24h | 7d | 30d

Overview

  • WordPress
  • WordPress

07 Aug 2026
Published
07 Aug 2026
Updated

CVSS v4.0
HIGH (8.9)
EPSS
0.77%

KEV

Description

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

Statistics

  • 5 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

📰 WordPress Patches 'XSS2Shell' Flaw Leading to RCE

WordPress patches critical 'XSS2Shell' flaw (CVE-2026-64638, CVSS 8.9). Unauthenticated XSS on login page can be chained for RCE. Update to version 7.0.3 immediately. #WordPress #XSS #RCE #Vulnerability #CVE202664638

🔗 cyber.netsecops.io/articles/wo

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

CVE-2026-64638: Severe Pre-Authentication XSS Flaw in WordPress Permits Remote Code Execution – Immediate Update to Version 7.0.3 #wordpress #programming

CVE-2026-64638 poses a serious pre-authentication XSS risk in WordPress that can lead to remote code execution. Immediate update to WordPress 7.0.3 is essential. Read the full incident overview and mitigation steps in our latest post: ift.tt/ghG2K8Z

Source: ift.tt/ghG2K8Z | Image: ift.tt/zle32Oa

  • 0
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
~Checkpoint~ Report covers North Carolina Ports cyberattack, WordPress XSS2Shell RCE flaw, and Shai-Hulud npm supply-chain campaign. - IOCs: CVE-2026-64638, keyv, WEL1DROPPER - #SupplyChain #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
📢 XSS2Shell : chaîne XSS pré-auth vers RCE sur WordPress Core (CVE-2026-64638) Cet article détaille la découverte et l'exploitation complète d'une chaîne de vulnérabilités baptisée XSS2Shell, affectant WordPress Core dans toutes ses… 🟡 vérification factuelle moyenne #RCE #WordPress #Cyberveille
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Progress Software
  • LoadMaster

04 Jun 2026
Published
08 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
99.31%

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Statistics

  • 4 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

⚠️ CRITICAL: CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

Progress Kemp LoadMaster has a critical RCE vulnerability (CVE-2026-8037) that allows unauthenticated attackers to execute arbitrary commands. Active exploitation started around June 29. Any organization running affected LoadMaster versions needs to patch immediately or risk full appliance compromi…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback

🚨 CRITICAL THREAT ALERT: CVE-2026-8037 is under active exploitation per CISA KEV. Progress LoadMaster appliances face remote command injection risks. Secure your perimeter with our strategic C-Suite breakdown covering technical indicators, backdoor mechanics, and hardening protocols.
thecybermind.co/2j7b

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback

Nutzt wer den Kemp LoadMaster und hat diesen nicht gepatcht?

borncity.com/blog/2026/08/08/k

  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
CISA says CVE-2026-8037 is actively exploited in Progress Kemp LoadMaster and MOVEit WAF. The command injection flaw can let unauthenticated attackers run arbitrary commands on exposed appliances. #LoadMaster #MOVEitWAF #CISA
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • N-able
  • N-central

02 Aug 2026
Published
04 Aug 2026
Updated

CVSS v4.0
HIGH (8.2)
EPSS
4.10%

Description

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Statistics

  • 5 Posts

Last activity: 2 hours ago

Bluesky

Profile picture fallback
N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 📖 Read more: www.helpnetsecurity.com/2026/08/10/c... #cybersecurity #cybersecuritynews #MSP #remotemanagement
  • 0
  • 0
  • 1
  • 22h ago
Profile picture fallback
Storm-1175 deployed StormEncryptor ransomware, likely using N-able Ncentral CVE-2026-18577 to bypass patches and gain access, then encrypt files and drop a ransom note.
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
📢 Storm-1175 déploie StormEncryptor, un nouveau ransomware exploitant CVE-2026-18577 📰 Source : GBHackers / Microsoft Threat Intelligence — Date de publication : 8 août 2026 🎯 Contexte général Microsoft Threat Intelligence… 🟡 vérification factuelle moyenne #Storm1175 #StormEncryptor #Cyberveille
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Former Medusa affiliate Storm-1175 is deploying StormEncryptor ransomware, likely after exploiting CVE-2026-18577 in N-central. It appends .encrypted and drops !!!README_FIRST!!!.txt, demanding payment in 3 days. #StormEncryptor #Ncentral #Medusa
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

14 Jul 2026
Published
10 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
2.33%

Description

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 17 hours ago

Fediverse

Profile picture fallback

CVE-2026-56155: The Actively Exploited AD FS Flaw That Hands Over Your Identity Keys | HackerNoon
hackernoon.com/cve-2026-56155-

Posted into Hacker Noon @hacker-noon-HackerNoon

  • 1
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
CVE-2026-56155 is an actively exploited AD FS flaw exposing token-signing keys — why patching alone isn't enough, and today's CISA deadline. #microsoftsecurity
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
CVE-2026-56155 exposes AD FS token signing and encryption keys, enabling attackers to forge trusted identities without stealing passwords or bypassing MFA.
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • SAP_SE
  • SAP NetWeaver and ABAP Platform

