Overview
- GitLab
- GitLab AI Gateway
Description
Statistics
- 4 Posts
Fediverse
GitLab AI Gateway vulnerability CVE-2026-90970 (CVSS 9.9) lets Duo Agent Platform users run commands. Upgrade self-hosted gateways now.
#GitLab #AIGateway #GitLabDuo #CVE202690970 #RCE #DevSecOps #Vulnerability
CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
Critical GitLab AI Gateway vulnerability (CVE-2026-90970) enables remote code execution on self-hosted servers
GitLab CVE-2026-90970 is a critical 9.9 AI Gateway sandbox escape affecting self-hosted deployments. Check affected versions and patcheshttps://thecybersecguru.com/exploits/gitlab-ai-gateway-cve-2026-90970/
Overview
- Microsoft
- Microsoft Exchange Server 2016 Cumulative Update 23
Description
Statistics
- 5 Posts
Fediverse
Es gibt mehrere #Sicherheits #Updates für #Microsoft #Exchange #Server, die gleich mehrere Schwachstellen, u.a. die Elevation of Privilege-Schwachstelle #CVE-2026-96940 schließen.
PSA: Exchange Server V2 Security Updates for September were published, additionally addressing CVE-2026-96940 https://eightwone.com/2026/10/03/v2-security-updates-exchange-2016-se-sep2026/ #MSExchange
Microsoft's September 2026 V2 Exchange Server security updates add CVE-2026-96940 for Exchange SE, 2019 and 2016. Install them now.
#Microsoft #ExchangeServer #ExchangeSE #CVE202696940 #SecurityUpdate #PatchManagement #ESU
CVE-2026-96940 - Privilege Escalation in Microsoft Exchange Server from weak authorization. CVSS 8.8. Currently unpatched. Restrict network access now. #CVE #Microsoft #infosec
Overview
Description
Statistics
- 4 Posts
- 2 Interactions
Fediverse
📰 Critical Fortinet FortiMail Zero-Day Exploited for RCE
Fortinet warns of critical zero-day (CVE-2026-104286) in FortiMail, actively exploited for RCE. CVSS 9.8. CISA added to KEV. Patches are pending, but urgent workarounds are available. #Fortinet #ZeroDay #CVE2026104286 #CyberSecurity
🚨 Fortinet reports active exploitation of CVE-2026-104286, a critical path traversal vulnerability affecting FortiMail.
Censys observes roughly 2,800 Internet-exposed FortiMail hosts after excluding honeypots. This is an exposure count, not a confirmed-vulnerable count.
No fixed builds have been released as of October 2. Censys ARC covers affected versions, Fortinet’s current workarounds, indicators, and remediation guidance: https://censys.com/advisory/cve-2026-10426/
#CensysARC #Fortinet #FortiMail #Cybersecurity #Vulnerability
Bluesky
Overview
Description
Statistics
- 5 Posts
- 13 Interactions
Fediverse
Citrix flags a NetScaler SAML authentication issue as patched NetScaler appliances reboot after CVE-2026-88771 attacks. Check your config.
#Citrix #NetScaler #SAML #CVE202688771 #CVE202688772 #ZeroDay #Vulnerability
📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack
Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE
Bluesky
Overview
Description
Statistics
- 5 Posts
- 11 Interactions
Fediverse
Looking for additional Citrix NetScaler IOC? Sygnia has novel and credible indicators from CVE-2026-88771 exploitation (published 9/30):
https://www.sygnia.co/threat-reports-and-advisories/actively-exploited-netscaler-vulnerabilities/
Citrix flags a NetScaler SAML authentication issue as patched NetScaler appliances reboot after CVE-2026-88771 attacks. Check your config.
#Citrix #NetScaler #SAML #CVE202688771 #CVE202688772 #ZeroDay #Vulnerability
📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack
Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE
Bluesky
Overview
- MikroTik
- RouterOS
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
CVE-2026-84411 (CRITICAL, CVSS 9.8) affects MikroTik RouterOS <7.24. Integer underflow in web mgmt lets unauth'd attackers exec root code or DoS via crafted HTTP. Restrict access & monitor now. https://radar.offseq.com/threat/cve-2026-84411-cwe-191-in-mikrotik-routeros-962ba80173301661 #OffSeq #CVE #MikroTik #InfoSec
Overview
- Fortra
- BoKS Manager boks-server
Description
Statistics
- 2 Posts
Fediverse
Fortra BoKS faces 3 CRITICAL vulns (CVE-2026-79901, - 79898, - 12627): auth bypass, command injection as root, and remote memory corruption. No active exploits seen. Patch now to secure privileged environments! https://radar.offseq.com/threat/fortra-patches-critical-vulnerabilities-in-boks-b7c49740fa76eb7b #OffSeq #Fortra #BoKS #Vulnerability
Overview
- Digi International
- IX Family
Description
Statistics
- 2 Posts
Fediverse
Digi DAL OS vulnerability CVE-2026-75937 (CVSS 9.4) lets attackers run root commands on Digi Accelerated Linux devices. Patch now.
#Digi #DALOS #CVE202675937 #CommandInjection #IoTSecurity #OTSecurity #Vulnerability
https://securityonline.info/digi-dal-os-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
Digi IX Family devices hit by CRITICAL OS command injection (CVE-2026-75937, CVSS 9.4). Unauthenticated remote attackers can execute root commands via HTTP POST. Disable web admin interface to reduce risk. https://radar.offseq.com/threat/cve-2026-75937-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-deedd882034e65bf #OffSeq #Vulnerability #IoT #Infosec
Overview
Description
Statistics
- 2 Posts
- 5 Interactions
Fediverse
Google Chrome published an empty blog post as a security advisory on Thursday afternoon. They filled it out in the past day, but don't make it easy to grasp the severity of their bugs.
For example, "Critical CVE-2026-103628: Out of bounds write in WebGL." is actually a CVSSv3.1: 9.6 critical because it allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. You'd have to chase down those details yourself on cve.org or elsewhere.
https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html
Chrome security update: Chrome 154 fixes 11 flaws, including critical WebGL sandbox escape CVE-2026-103628. Update your browser now.
#Chrome #GoogleChrome #Chrome154 #CVE2026103628 #CVE2026103631 #BrowserSecurity #Vulnerability
Overview
Description
Statistics
- 2 Posts
Fediverse
U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog