24h | 7d | 30d

Overview

  • Cisco
  • Cisco Secure Firewall Management Center (FMC)

04 Mar 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
74.70%

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

Statistics

  • 11 Posts
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Your firewall management plane has a CVSS 10.0 root vulnerability, and the attackers have been inside for six weeks.

Cisco confirmed active exploitation of CVE-2026-20079 in Secure Firewall Management Center this week. Unauthenticated. No credentials. Root on the box. No workaround. The web interface is the entry point. The compromised system is the one that pushes policy to every firewall you own.

Patch Tuesday gave you 974 CVEs this week. CISA just told you which three come first.

  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback

The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. bleepingcomputer.com/news/secu

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback

The EU Cyber Resilience Act (CRA) takes effect today, September 11, mandating 24-hour vulnerability reporting from manufacturers of connected hardware and software. Simultaneously, state-backed threat actors are increasingly targeting EU officials via encrypted messaging apps for phishing attacks, and a critical Cisco Secure Firewall Management Center flaw (CVE-2026-20079) requires urgent patching. Geopolitically, tensions escalated in the Strait of Hormuz following Iranian claims of ship attacks after US actions, and conflicts continue in the Middle East. In technology, Google Threat Intelligence reported on an AI system capable of harvesting thousands of credentials autonomously.

#Cybersecurity #Geopolitics #TechNews

  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback

Three threat clusters, including state-sponsored actors and Qilin ransomware affiliates, have exploited two critical Cisco FMC vulnerabilities to deploy web shells, Cyclops Blink malware, and steal sensitive credentials. Cisco has confirmed the exploitation of CVE-2026-20079 and CVE-2026-20316 and urges all customers to install the released hotfixes immediately.
bleepingcomputer.com/news/secu

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
CVE-2026-20079 enables unauthenticated remote attackers to bypass authentication, execute scripts, and gain root access on vulnerable Cisco Secure Firewall FMC devices.
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
📢 Cisco confirme l'exploitation active de CVE-2026-20079, faille critique dans Secure FMC BleepingComputer, publié le 9 septembre 2026. Cisco a officiellement confirmé l'exploitation active de CVE-2026-20079, une vulnérabilité… 🟢 vérification factuelle haute #CISAKEV #CiscoSecureFMC #Cyberveille
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks #cybersecurity #hacking #news #infosec #security #technology #privacy
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) 📖 Read more: www.helpnetsecurity.com/2026/09/10/c... #cybersecurity #cybersecuritynews #APT #firewall #ransomware #vulnerability @cisco.com @talosintelligence.com @horizon3ai.bsky.social
  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback
Cisco FMC bugs CVE-2026-20079 and CVE-2026-20316 are being exploited by nation-state and ransomware actors for unauthenticated access and root control. Talos links activity to Sandworm and Qilin. #CiscoFMC #Sandworm #Qilin
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Cisco FMCの脆弱性、ランサムウェアアクターや国家型ハッカーに悪用される:CVE-2026-20079、CVE-2026-20316 | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47682/
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)(Cisco FMCの脆弱性、国家支援型攻撃者やランサムウェア攻撃者が悪用) #HelpNetSecurity (Sep 10) www.helpnetsecurity.com/2026/09/10/c...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • DeepSeek
  • DeepSeek Harness

08 Sep 2026
Published
10 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.42%

KEV

Description

DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the default configuration, a confined tool-executed process can reach the loopback API without any port exposure and use it to escape its own OS sandbox, escalate to unconfined execution, and disable the approval prompt. When the port is externally reachable via tunnel, SSH forward, or reverse proxy, a remote attacker can exploit the same flaw to create sessions, execute arbitrary commands, and exfiltrate stored conversation transcripts without credentials.

Statistics

  • 3 Posts
  • 12 Interactions

Last activity: 21 hours ago

Fediverse

Profile picture fallback

CVE-2026-82533: la falla in DeepSeek Harness che lasciava agli agenti AI le chiavi della propria sandbox
#tech
spcnet.it/cve-2026-82533-la-fa
@informatica

  • 10
  • 0
  • 0
  • 21h ago
Profile picture fallback

CVE-2026-82533: la falla in DeepSeek Harness che lasciava agli agenti AI le chiavi della propria sandbox

Un'interfaccia locale priva di autenticazione e vulnerabile a host header spoofing permetteva agli agenti di DeepSeek Harness di disattivare la propria sandbox con un solo comando. Analisi tecnica di CVE-2026-82533 (CVSS 9.4) e consigli pratici per proteggere gli ambienti dove girano coding agent AI.

spcnet.it/cve-2026-82533-la-fa

  • 1
  • 0
  • 0
  • 22h ago

Bluesky

Profile picture fallback
✨ CVE-2026-82533: la falla in DeepSeek Harness che lasciava agli agenti AI le chiavi della propria sandbox Leggi il blog: spcnet.it/cve-2026-825...
  • 0
  • 1
  • 0
  • 21h ago

Overview

  • SAP_SE
  • SAP Extended Passport (EPP) Processing

08 Sep 2026
Published
08 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.32%

KEV

Description

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

Statistics

  • 3 Posts

Last activity: 6 hours ago

Fediverse

Profile picture fallback

The SAP OVERPASS vulnerability (CVE-2026-44756) scores a perfect CVSS 10.0, letting attackers seize SAP servers before login. Patch Note 3747649 now.

securityexpress.info/sap-overp

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

#SAP toppt mit #Schwachstellen (CVSS Base Score 10.0) zum Sept. 2026 Patchday mal wieder alles - das BSI warnt, patchen, patchen, patchen.

