24h | 7d | 30d

Overview

  • GitLab
  • GitLab

12 Sep 2026
Published
12 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
11.12%

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Statistics

  • 12 Posts
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Recent reports confirm a critical GitLab zero-day (CVE-2026-85706) exploited within 24 hours, alongside new EU Cyber Resilience Act mandates for 24-hour vulnerability reporting. Operational technology (OT) sectors face emerging ransomware threats. Meanwhile, leading AI developers advocate for a slowdown in development due to safety concerns, prompting market shifts. Geopolitically, the BRICS summit addressed rising global tensions and the "weaponization of technology."

#Cybersecurity #TechNews #Geopolitics

  • 0
  • 1
  • 0
  • 7h ago
Profile picture fallback

CVE-2026-85706 GitLab CE/EE: unauthenticated arbitrary file read via commits API, CVSS 10. Affects 18.7 up to 19.1.8, 19.2.6, 19.3.2. No patch confirmed yet, restrict access now. valtersit.com/cve/CVE-2026-857 #CVE #GitLab #infosec

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

⚠️GitLab : CVE-2026-85706 est activement exploitée.

Une faille critique de traversée de répertoires permet à un attaquant non authentifié de lire des fichiers arbitraires sur le serveur.

Encore une vulnérabilité qui prend des chemins de traverse…
../../../../etc/ :dumpster_fire_gif: 👀

-->GitLab auto-hébergé exposé sur Internet : mise à jour rapide recommandée.

Correctifs : 19.1.8, 19.2.6 et 19.3.2.

La faille a déjà rejoint le catalogue KEV de la CISA, et ça commence clairement à renifler autour : watchTowr et plusieurs honeypots ont déjà vu passer des tentatives de probing.

Onyphe recense une bonne centaine d’instances vulnérables en CH aujourd'hui...

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours(GitLabのCVSS 10.0脆弱性、認証不要・1リクエストでファイル窃取、24時間以内に悪用) #SecurityAffairs (Sep 13) securityaffairs.com/198945/hacki...
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
CISA Adds Three Known Exploited Vulnerabilities to Catalog(CISA、悪用が確認された3件の脆弱性をKEVカタログに追加) #CISA (Sep 11) CVE-2026-85706 GitLab Community EditionおよびEnterprise Editionにおけるパス・トラバーサル脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
GitLab Vulnerabilities: CVE-2026-85706 Scores CVSS 10.0, Under Active Attack(GitLabにCVSS 10.0の重大脆弱性、公開直後から実環境で攻撃) #SecurityOnline (Sep 11) securityonline.info/gitlab-vulne...
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
CISA says attackers are exploiting a max-severity GitLab flaw, CVE-2026-85706, that can expose credentials and secrets. GitLab has released fixes in CE and EE. #GitLab #CISA #watchTowr
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
GitLab released critical patches for CVE-2026-85706, enabling unauthenticated attackers to read arbitrary files from self-managed servers via the commits API.
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
📢 [VULN] GitLab : mise à jour de sécurité critique CVE-2026-85706 GitLab a publié le 10 septembre des mises à jour de sécurité. Ce patch critique concerne les versions enterprise et communautaire. #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours securityaffairs.com/198945/hacki...
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
GitLab sotto attacco: falla CVSS 10 legge file senza autenticazione CISA conferma lo sfruttamento di CVE-2026-85706, falla GitLab CVSS 10 che permette di leggere f... https://www.ilsoftware.it/gitlab-sotto-attacco-falla-cvss-10-legge-file-senza-login/
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
~Checkpoint~ Breaches, AI abuse, ransomware surge, and critical actively exploited flaws demand urgent patching. - IOCs: CVE-2026-85706, CVE-2026-81963, CVE-2026-85046 - #Ransomware #ThreatIntel #Vulnerabilities
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • ConnectWise
  • ScreenConnect

08 Sep 2026
Published
12 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.69%

Description

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

Statistics

  • 4 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

ConnectWise ScreenConnect CRITICAL vuln (CVE-2026-84869) exploited in worm-like attacks — unauthorized file transfer & execution via remote sessions in versions <26.6.5. Patch to 26.6.5 now or disable TransferFiles. radar.offseq.com/threat/connec

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

CRITICAL CISA KEV ALERT: CVE-2026-84869 targets ConnectWise ScreenConnect with unauthorized file transfer and RCE. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to protect your environment. thecybermind.co/g5ob

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
ConnectWise released urgent patches for CVE-2026-84869, a critical ScreenConnect flaw exploited in worm-like attacks, enabling unauthorized file transfer and execution via remote sessions.
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
CISA Adds Three Known Exploited Vulnerabilities to Catalog(CISA、悪用が確認された3件の脆弱性をKEVカタログに追加) #CISA (Sep 11) CVE-2026-42016 JFrog Artifactoryにおける認証エラーの脆弱性 CVE-2026-42018 JFrog Artifactoryの認証エラーの脆弱性 CVE-2026-84869 ConnectWise ScreenConnectにおける不適切な権限管理と認証の欠落の脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback
  • 1
  • 1
  • 0
  • 10h ago
Profile picture fallback

