24h | 7d | 30d

Overview

  • WordPress
  • WordPress

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS
Pending
EPSS
2.88%

KEV

Description

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Statistics

  • 16 Posts
  • 2 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Cybersecurity faces immediate threats as a critical WordPress vulnerability (CVE-2026-87902) was exploited post-disclosure (Sept 24). Ransomware attacks reached a record high in August 2026, marking a significant surge. On the technology front, Meta Connect 2026 showcased key advancements in AI and virtual reality. Geopolitically, the Ukraine war persists, with President Zelensky expressing hope for peace before winter amidst ongoing US-Iran tensions.

#Cybersecurity #TechNews #Geopolitics

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
WordPress 7.1.2 で直った脆弱性 CVE-2026-87902 と、いま確認すること https://raplsworks.com/wordpress-7-1-2-security-release/ トリアージ目的もあり、対象判定の方法がまとまってるの助かる
  • 0
  • 1
  • 0
  • 10h ago
Profile picture fallback
Attackers are exploiting WordPress CVE-2026-87902 to include pearcmd.php and write PHP files when specific theme and server conditions are met.
  • 0
  • 1
  • 0
  • 7h ago
Profile picture fallback
WordPress重大な脆弱性 CVE-2026-87902のサイバー攻撃 悪用を確認-71.2など修正版へ更新を rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース #脆弱性
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
WordPress 7.1.2 fixes CVE-2026-87902, a critical no-login file inclusion flaw in core that can lead to code execution on some servers. www.cyberkendra.com/2026/09/cve-... #wordpress #webdev #security
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Exploited WordPress RCE Vulnerability: PoC Released for CVE-2026-87902(実悪用されるWordPressの重大なRCE脆弱性、PoCも公開) #SecurityOnline (Sep 24) securityonline.info/exploited-wo...
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
WordPress RCE Vulnerability CVE-2026-87902: Critical Unauthenticated Flaw Exploited in the Wild(WordPressの重大な認証不要RCE脆弱性、公開直後から攻撃を観測) #SecurityOnline (Sep 23) securityonline.info/wordpress-rc...
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
Hackers Exploit Critical WordPress Flaw for Code Execution Hackers are actively exploiting CVE-2026-87902, a critical WordPress flaw that can allow attackers to write malicious files and execute shell commands.
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
CVE-2026-87902 enables unauthenticated path traversal leading to remote code execution in affected WordPress setups.
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
CVE-2026-87902 enables unauthenticated remote code execution in WordPress when specific theme and readable local PHP file conditions are met.
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html
  • 0
  • 0
  • 1
  • 11h ago
Profile picture fallback
Threat actors are actively exploiting a critical WordPress vulnerability, CVE-2026-87902, just hours after its public disclosure. The unauthenticated remote code […]
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
WordPress 7.1.1-CVE-2026-87902 exploit
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
Die kritische WordPress-Lücke CVE-2026-87902 zeigt, wie schnell aus einem Sicherheitsupdate ein Wettlauf gegen die Zeit wird. Was hinter der Schwachstelle steckt, wie die Angriffe in drei Stufen ablaufen und warum das Update jetzt dringend ist. www.it-administrator.de/wordpress-sc...
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • F5
  • BIG-IP

22 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.29%

Description

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 14 Posts
  • 5 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Neu Warnung:
Aktive Ausnutzung: Kritische Sicherheitslücke in F5 BIG-IP APM (CVE-2026-94127) cert.at/de/warnungen/2026/9/f5

  • 1
  • 0
  • 0
  • 7h ago
Profile picture fallback

Have people seen exploit attempts (successful or not) before 2026-08?