borncity.com/blog/2026/09/10/s

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-44756) #SAP Remote Code Execution via Extended Passport Processing". #cybersecurity #AttackSurfaceManagement #EASM https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Cisco
  • Cisco Secure Firewall Management Center (FMC)

29 Jul 2026
Published
11 Sep 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
11.15%

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Statistics

  • 5 Posts
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Three threat clusters, including state-sponsored actors and Qilin ransomware affiliates, have exploited two critical Cisco FMC vulnerabilities to deploy web shells, Cyclops Blink malware, and steal sensitive credentials. Cisco has confirmed the exploitation of CVE-2026-20079 and CVE-2026-20316 and urges all customers to install the released hotfixes immediately.
bleepingcomputer.com/news/secu

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) 📖 Read more: www.helpnetsecurity.com/2026/09/10/c... #cybersecurity #cybersecuritynews #APT #firewall #ransomware #vulnerability @cisco.com @talosintelligence.com @horizon3ai.bsky.social
  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback
Cisco FMC bugs CVE-2026-20079 and CVE-2026-20316 are being exploited by nation-state and ransomware actors for unauthenticated access and root control. Talos links activity to Sandworm and Qilin. #CiscoFMC #Sandworm #Qilin
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Cisco FMCの脆弱性、ランサムウェアアクターや国家型ハッカーに悪用される:CVE-2026-20079、CVE-2026-20316 | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47682/
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)(Cisco FMCの脆弱性、国家支援型攻撃者やランサムウェア攻撃者が悪用) #HelpNetSecurity (Sep 10) www.helpnetsecurity.com/2026/09/10/c...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Adobe
  • Adobe Commerce

07 Sep 2026
Published
09 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
2.15%

Description

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 16 hours ago

Fediverse

Profile picture fallback

If you want to learn more about the latest zero-day #Magento exploit (StyleSmuggler), this a great read: graycore.io/case-studies/CVE-2

  • 2
  • 0
  • 0
  • 16h ago
Profile picture fallback

Executive alert: CVE-2026-75650 actively threatens Adobe Commerce and Magento infrastructure. Review board-ready risk evaluation protocols, asset integrity measures, and strategic remediation steps to protect your enterprise value today.

thecybermind.co/hip4

  • 0
  • 0
  • 0
  • 23h ago

Overview

  • N-able
  • N-central

06 Sep 2026
Published
09 Sep 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.74%

Description

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 14 hours ago

Fediverse

Profile picture fallback

Discover the severe N-central CVE-2026-86218 vulnerability allowing unauthenticated RCE. Learn about N-able HF4 patches, CISA mandates, and threat actors.

meterpreter.org/n-central-cve-

  • 0
  • 0
  • 0
  • 19h ago

Bluesky

Profile picture fallback
New (draft) @metasploit-r7.bsky.social exploit module in the queue for the latest N-able N-central unauth RCE, CVE-2026-86218. Already being exploit in-the-wild, was disclosed five day ago, added to KEV two days ago. github.com/rapid7/metas...
  • 1
  • 2
  • 0
  • 14h ago

Overview

  • WatchGuard
  • Fireware OS

19 Dec 2025
Published
09 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
26.51%

Description

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

Statistics

  • 2 Posts

Last activity: 20 hours ago

Fediverse

Profile picture fallback

CVE-2025-14733: CRITICAL RCE in WatchGuard Firebox (Fireware OS 11.x+, 12.x+, 2025.1 – 2025.1.3) exploited by ransomware. Patch ASAP! Review VPN configs, monitor for IOCs. Details: radar.offseq.com/threat/cisa-w

  • 0
  • 0
  • 0
  • 21h ago

Bluesky

Profile picture fallback
CISA says ransomware gangs are exploiting CVE-2025-14733 in WatchGuard Firebox, a critical RCE flaw affecting Fireware OS 11.x, 12.x, and 2025.1. Tens of thousands of devices may still be exposed. #WatchGuard #CISA #RCE
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • SonicWall
  • SMA1000

14 Jul 2026
Published
04 Aug 2026
Updated

CVSS
Pending
EPSS
83.66%

Description

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Statistics

  • 3 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

An active SonicWall SMA 1000 campaign breached a UK council. Learn how the SonicWall SMA 1000 campaign exposed Active Directory records worldwide.

securityonline.info/sonicwall-

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
🕵️‍♂️ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance
  • 0
  • 0
  • 1
  • 15h ago

Overview

  • Forgejo
  • Forgejo

10 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
Pending

KEV

Description

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

Statistics

  • 1 Post
  • 11 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

RE: infosec.exchange/@cR0w/1172478

CVE for this one:

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

  • 6
  • 5
  • 0
  • 11h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

08 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.05%

KEV

Description

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

Statistics

  • 3 Posts

Last activity: 13 hours ago

Fediverse

Profile picture fallback

patched a Critical DNS Server Remote Code Execution (#RCE) in September Patch Tuesday:

🔴 CVE-2026-69730
⚠️ CVSS: 9.8
🌐 Unauthenticated remote attack (use-after-free)

Patch your DNS servers!
👇
msrc.microsoft.com/update-guid

  • 0
  • 0
  • 1
  • 13h ago

Bluesky

Profile picture fallback
比较严重的 bug 包括存在于 Windows Server 2012 以上版本 和 Windows 10 的 DNS 漏洞 CVE-2026-69730,未经身份验证的攻击者只需向受影响系统发送特制数据包即可利用该漏洞;另一个是 Windows Shell 程代码执行 bug CVE-2026-69829,威胁评分 9.8.10,极其容易利用。
  • 0
  • 0
  • 0
  • 20h ago
Showing 1 to 10 of 81 CVEs