24h | 7d | 30d

Overview

  • TP-Link Systems Inc.
  • Kasa EC71 v4

15 Jul 2026
Published
15 Jul 2026
Updated

CVSS v4.0
MEDIUM (5.3)
EPSS
0.38%

KEV

Description

An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of integrity of availability impact.

Statistics

  • 2 Posts
  • 306 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

The LG TV network scanning story breaking today includes UDP 9999 Kasa discovery broadcasts every 25 seconds. That's the exact port I documented in CVE-2026-13230 as returning unauthenticated precise GPS coordinates from Kasa cameras with no authentication. Any LG TV + unpatched Kasa camera on the same network = GPS harvesting every 25 seconds. @briankrebs Advisory: github.com/BadChemical/IoT-Vul

  • 182
  • 124
  • 0
  • 17h ago
Profile picture fallback

@ohunt I can't speak to the CFAA since I'm no lawyer. Exploitation in this exact scenario isn't a valid classifier either since the underlying vuln of CVE-2026-13230 is a lack of meaningful protection, it equates to intercepting HTTP at this point. Ask and receive. However the protocol that operates on UDP 9999 has been broken for about 10 years now and has an RCE vuln on a different device class.

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • N-able
  • N-central

06 Sep 2026
Published
08 Sep 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.41%

KEV

Description

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Statistics

  • 9 Posts
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-86218: N-able N-central on-prem RCE (CRITICAL) enables unauthenticated code execution. Hotfix 4 (2026.3) required ASAP. Nearly 1,500 exposed servers tracked. Patch now: radar.offseq.com/threat/n-able

  • 1
  • 0
  • 0
  • 23h ago
Profile picture fallback

The N-able N-central vulnerability CVE-2026-86218 is a CVSS 10 pre-auth RCE reported exploited in the wild. Apply 2026.3 HF4 immediately.

securityonline.info/n-able-n-c

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback

Active N-central vulnerability exploitation targets IT servers. Patch the critical N-central vulnerability now to stop pre-auth RCE attacks.

meterpreter.org/cve-2026-86218

  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback

📰 N-able N-central Hit by Actively Exploited CVSS 10.0 RCE Flaw

🚨 URGENT: N-able N-central is being actively exploited via a CVSS 10.0 RCE zero-day (CVE-2026-86218). Unauthenticated attackers can take over RMM servers. On-prem customers must apply Hotfix 4 immediately. #CyberSecurity #RMM #MSP

🔗 cyber.netsecops.io/articles/n-

  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

⚠️ CRITICAL: N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

N-able N-central RMM platform contains a critical unauthenticated RCE vulnerability (CVE-2026-86218, CVSS 10.0) affecting all builds before 2026.3.1.14. While N-able denies confirmed exploitation, incident reports indicate active wild exploitation. Any organization running N-central is at immediate…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

⚠️ CRITICAL: N-able patches max severity N-central flaw amid ongoing attacks

N-able has released emergency patches for three vulnerabilities in N-central RMM, including a critical unauthenticated RCE (CVE-2026-86218) and two high-severity authentication bypasses. Evidence indicates active exploitation in customer environments. Any organization running N-central is at immedi…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
N-able released Hotfix 4 for N-central to fix CVE-2026-86218, a critical pre-auth RCE affecting on-prem builds before 2026.3.1.14. Notices differ on exploitation status. #Ncentral #CVE202686218 #Nable
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) 🔗 Read more: www.helpnetsecurity.com/2026/09/07/n... #Vulnerability #ZeroDay #Cybersecurity
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)(N-able、実攻撃で悪用されるN-centralの重大ゼロデイ脆弱性を修正) #HelpNetSecurity (Sep 7) www.helpnetsecurity.com/2026/09/07/n...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Google
  • Chrome

03 Sep 2026
Published
06 Sep 2026
Updated

CVSS
Pending
EPSS
1.16%

Description

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Statistics

  • 7 Posts
  • 7 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

🐀 ZERO-DAY CHROMIUM

La vulnerabilità CVE-2026-85046 nel motore V8 viene sfruttata attivamente. Il problema riguarda Chrome e richiede attenzione anche per i browser basati su Chromium, come Brave, Edge, Vivaldi e Opera.

Controlla la versione installata e aggiorna subito: la privacy non può sostituire una patch di sicurezza.

@sicurezza

#Cybersecurity #Chromium #Linux #NextRed

  • 3
  • 3
  • 0
  • 3h ago
Profile picture fallback

Geopolitical tensions escalated in the Strait of Hormuz with Iran-US vessel clashes reported (Sept 6). In cybersecurity, Google patched an actively exploited Chrome zero-day (CVE-2026-85046), while the FBI is probing a breach at an ID verification company that may have exposed millions of driver's licenses (Sept 6). AI integration into ALPRs also raises new privacy concerns (Sept 7).

#Cybersecurity #Geopolitics #TechNews

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback

Since I saw people asking, yes it included a fix for the zero day CVE-2026-85046 (Type confusion in V8)

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback

Google corrige un día cero de V8 en Chrome que se explota de forma activa

Google ha distribuido una actualización urgente de Chrome para corregir CVE-2026-85046, un zero-day en V8 con explotación activa. La solución pasa por actualizar a Chrome 152.0.7977.82 o superior y reiniciar el navegador para aplicar el parche.

unaaldia.hispasec.com/google-c

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback

Geopolitical tensions escalate as Iran announces a "restricted zone" near the Strait of Hormuz, following reports of attacks on vessels. In technology, OpenAI's GPT-6 Astra has achieved "Critical" cyber capabilities, able to discover and exploit vulnerabilities, alongside a $1B pledge for cyber defense. Cybersecurity highlights include a $320M Liquid Network hack and Google patching its sixth Chrome zero-day (CVE-2026-85046) under active exploitation this year.

#AnonNews_irc #Cybersecurity #News

  • 0
  • 0
  • 0
  • 17h ago

Bluesky

Profile picture fallback
🚨 Google fixed 38 Chrome security vulnerabilities in just a few days — and one is already being actively exploited. CVE-2026-85046 affects the V8 JavaScript engine and can enable code execution inside the browser sandbox. basefortify.eu/posts/2026/0... #CyberSecurity #Chrome #CVE
  • 0
  • 1
  • 0
  • 21h ago
Profile picture fallback
⚠️ The Chrome updates address vulnerabilities in V8, WebGL, DevTools, Skia, WebRTC and more. Several flaws can enable code execution outside the Chrome sandbox. Google confirms an exploit for CVE-2026-85046 exists in the wild. #InfoSec #Vulnerability
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Adobe
  • Adobe Commerce

07 Sep 2026
Published
07 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
Pending

KEV

Description

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Statistics

  • 4 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Adobe Commerce faces a CRITICAL (CVSS 10) template engine flaw (CVE-2026-75650) allowing arbitrary code execution with no user interaction required. Update and monitor for patches. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

An Adobe Commerce vulnerability, CVE-2026-75650 (CVSS 10), enables unauthenticated arbitrary code execution and is exploited in the wild. Patch now.

securityonline.info/adobe-comm

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
Magentoのゼロデイ「StyleSmuggler」が悪用され、Linuxバックドアが展開される(CVE-2026-75650) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47651/
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
Adobe Commerce CVE-2026-75650 “StyleSmuggler”: Critical RCE Exploited in the Wild(Adobe Commerce「StyleSmuggler」、CVSS 10.0のRCE脆弱性が実攻撃で悪用) #SecurityOnline (Sep 8) securityonline.info/adobe-commer...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

11 Aug 2026
Published
03 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.48%

KEV

Description

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

A Windows HTTP.sys vulnerability, CVE-2026-62735 (CVSS 7.8), now has public details and a PoC. It escalates local users to SYSTEM. Patch now.

securityonline.info/windows-ht

  • 0
  • 1
  • 0
  • 8h ago

Bluesky

Profile picture fallback
Windows HTTP.sys CVE-2026-62735: PoC Exploit Released for Privilege Escalation Flaw(Windows HTTP.sysの権限昇格脆弱性、CVE-2026-62735のPoC Exploitが公開) #SecurityOnline (Sep 7) securityonline.info/windows-http...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

A Dell Secure Connect Gateway vulnerability (CVE-2026-80172, CVSS 9.8) grants unauthorized access via forged admin tokens. Patch SCG now.

securityonline.info/dell-scg-c

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
Dell SCG CVE-2026-80172: Critical Flaw Allows Attackers to Generate ADMIN Tokens(Dell Secure Connect Gatewayに重大な脆弱性、攻撃者がADMINトークンを生成可能) #SecurityOnline (Sep 8) securityonline.info/dell-scg-cve...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Proxmox Server Solutions GmbH
  • Proxmox Virtual Environment (VE)

01 Sep 2026
Published
03 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
1.75%

KEV

Description

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.

Statistics

  • 3 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

🚨 In this week’s newsletter, we cover CVE-2023-54391, a critical authentication bypass affecting Proxmox VE that is seeing exploitation attempts. We break down how attackers can bypass password verification with a single unauthenticated request and what defenders should do next.

Read the full analysis and protect your systems 👉 crowdsec.net/vulntracking-repo

  • 0
  • 0
  • 1
  • 20h ago

Bluesky

Profile picture fallback
⚠️ Cette faille Proxmox corrigée en 2023 est activement exploitée (CVE-2023-54391) Surtout, elle est restée dans l'ombre pendant 3 ans. Retrouvez mon article à ce sujet 👇 - www.it-connect.fr/proxmox-ve-c... #Proxmox #infosec #cybersecurite
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • NetScaler
  • ADC

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
3.37%

KEV

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Statistics

  • 2 Posts

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Hackers are actively exploiting CVE-2026-19490, a critical authentication bypass vulnerability in Citrix NetScaler. Update your systems immediately.

meterpreter.org/citrix-netscal

  • 0
  • 0
  • 0
  • 20h ago

Bluesky

Profile picture fallback
Citrix NetScalerの脆弱性 CVE-2026-19490がサイバー攻撃への悪用試行 PoC公開後に観測、認証回避でCVSS 9.3 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • SonicWall
  • SMA1000

01 Sep 2026
Published
03 Sep 2026
Updated

CVSS
Pending
EPSS
0.71%

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

SonicWall SMA 1000 vulnerabilities are exploited in the wild. Public PoC exploit code is disclosed for the critical SonicWall SMA 1000 exploit chain.

securityonline.info/sonicwall-

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
Just added a @metasploit-r7.bsky.social exploit for last weeks SonicWall SMA1000 0-day chain that's exploited in-the-wild (CVE-2026-83548, SMA1000-9427, CVE-2026-83549). 3 bug chain; SSRF to CouchDB read/write for low priv RCE, to root RCE via cmd injection in cmsSnmpTrap github.com/rapid7/metas...
  • 0
  • 2
  • 0
  • 12h ago
Profile picture fallback
~Checkpoint~ Critical zero-days hit SonicWall and JFrog; AI attacks and data breaches expand. - IOCs: CVE-2026-83548, CVE-2026-83549, CVE-2026-82329 - #CVE #Ransomware #ThreatIntel
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Mikrotik
  • RouterOS

05 Sep 2026
Published
07 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.25%

KEV

Description

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

Statistics

  • 3 Posts
  • 3 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit

🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity

🔗 cyber.netsecops.io/articles/mi

  • 2
  • 1
  • 0
  • 15h ago
Profile picture fallback

⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
MikroTik Routers Targeted Through Internet-Exposed SSH Access #CVE202667276 #CVE202686060 #MikroTikRouterOS
  • 0
  • 0
  • 0
  • 21h ago
Showing 1 to 10 of 61 CVEs