24h | 7d | 30d

Overview

  • Langflow
  • Langflow

23 Jan 2026
Published
26 Feb 2026
Updated

CVSS v3.0
CRITICAL (9.8)
EPSS
2.34%

KEV

Description

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-27322.

Statistics

  • 7 Posts
  • 5 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Cyberkriminelle nutzen aktiv eine ungepatchte RCE-Schwachstelle (CVE-2026-0768) im KI-Framework Langflow aus. Über den kritischen Fehler erlangen Angreifer unautorisierten Zugriff auf Systeme, um sensible API-Schlüssel, Tokens und Anmeldedaten von Plattformen wie OpenAI oder AWS abzugreifen. Anwender sollten die Software umgehend absichern.

#Langflow #AI #CyberSecurity #InfoSec #ITSecurity #TechNews

  • 1
  • 1
  • 0
  • 9h ago
Profile picture fallback

📰 Critical RCE Flaw in Langflow AI Platform Actively Exploited

Critical RCE flaw (CVE-2026-0768, 9.8 CVSS) in the Langflow AI platform is actively exploited. Unauthenticated attackers can get root access to steal credentials. Patch to version 1.4.3+ now! #Langflow #AI #CyberSecurity #RCE #CVE

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys.
  • 2
  • 1
  • 0
  • 9h ago
Profile picture fallback
Threat actors exploit CVE-2026-0768 in Langflow to execute arbitrary root code without authentication, targeting reconnaissance and credential harvesting.
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
Attackers are exploiting CVE-2026-0768 in Langflow for unauthenticated RCE, stealing environment variables and secret files to grab OpenAI and AWS keys from vulnerable AI apps. #Langflow #OpenAI #AWS
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
Хакеры начали использовать критическую уязвимость Langflow Отслеживаемый как CVE-2026-0768, дефект безопасности позволяет неаутентифицированным злоумышленникам удаленно выполнять произвольный код Python. Telegram ИИ Дайджест #ai #news
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
Hackers Start Exploiting Critical Langflow Vulnerability Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. Telegram AI Digest #ai #news
  • 0
  • 0
  • 0
  • Last hour

Overview

  • jfrog
  • artifactory

28 Aug 2026
Published
31 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.38%

KEV

Description

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Statistics

  • 6 Posts
  • 2 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

A critical Artifactory authentication bypass flaw (CVE-2026-82329) is exploited in the wild, letting attackers obtain administrative privileges.

securityonline.info/cve-2026-8

  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback

📰 Critical JFrog Artifactory Auth Bypass Flaw Under Active Exploit

Critical auth bypass flaw (CVE-2026-82329) in self-hosted JFrog Artifactory is actively exploited. Attackers can gain admin access, posing a severe software supply chain risk. Patch immediately! #JFrog #Artifactory #CyberSecurity #CVE

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
CVE-2026-82329 in JFrog Artifactory enables unauthenticated attackers to bypass authentication and obtain admin access under default settings.
  • 1
  • 0
  • 0
  • 17h ago
Profile picture fallback
Threat actors exploit CVE-2026-82329 in JFrog Artifactory to bypass authentication and obtain administrative privileges, enabling token generation and user enumeration.
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
JFrog Artifactoryの脆弱性 CVE-2026-82329、認証なしで管理者権限取得のおそれ 実悪用報告、Self-Hostedは更新を rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
CVE-2026-82329 が悪用されました: JFrog Artifactory 管理者の乗っ取り CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover #DailyCyberSecurity (Sep 1) securityonline.info/cve-2026-823...
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • PaperCut
  • PaperCut MF/NG

28 Aug 2026
Published
01 Sep 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.77%

Description

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Statistics

  • 7 Posts
  • 2 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

UmbrielAI revoluciona la ciberseguridad con IA avanzada para detección en tiempo real, mientras nuevos métodos autónomos superan barreras de autenticación en pruebas de seguridad. Se alerta sobre vulnerabilidad crítica en PaperCut, ola de ciberataques impulsados por IA en Latinoamérica, y se destacan herramientas clave como Entra ID y Cloudflare One para proteger infraestructuras. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 01/09/26 📆 |====

