24h | 7d | 30d

Overview

  • GNU
  • gzip

29 Jun 2026
Published
27 Aug 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.36%

KEV

Description

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer. This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d.

Statistics

  • 5 Posts
  • 20 Interactions

Last activity: 15 hours ago

Fediverse

Profile picture fallback
  • 3
  • 10
  • 1
  • 16h ago
Profile picture fallback

I physically can't access most of my computers right now due to motorbike logistics, and in the middle of nowhere I read about a buffer overflow in GNU gzip (CVE-2026-41992).

Fortunately, I believe every place that matters I'm explicitly using a pure #rust implementation of gzip.

  • 1
  • 3
  • 0
  • 15h ago

Bluesky

Profile picture fallback
[some-subscribed-rss] New Post: "No way to prevent this" say users of only language where this regularly happens, by https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • NetScaler
  • ADC

30 Jun 2026
Published
27 Aug 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
1.61%

Description

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Statistics

  • 5 Posts
  • 4 Interactions

Last activity: 16 hours ago

Fediverse

Profile picture fallback

🚨 Executive Risk Brief: CVE-2026-8452 targets Citrix NetScaler ADC & Gateway via memory buffer flaws. Leaders must review asset visibility, patch velocity, and risk governance. Read the full CSUITE brief: thecybermind.co/zapn

  • 0
  • 1
  • 0
  • 16h ago

Bluesky

Profile picture fallback
CISA urges immediate remediation of CVE-2026-8452 in Citrix NetScaler due to active exploitation, including unauthenticated remote code execution and web shell deployment.
  • 0
  • 1
  • 0
  • 23h ago
Profile picture fallback
CISA added CVE-2026-8452 to its KEV list after active exploitation of Citrix NetScaler flaws enabling unauthenticated RCE. Attackers were seen deploying web shells and running discovery commands. #Citrix #NetScaler #CISA
  • 0
  • 1
  • 0
  • 20h ago
Profile picture fallback
Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) 🔗 Read more: www.helpnetsecurity.com/2026/08/27/n... #exploit #vulnerability #cybersecurity
  • 0
  • 1
  • 0
  • 18h ago
Profile picture fallback
CISA ordered federal agencies to patch Citrix NetScaler by Aug. 29 after CVE-2026-8452, a memory overflow flaw under active exploitation that can enable root RCE. #CISA #Citrix #NetScaler
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • DJI
  • Neo

24 Aug 2026
Published
27 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.39%

KEV

Description

DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.

Statistics

  • 1 Post
  • 28 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Go hack more drone shit.

nvd.nist.gov/vuln/detail/cve-2

DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in /blackbox/upgrade/, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.

  • 17
  • 11
  • 0
  • 9h ago

Overview

  • OpenZFS
  • OpenZFS

26 Aug 2026
Published
27 Aug 2026
Updated

CVSS v4.0
HIGH (7.3)
EPSS
0.14%

KEV

Description

On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.

Statistics

  • 1 Post
  • 30 Interactions

Last activity: 18 hours ago

Fediverse

Profile picture fallback

#OpenZFS security advisory. If you're using OpenZFS on Linux, and you have unprivileged users or containers on the system, you should upgrade to the latest releases ASAP.

github.com/openzfs/zfs/securit
cve.org/CVERecord?id=CVE-2026-

  • 15
  • 15
  • 0
  • 18h ago

Overview

  • Zimbra
  • Collaboration

13 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
20.53%

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Statistics

  • 2 Posts

Last activity: 19 hours ago

Fediverse

Profile picture fallback

Zimbra : plus de 270 serveurs de messagerie compromis grâce à la faille CVE-2026-73570 it-connect.fr/zimbra-cve-2026- #ActuCybersécurité #Cybersécurité #Vulnérabilité

  • 0
  • 0
  • 0
  • 19h ago

Bluesky

Profile picture fallback
🛑 Zimbra Plus de 270 serveurs de messagerie compromis grâce à la faille CVE-2026-73570. Une alerte à prendre au sérieux liée à cette faille permettant l'injection de commande au niveau de l'OS. Plus d'infos : - www.it-connect.fr/zimbra-cve-2... #infosec #zimbra
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 3 Posts