11 Aug 2026
Published
11 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Time to patch your Kernel...
CVSS v3.0 Base Score: 9,8 / 10

3714806 - [CVE-2026-34265] Memory Corruption vulnerability in Application Server #ABAP for #SAP NetWeaver and ABAP Platform

me.sap.com/notes/3714806

  • 1
  • 0
  • 0
  • 3h ago
Profile picture fallback

CVE-2026-34265: CRITICAL out-of-bounds write in SAP NetWeaver & ABAP Platform (CVSS 9.8) allows unauthenticated memory corruption. No patch yet — restrict access & monitor SAP advisories for updates. radar.offseq.com/threat/cve-20

  • 0
  • 1
  • 0
  • 7h ago

Overview

  • mlflow
  • mlflow/mlflow

15 May 2026
Published
15 May 2026
Updated

CVSS v3.0
HIGH (8.6)
EPSS
18.86%

KEV

Description

A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI permission middleware only enforces authentication on `/gateway/` routes, leaving other routes such as the Job API (`/ajax-api/3.0/jobs/*`) and the OpenTelemetry trace ingestion API (`/v1/traces`) unprotected. This allows unauthenticated remote attackers to submit jobs, read job results, cancel running jobs, and inject arbitrary trace data into experiments. The issue arises from an architectural mismatch between Flask and FastAPI authentication mechanisms, where the `_find_fastapi_validator()` function fails to handle non-`/gateway/` paths, resulting in a complete authentication bypass. This vulnerability is fixed in version 3.10.0.

Statistics

  • 2 Posts

Last activity: 21 hours ago

Fediverse

Profile picture fallback

🚨 In this week’s newsletter, we cover CVE-2026-2652, an authentication bypass vulnerability affecting MLflow that is seeing active exploitation.

We break down how attackers can access protected API endpoints without credentials, potentially exposing jobs and connected infrastructure, and what defenders should do next.

Read the full analysis and protect your systems 👉 crowdsec.net/vulntracking-repo

  • 0
  • 0
  • 0
  • 21h ago

Bluesky

Profile picture fallback
🚨 In this week’s newsletter, we cover CVE-2026-2652, an authentication bypass vulnerability affecting MLflow that is seeing active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Linux
  • Linux

04 Aug 2026
Published
09 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.48%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed transport (->ipaddr, ->state) and plants the dangling pointer into asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping only the pointer that is no longer on the list, removes every real transport, leaving the association with a transport_count of 0 and primary_path/active_path pointing at freed memory. Reject a DEL-IP that targets the transport the ASCONF is being processed against, mirroring the existing source-address guard, so the wildcard branch can never reuse a freed transport.

Statistics

  • 2 Posts

Last activity: 21 hours ago

Bluesky

Profile picture fallback
⚠️ 18-Year-Old Linux Kernel Vulnerability Enables Root Access and Container Escape linuxiac.com/18-year-old-... #linux #SCTPhantom #CVE202664564 #cybersecurity
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
The SCTPhantom vulnerability, CVE-2026-64564, affects Linux SCTP code and can be exploited for root access and container escape. #Linux
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • duhow
  • xiaoai-patch

10 Aug 2026
Published
10 Aug 2026
Updated

CVSS v3.1
HIGH (8.6)
EPSS
Pending

KEV

Description

A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal or external URLs. The /auth endpoint in api/main.py uses the user-supplied url POST parameter to redirect to a Home Assistant instance without validating the destination URL, enabling internal network scanning and access to internal services.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 19 hours ago

Fediverse

Profile picture fallback

CVE-2026-72581 - SSRF in duhow/xiaoai-patch lets attackers hit internal networks via Xiaomi smart speaker. CVSS 8.6. Unpatched. Block access or update once fixed. #CVE #infosec #IoT

valtersit.com/cve/CVE-2026-725

  • 1
  • 1
  • 0
  • 19h ago

Overview

  • Red Hat
  • Red Hat OpenShift AI 3.3
  • rhoai/odh-feature-server-rhel9

10 Aug 2026
Published
11 Aug 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also achieve arbitrary code execution on the registry server by bypassing authorization checks during deserialization. This vulnerability can result in cross-tenant data access and lateral movement within the system.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CVE-2026-18948: CRITICAL in RHOAI Feast — unsafe UDF deserialization allows unauth RCE on feature-server. Auth attackers can bypass auth to run code on registry-server. Mitigate by enforcing `auth.type: kubernetes`. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 5h ago

Overview

  • Linux
  • Linux

10 Aug 2026
Published
10 Aug 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is added to an empty team device. The team's delegated GRE header callback then expands the skb head. PPPoE subsequently writes six bytes through the stale pointer into the freed head. Reload the PPPoE header through the skb's network-header offset after device header creation. pskb_expand_head() updates that offset when it relocates the head.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 16 hours ago

Fediverse

Profile picture fallback

CVE-2026-68121 - Linux kernel pppoe_sendmsg() use-after-free via reallocated skb header. Potential memory corruption. CVSS N/A, unpatched. Update kernels once fixed. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-681

  • 0
  • 3
  • 0
  • 16h ago
Showing 1 to 10 of 44 CVEs