🚀 UMBRIELAI: INNOVACIÓN EN SEGURIDAD INFORMÁTICA Y MODELOS DE LENGUAJE AVANZADOS

UmbrielAI presenta una nueva era en investigación y desarrollo de modelos de lenguaje (LLM) aplicados a la ciberseguridad. Su enfoque combina IA avanzada con pipelines automatizados para detectar y mitigar amenazas en tiempo real, ampliando el potencial de defensa contra ataques sofisticados. Esta iniciativa promete transformar la forma en que las organizaciones protegen sus sistemas mediante inteligencia artificial. Descubre más sobre esta revolución en IA y seguridad 👉 djar.co/4VX9

🔐 NOAUTH, NO PROBLEM: AUTENTICACIÓN EN PRUEBAS DE SEGURIDAD

La autenticación comúnmente limita la capacidad para realizar pruebas de seguridad exhaustivas. Sin embargo, agentes autónomos han desarrollado métodos para navegar flujos complejos de autenticación, permitiendo descubrir vulnerabilidades críticas que pasan desapercibidas en pruebas convencionales. Este avance mejora significativamente la cobertura y efectividad en la detección de brechas de seguridad. Conoce cómo mejorar tus evaluaciones de seguridad aquí 👉 djar.co/4EMqG0

🛠 INVESTIGACIÓN EN BUGS Y EXPLOITS DESDE CALIFORNIA

Una reciente investigación focalizada en bugs, exploits y análisis profundos ha sido publicada desde California, aportando datos valiosos para la comunidad de seguridad informática. Esta investigación contribuye a la comprensión y mitigación de amenazas emergentes, facilitando la creación de soluciones más robustas. Explora los hallazgos y mantente actualizado con los últimos descubrimientos 👉 djar.co/daT3

⚠️ CVE-2026-81578: VULNERABILIDAD CRÍTICA EN PAPERCUT NG/MF

Se ha identificado una cadena de ejecución remota de código no autenticada en PaperCut NG/MF, clasificada con una gravedad CVSS de 9.4. Esta vulnerabilidad puede ser explotada para comprometer sistemas sin necesidad de autenticación previa, representando un riesgo alto para empresas que utilizan esta plataforma. Es fundamental aplicar los parches correspondientes y revisar la seguridad de estos sistemas cuanto antes. Consulta detalles técnicos y recomendaciones aquí 👉 djar.co/hHBsNx

🛡 ALERTA DE 116 EMPRESAS SOBRE OLA DE CIBERATAQUES POTENCIADOS POR IA

Un consorcio de 116 empresas líderes en inteligencia artificial ha emitido una advertencia sobre un inminente aumento de ciberataques impulsados por IA que afectarán a Ecuador y Latinoamérica. Recomiendan fortalecer las defensas cibernéticas mediante estrategias proactivas y capacitación especializada para anticipar estas amenazas avanzadas. Conoce cómo prepararte ante esta ola creciente de ataques inteligentes 👉 djar.co/th6tLa

🔑 ASEGURANDO LA ADMINISTRACIÓN DE ENTRA ID: PRIORIDAD TIER 0

La administración segura de Entra ID requiere identificar, proteger y manejar con rigor las identidades privilegiadas de nivel Tier 0. Aplicar las mejores prácticas en esta área es crucial para evitar accesos no autorizados que podrían comprometer toda la infraestructura. Este recurso ofrece una guía detallada para reforzar la seguridad en la gestión de identidades críticas. Aprende a proteger tu entorno con estas recomendaciones 👉 djar.co/TOl2

☁️ CLOUDFLARE ONE: PLATAFORMA SASE ÁGIL PARA SEGURIDAD Y CONECTIVIDAD

Cloudflare One se presenta como una plataforma SASE diseñada para proporcionar conectividad segura y protección integral a la fuerza laboral, agentes de IA e infraestructuras. Facilita la adopción segura de tecnologías IA y el acceso Zero Trust, permitiendo a las organizaciones operar con mayor agilidad y resistencia frente a amenazas cibernéticas modernas. Descubre cómo Cloudflare One transforma la seguridad empresarial 👉 djar.co/nTh7DR

  • 1
  • 1
  • 0
  • 16h ago
Profile picture fallback

Two vulnerabilities in PaperCut NG and MF print management software are now being used by attackers in data theft campaigns.
PaperCut software is used by millions of people across thousands of organizations.
The flaws are tracked as CVE-2026-81578 and CVE-2026-82078.