  • 1
  • 0
  • 0
  • 5h ago
Profile picture fallback

‼️[POC] CVE-2026-94127: When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)

GitHub: github.com/watchtowrlabs/watch

  • 1
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
watchTowr details CVE-2026-94127, an unauthenticated heap overflow in F5 BIG-IP reachable through the auth header itself, leading to RCE. An oversized header is apparently all it takes on hardware that costs a fortune. Patching advice follows shortly, presumably.
  • 0
  • 2
  • 0
  • 19h ago
Profile picture fallback
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) - watchTowr Labs
  • 0
  • 0
  • 5
  • 22h ago
Profile picture fallback
F5 BIG-IP APMで認証不要のRCE 脆弱性 CVE-2026-94127、実際の攻撃で悪用確認 CVSS 9.8・CISA KEV掲載 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
~Watchtowr~ Unauthenticated OAuth requests can trigger heap overflow and remote code execution on vulnerable BIG-IP APM. - IOCs: CVE-2026-94127 - #CVE-2026-94127 #F5 #ThreatIntel
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
> 注意喚起: F5 BIG-IP Access Policy Managerにおけるヒープベースのバッファオーバーフローの脆弱性(CVE-2026-94127)に関する注意喚起 (公開) https://www.jpcert.or.jp/at/2026/at260028.html
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
📢 CVE-2026-94127 : Vulnérabilité critique F5 BIG-IP APM exploitée en zero-day SecurityWeek, article de Ionut Arghire publié le 23 septembre 2026. F5 et la CISA ont émis conjointement une alerte concernant l'exploitation active d'une… 🟡 vérification factuelle moyenne #APM #F5BIGIP #Cyberveille
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Cisco
  • Cisco Identity Services Engine Software

16 Sep 2026
Published
17 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
14.03%

Description

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 1 hour ago

Fediverse

Profile picture fallback

(CISA TS-MAN) The Cyber Mind TSUITE Brief: CVE-2026-76460 – Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Analyze the technical mechanics of CVE-2026-76460 with our Cisco TSUITE brief, covering Cisco ISE authentication bypass, path traversal vectors, and endpoint hardening....

thecybermind.co/9ysa

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
Cisco ISE has a CVSS 10.0 unauthenticated API authentication bypass (CVE-2026-76460) granting root command execution on all supported versions, 3.1 to 3.51. Exploited in the wild before the patch, now on CISA KEV. Cisco says no workarounds, though iACLs may mitigate. Patch your NAC platform.
  • 0
  • 1
  • 0
  • 1h ago
Profile picture fallback
The latest update for #BitSight includes "Identity Risk: 5 Access Pathways Emerging Across Threat Intelligence" and "CVE-2026-76460: A critical Cisco ISE authentication bypass under active exploitation". #Cybersecurity #RiskManagement https://opsmtrs.com/43KoF0t
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • checkpoint
  • Quantum Security Gateway

09 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.99%

Description

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Statistics

  • 3 Posts

Last activity: 17 hours ago

Bluesky

Profile picture fallback
Check Point VPNに脆弱性 CVE-2026-85102-サイバー攻撃への悪用を確認 Spark顧客を世界的に攻撃、CISA KEV追加 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース #脆弱性
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Check Point VPNに脆弱性 CVE-2026-85102-サイバー攻撃への悪用を確認 Spark顧客を世界的に攻撃、CISA KEV追加|セキュリティニュースのセキュリティ対策Lab KEVでは既知のランサムウェアキャンペーンでの利用は「Unknown」です。 米Federal Civilian Executive Branch(FCEB)機関にはBOD 26-04に基づく対応期限として9 ... rocket-boys.co.jp/security-mea...
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Check Point confirms active exploitation of CVE-2026-85102 and CVE-2026-93616 against Security Gateway and Management web services. Attackers used VPNs and proxies to hide origin. #CheckPoint #CISA #NCSC
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Roundcube
  • Webmail

25 May 2026
Published
03 Jun 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.89%

KEV

Description

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

An exploited Roundcube Webmail vulnerability allows SQL injection attacks. Learn how CVE-2026-48842 impacts servers and apply the latest patches immediately.