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Critical Next.js & libheif RCE Vulnerabilities: Inside the August 2026 AVIF Zero-Day Exploit Chain

Critical Next.js RCE vulnerabilities affect AVIF image optimization and Windows servers. Learn about libheif, GHSA-2xp9-vwfh-vxw4, CVE-2026-75604

thecybersecguru.com/news/nextj

  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

: Two Critical Vulnerabilities in NextJS allow unauthenticated : one through crafted AVIF images, another via path traversal on Windows (CVE-2026-75604).
Upgrade your NextJS immediately to v15.5.24 or 16.3.3!:
👇
thehackernews.com/2026/08/next

  • 0
  • 0
  • 1
  • 10h ago

Overview

  • Oracle Corporation
  • Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in

20 Jan 2026
Published
25 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
42.02%

Description

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Statistics

  • 2 Posts

Last activity: 18 hours ago

Fediverse

Profile picture fallback

Oracle Sicherheitsloch von Januar wird angegriffen!

Vor einem Monat hatte Oracle einen riesigen Haufen Sicherheitslücken geflickt. Aber um gefährdet zu sein, braucht man keine frischen Sicherheitslücken. Es reicht auch, Updates nicht zu installieren. Die CISA hat die Sicherheitslücke CVE-2026-21962 (Risiko 10 von 10) in Oracle-Software, gegen die im Januar bereits ein Update veröffentlicht wurde, am 2026-08-24 in den Katalog der als ausgenutzt bekannten Sicherheitslücken (KEV) aufgenommen. Die US-Behörden wurden angewiesen, das Update nunmehr binnen drei Tagen einzuspielen. Ab heute müssten also Angriffe auf diese Lücke in Leere laufen. ;-)

pc-fluesterer.info/wordpress/2

#cybercrime #exploits #sicherheit #UnplugOracle #UnplugTrump

  • 0
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
CISA、悪用されているOracle WebLogicの脆弱性について警告(CVE-2026-21962) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47375/
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

11 Aug 2026
Published
27 Aug 2026
Updated

CVSS v3.1
HIGH (8.0)
EPSS
0.95%

KEV

Description

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Statistics

  • 2 Posts

Last activity: 15 hours ago

Fediverse

Profile picture fallback

Aktuelle Neuigkeiten: Microsoft Exchange: Exploit-Code veröffentlicht (CVE-2026-62911)
cert.at/de/aktuelles/2026/8/mi

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
📢 [VULN] Une vulnérabilité Exchange à patcher d'urgence CVE-2026-62911 Le 11 août dernier, Microsoft dévoilait son patch tuesday le plus volumineux, avec des correctifs pour rien moins que 421 vulnérabilités, dont 7 pour Exchange. #Vulnérabilité #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • mcp-router
  • mcp-router

27 Aug 2026
Published
27 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP server it fronted, to anyone able to reach the port. Release 0.6.3 defaults the host to the loopback address and refuses to start without a token whenever the host it is given is not a loopback address; no earlier release carries either check.

Statistics

  • 1 Post
  • 8 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Go hack more MCP shit.

nvd.nist.gov/vuln/detail/cve-2

The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP server it fronted, to anyone able to reach the port. Release 0.6.3 defaults the host to the loopback address and refuses to start without a token whenever the host it is given is not a loopback address; no earlier release carries either check.

  • 3
  • 5
  • 0
  • 9h ago

Overview

  • Spring
  • Spring Security

27 Aug 2026
Published
27 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
0.29%

KEV

Description

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback

wat

spring.io/security/cve-2026-59

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.

An attacker who could reach the LDAP listener port could authenticate using the well-known administrative bind DN, and then read or modify entries in the in-memory directory.

  • 2
  • 3
  • 0
  • 12h ago
Showing 1 to 10 of 80 CVEs