  • 0
  • 0
  • 1
  • 19h ago
Profile picture fallback

Frisch geschlossene Sicherheitslücken in PaperCut NG und MF (CVE-2026-81578 & CVE-2026-82078) dienen Angreifern aktuell aktiv als Einfallstor für massiven Datendiebstahl. Die Kombination aus Authentifizierungs-Bypasses und Remote Code Execution erlaubt vollständige Systemübernahmen im Netz exponierter Printserver. Administratoren müssen ausstehende Patches zwingend einspielen und den Zugriff sofort einschränken.

#PaperCut #Infosec #Vulnerability #CyberSecurity #DataTheft #SysAdmin

  • 0
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
PaperCutのゼロデイ 脆弱性、CISAがCVE-2026-81578/82078をKEV追加 Huntressが認証前RCEを再現 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
📢 Deux zero-days PaperCut NG/MF exploités activement : second patch d'urgence publié Deux CVE ont été officiellement attribuées : CVE-2026-81578 : Contournement d'authentification de haute sévérité permettant à un attaquant distant… 🟢 vérification factuelle haute #PaperCut #ZeroDay #Cyberveille
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
PaperCut NG/MF: Critical Authentication Bypass and RCE Chain CVE-2026-81578 & CVE-2026-82078 https://horizon3.ai/attack-research/vulnerabilities/cve-2026-81578-cve-2026-82078 https://flagthis.com/tldr/6834 ##RCE ##ZeroDay ##PaperCut ##AuthenticationBypass ##CyberSecurity
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

11 Aug 2026
Published
01 Sep 2026
Updated

CVSS v3.1
HIGH (8.0)
EPSS
1.25%

KEV

Description

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Statistics

  • 5 Posts
  • 9 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

A critical authentication bypass vulnerability (CVE-2026-62911) affects approximately 22,000 unpatched Microsoft Exchange servers running versions 2016, 2019, and SE. Attackers can hijack all user mailboxes on vulnerable systems. Exploit code is publicly available; active exploitation in the wild h…

threatnoir.com/focus

🤖 AI generated summary

  • 1
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
We are scanning & reporting daily on vulnerable Microsoft Exchange CVE-2026-62911 (Authentication Bypass by Capture-replay) instances in our Vulnerable Exchange reporting: www.shadowserver.org/what-we-do/n... At least 21899 IPs seen unpatched 2026-08-31, top US (6.2K) & Germany (5.1K)
  • 3
  • 5
  • 0
  • 17h ago
Profile picture fallback
PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE Attack Chain https://gbhackers.com/poc-released-for-microsoft-exchange-cve-2026-62911/
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Dashboard World Map view stats: dashboard.shadowserver.org/statistics/c... Dashboard Tree Map stats: dashboard.shadowserver.org/statistics/c... NVD entry: nvd.nist.gov/vuln/detail/... MS advisory: msrc.microsoft.com/update-guide... Daily IP data tagged 'cve-2026-62911'
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Exchange Serverの事前認証RCEの概念実証(PoC)であるCVE-2026-62911が公開されました CVE-2026-62911 Exchange Server Pre-Auth RCE PoC Released #DailyCyberSecurity (Sep 1) securityonline.info/cve-2026-629...
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Sauter
  • modu680-AS

01 Sep 2026
Published
01 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.40%

KEV

Description

A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this race condition to bypass intended security controls. This may result in the execution of unauthorized code.

Statistics

  • 3 Posts

Last activity: 9 hours ago

Fediverse

Profile picture fallback

🔒 New CSAF advisory published

VDE-2026-093
SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution
CVE-2026-78319

A vulnerability has been found in the firmware update process of SAUTER Building Controllers. The identified vulnerability could allow unauthorized code execution on affec…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: sauter.csaf-tp.certvde.com/.we

  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback

Public advisory details CVE-2026-78319, a critical SAUTER building controller vulnerability enabling unauthenticated remote code execution via a TOCTOU flaw.

securityonline.info/sauter-cve

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

📰 Critical RCE Flaw in SAUTER Building Controllers Threatens Physical Systems

Critical 9.8 CVSS RCE flaw (CVE-2026-78319) disclosed in SAUTER building automation controllers. Attackers could control HVAC & other physical systems. Patch immediately! #ICS #OTsecurity #CyberSecurity #CVE #BuildingAutomation

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • SonicWall
  • SMA1000

01 Sep 2026
Published
01 Sep 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Statistics

  • 3 Posts
  • 5 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CVE-2026-83548, a critical SonicWall SMA1000 vulnerability, is exploited in the wild. The pre-authentication SSRF flaw scores a maximum 10.0 CVSS.