Defend against the CVE-2026-51990 Sogou exploit. Discover how hackers use this one-click flaw to drop backdoors and how to secure your systems today.

securityonline.info/cve-2026-5

  • 0
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
CVE-2026-51990 in Sogou Input Method enables a one-click exploit that injects command-line arguments and uses an outdated, unsandboxed Chromium engine to execute system-level code.
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Fortinet
  • FortiSwitchManager

13 Jan 2026
Published
10 Sep 2026
Updated

CVSS v3.1
HIGH (7.4)
EPSS
2.40%

Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

Statistics

  • 2 Posts

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Discover how the PivotC2 FortiGate RAT uses CVE-2025-25249 exploitation to harvest credentials and tunnel traffic across corporate network environments.

securityonline.info/pivotc2-fo

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
Fortinet製品におけるコード実行の脆弱性を悪用し、RAT「PivotC2」が展開される(CVE-2025-25249) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47685/
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • irontec
  • sngrep

12 Sep 2026
Published
12 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.51%

KEV

Description

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.

Statistics

  • 3 Posts

Last activity: 3 hours ago

Bluesky

Profile picture fallback
sngrep: fix CVE-2026-90558 https://github.com/NixOS/nixpkgs/pull/562971 https://tracker.security.nixos.org/issues/NIXPKGS-2026-2567 #security
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
Merged PRs for 2026-09-13 Packages #563033 wlr-utils: 1.7.0 -> 1.8.0 #563024 linux_testing: 7.3-rc2 -> 7.3-rc3 #563020 vaultwarden: 1.37.2 -> 1.37.3 #562984 npb: add changelog #562972 workflows/periodic-merge: use correct permissions #562971 sngrep: fix CVE-2026-90558
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
[Backport release-26.05] sngrep: 1.8.3 -> 1.8.4, fix CVE-2026-90558 https://github.com/NixOS/nixpkgs/pull/563160 https://tracker.security.nixos.org/issues/NIXPKGS-2026-2567 #security
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Adobe
  • Adobe Commerce

07 Sep 2026
Published
09 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
2.15%

Description

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Bluesky

Profile picture fallback
🚨 This week’s Threat Alert covers CVE-2026-75650 (StyleSmuggler), a critical RCE affecting Adobe Commerce & Magento. Exploited before the patch, it escalated to mass scanning, with 500+ IPs observed. Read the full analysis and protection recommendations: www.crowdsec.net/vulntracking...
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
~Akamai~ Unauthenticated RCE in Adobe Commerce/Magento is actively exploited; patch APSB26-146. - IOCs: CVE-2026-75650, StyleSmuggler - #CVE202675650 #RCE #ThreatIntel
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • jfrog
  • artifactory

28 Aug 2026
Published
03 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
7.67%

Description

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Statistics

  • 2 Posts

Last activity: 7 hours ago

Bluesky

Profile picture fallback
Critical Authentication Bypass in JFrog Artifactory CVE-2026-82329 https://simplysecuregroup.com/attackers-exploit-critical-jfrog-artifactory-flaw-to-mint-admin-tokens-days-after-disclosure https://flagthis.com/tldr/6838 ##SupplyChain ##Vulnerability ##JFrog ##AuthenticationBypass
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
Another excellent writeup by my colleague Nate Robb, this one analyzing an auth bypass affecting JFrog Artifactory (CVE-2026-82329)! bishopfox.com/blog/cve-202...
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Cisco
  • Cisco Secure Firewall Management Center (FMC)

04 Mar 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
75.75%

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow&nbsp;root access to the device.&nbsp;

Statistics

  • 1 Post
  • 12 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability…

Also tracked this week: Hackers exploit Sangoma Switchvox flaw to deploy reverse… · Microsoft Plugs Nearly 1,000…

nexus8.8bitsecurity.com/entity

  • 5
  • 7
  • 0
  • 11h ago

Overview

  • jfrog
  • artifactory

27 Jul 2026
Published
12 Sep 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.89%

Description

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Statistics

  • 2 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CRITICAL CISA KEV ALERT: CVE-2026-42016 targets JFrog Artifactory via incorrect authorization and token scope flaws. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to secure your software pipelines.

thecybermind.co/4u1b

  • 0
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
CISA Adds Three Known Exploited Vulnerabilities to Catalog(CISA、悪用が確認された3件の脆弱性をKEVカタログに追加) #CISA (Sep 11) CVE-2026-42016 JFrog Artifactoryにおける認証エラーの脆弱性 CVE-2026-42018 JFrog Artifactoryの認証エラーの脆弱性 CVE-2026-84869 ConnectWise ScreenConnectにおける不適切な権限管理と認証の欠落の脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Cisco
  • Cisco Secure Email

14 Sep 2026
Published
14 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Statistics

  • 1 Post
  • 6 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

ayy lmao Cisco CVE-2026-76461
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.

sec.cloudapps.cisco.com/securi

  • 3
  • 3
  • 0
  • 1h ago
Showing 1 to 10 of 61 CVEs