm_source=flipboard&utm_medium=activitypub
Posted into Hacker Noon @hacker-noon-HackerNoon
CVE-2026-69258: two ungated spread operators let an unauthenticated caller write into the flow execution context of any public Flowise chatflow. https://hackernoon.com/the-spread-operator-is-an-allowlist-with-nothing-in-it-cve-2026-69258-in-flowise #flowisevulnerability
Overview
Description
Statistics
- 2 Posts
Fediverse
CISA impone un parche urgente por un fallo crítico en Citrix NetScaler con explotación activa
CISA ha metido CVE-2026-8452 en su catálogo Known Exploited Vulnerabilities y obliga a las agencias federales de EEUU a parchear Citrix NetScaler antes del 29 de agosto de 2026. La falla, que empezó describiéndose como un problema de denegación de servicio, ya se está aprovechando para lograr ejecución remota de código...
Description
Statistics
- 1 Post
- 13 Interactions
Overview
- Tenda
- HG10
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
https://www.cve.org/CVERecord?id=CVE-2026-82542
sev:CRIT 10.0 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Overview
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
CVE-2026-82461 - Auth bypass in pac4j-oidc. Unverified access tokens allow forging admin roles. CVSS 8.1. Update to v6.5.6 now. #CVE #infosec #cybersecurity
Overview
- TangibleWP
- MyHome Core
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
CVE-2026-15980 - Critical Auth Bypass in WordPress MyHome Core plugin (<= 4.4.5) allows unauthenticated admin account takeover. CVSS 9.8. Mitigate now. #CVE #WordPress #infosec
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Certighost: cuando un usuario de dominio puede acabar obteniendo un certificado de un Domain Controller (CVE-2026-54121)
Si durante los últimos años ha habido una tecnología de Active Directory que ha pasado de ser la gran olvidada a convertirse en uno de los objetivos favoritos de Red Teams y atacantes reales, esa es Active Directory Certificate Services (AD CS). Desde la publicación de Certified Pre-Owned...
https://www.hackplayers.com/2026/07/certighost-cuando-un-usuario-de-dominio.html
Overview
- Skyvern-AI
- skyvern
Description
Statistics
- 1 Post
- 1 Interaction
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-82635 - Path Traversal in Pake allows arbitrary file write via unsanitized download paths. CVSS 8.8. Update to 3.13.1 now. #CVE #infosec #cybersecurity