securityonline.info/sonicwall-

  • 1
  • 0
  • 0
  • 5h ago

Bluesky

Profile picture fallback
CVE-2026-83548 が悪用されました: SMA1000 SSRF が 10.0 に到達 CVE-2026-83548 Exploited: SMA1000 SSRF Hits 10.0 #DailyCyberSecurity (Sep 1) securityonline.info/sonicwall-sm...
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
CVE-2026-83548 & CVE-2026-83549
  • 0
  • 4
  • 0
  • 6h ago

Overview

  • WebPros
  • Plesk

01 Sep 2026
Published
01 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.0)
EPSS
1.17%

KEV

Description

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.

Statistics

  • 2 Posts
  • 7 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

sev:CRIT LPE in Plesk. Gotta love that shared infra and the inherited risk that comes with it.

nvd.nist.gov/vuln/detail/cve-2

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.

  • 5
  • 2
  • 0
  • 13h ago

Bluesky

Profile picture fallback
~Cybergcca~ Plesk versions before 18.0.79.9 and 18.0.80.5 allow privilege escalation to root; update promptly. - IOCs: CVE-2026-67394 - #CVE202667394 #Plesk #ThreatIntel
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • PaperCut
  • PaperCut MF/NG

28 Aug 2026
Published
01 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.93%

Description

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

Statistics

  • 5 Posts

Last activity: 7 hours ago

Fediverse

Profile picture fallback

T-Suite Technical Brief: CVE-2026-82078 active exploitation targets PaperCut NG/MF with unsafe reflection & arbitrary Java execution. Read our engineering runbook for CrowdStrike CQL detection rules, ATT&CK mapping, and hardening controls.
thecybermind.co/zqkw

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback

Two vulnerabilities in PaperCut NG and MF print management software are now being used by attackers in data theft campaigns.
PaperCut software is used by millions of people across thousands of organizations.
The flaws are tracked as CVE-2026-81578 and CVE-2026-82078.

  • 0
  • 0
  • 1
  • 19h ago
Profile picture fallback

Frisch geschlossene Sicherheitslücken in PaperCut NG und MF (CVE-2026-81578 & CVE-2026-82078) dienen Angreifern aktuell aktiv als Einfallstor für massiven Datendiebstahl. Die Kombination aus Authentifizierungs-Bypasses und Remote Code Execution erlaubt vollständige Systemübernahmen im Netz exponierter Printserver. Administratoren müssen ausstehende Patches zwingend einspielen und den Zugriff sofort einschränken.

#PaperCut #Infosec #Vulnerability #CyberSecurity #DataTheft #SysAdmin

  • 0
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
PaperCut NG/MF: Critical Authentication Bypass and RCE Chain CVE-2026-81578 & CVE-2026-82078 https://horizon3.ai/attack-research/vulnerabilities/cve-2026-81578-cve-2026-82078 https://flagthis.com/tldr/6834 ##RCE ##ZeroDay ##PaperCut ##AuthenticationBypass ##CyberSecurity
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Metabase
  • Metabase

10 Aug 2026
Published
12 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
82.32%

Description

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Eine kritische Schwachstelle in Metabase (CVE-2026-72898) reißt ein massives Sicherheitsloch auf: Die ungeauth-fähige Lücke mit dem Höchstwert CVSS 10.0 erlaubt Angreifern den direkten Zugriff auf Anmeldedaten aller verknüpften Datenbanken. Prominente Unternehmen wie Framework, n8n und Checkly wurden bereits Opfer von Datenabflüssen. Betreiber müssen Instanzen sofort patchen und alle Credentials rotieren.

#Metabase #CyberSecurity #DataLeak #Infosec #Database #TechNews

  • 1
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
CVE-2026-72898 (CVSS 10.0) has been in the wild for over a week. N8n and Kilo Code are the latest victims, joining the first-wave roster. The week-two pattern: SMB self-hosted Metabase is the soft target. Audit every instance + run the compromise-hunting query: https://secureinseconds.com/blog/2026-
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Sangoma
  • Switchvox SMB Edition

17 Jul 2026
Published
12 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.43%

KEV

Description

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Statistics

  • 3 Posts

Last activity: 12 hours ago

Fediverse

Profile picture fallback

CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution.

securityonline.info/sangoma-sw

  • 0
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586
  • 0
  • 0
  • 1
  • 15h ago
Showing 1 to 10 of 46 CVEs