securityonline.info/exploited-

  • 1
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
Critical Roundcube flaw CVE-2026-48842 is being actively exploited in the wild, enabling pre-auth SQL injection via virtuser_query and possible auth bypass. #Roundcube #Canada #CVE-2026-48842
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Samsung Electronics
  • MagicINFO 9 Server

13 May 2025
Published
26 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
24.30%

Description

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 1 hour ago

Bluesky

Profile picture fallback
@huntress.com Attackers exploited Samsung MagicINFO, installed AnyDesk, disabled Defender, and compiled a Monero miner. - IOCs: 194[.]87[.]89[.]30, auto[.]c3pool[.]org, oldadministrator - #CVE-2025-4632 #Cryptominer #ThreatIntel
  • 0
  • 1
  • 0
  • 5h ago
Profile picture fallback
Huntress found an intrusion via Samsung MagicINFO CVE-2025-4632, followed by repeated AnyDesk installs, Defender tampering, and a SilentXMRMiner-based Monero miner compiled on the endpoint and tied to C3Pool. #MagicINFO #AnyDesk #C3Pool
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Veeam
  • Backup and Replication

28 May 2026
Published
23 Sep 2026
Updated

CVSS v4.0
HIGH (7.3)
EPSS
0.14%

KEV

Description

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
📢 [VULN] Veeam Agent pour Windows - Une faille qui donne les droits SYSTEM CVE-2026-32996 Si vous faites tourner Veeam Agent pour sauvegarder un poste Windows, et surtout si plusieurs personnes s'y connectent, allez vérifier tout de suite son numéro de build parce que depuis que… #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
Veeam Agent pour Windows : la faille CVE-2026-32996 offre les privilèges SYSTEM, un exploit est public www.it-connect.fr/veeam-agent-...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • checkpoint
  • Quantum Security Management

22 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.42%

Description

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

Statistics

  • 2 Posts

Last activity: 21 hours ago

Bluesky

Profile picture fallback
Check Point 管理サーバーにゼロデイ 脆弱性 CVE-2026-93616、7月からサイバー攻撃に悪用 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース #脆弱性
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Check Point confirms active exploitation of CVE-2026-85102 and CVE-2026-93616 against Security Gateway and Management web services. Attackers used VPNs and proxies to hide origin. #CheckPoint #CISA #NCSC
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Google
  • Chrome

30 Jun 2026
Published
01 Jul 2026
Updated

CVSS
Pending
EPSS
0.28%

KEV

Description

Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

One tap was enough to bypass a Chrome for iOS security check.

We found a way to use shortcuts to reach tel: or facetime: without Chrome applying its normal user-interaction checks to the final URL.

The issue, CVE-2026-13795, has been fixed.

Details 👇
blog.doyensec.com/2026/09/24/c

  • 2
  • 0
  • 0
  • 5h ago

Overview

  • pgpartman
  • pg_partman

18 Sep 2026
Published
19 Sep 2026
Updated

CVSS v3.1
HIGH (8.5)
EPSS
0.73%

KEV

Description

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_config.time_dncoder text value without identifier quoting into dynamic SQL. A role with the documented partman_user privileges can store SQL rather than a decoder function name. When an affected operation later uses the poisoned value, including pg_partman_bgw maintenance for a text- or UUID-keyed set, the SQL executes with the operation's privileges, which can be the default PostgreSQL superuser background-worker role. The persistent row can restore elevated access on later ticks, and successful exploitation can permit database-wide compromise and operating-system command execution as the PostgreSQL service account. This issue is fixed in version 5.5.0.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 16 hours ago

Fediverse

Profile picture fallback

CVE-2026-61817: SQL injection in pg_partman before 5.5.0. A partman_user role can poison part_config and inject SQL through run_maintenance. CVSS 8.5, no patch yet. Restrict that role until 5.5.0 lands. valtersit.com/cve/CVE-2026-618 #CVE #infosec #PostgreSQL

  • 1
  • 0
  • 0
  • 16h ago
Showing 1 to 10 of 80 CVEs