24h | 7d | 30d

Overview

  • Atlassian
  • Bamboo Data Center

05 Oct 2026
Published
07 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
1.76%

KEV

Description

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.

Statistics

  • 24 Posts
  • 227 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

OK, this is an innovative directory traversal vuln:
GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1

This is from CVE-2026-21589, labs.watchtowr.com/you-wont-he

The "::" gets replaced with "/" by some weird sanitation method, read more about it in the writeup.

Tagging @nynbinary for humorous memeing.

  • 103
  • 108
  • 0
  • 20h ago
Profile picture fallback

Daily Briefing: Church Cyberattacks Expose Member Data, Plus 3 Stories raymondtec.com/2026/10/church-

South Korean churches investigate breaches exposing member and donation data. Plus a critical Atlassian flaw, FICO layoffs, and Google’s new nuclear-power deal.

#TechNews #ArtificialIntelligenceAI #Atlassian #CVE202621589 #databreach #DataCenters #FICO

  • 1
  • 0
  • 0
  • 15h ago
Profile picture fallback

Recent developments include the US evacuating B-1 bombers from the UK due to an Iranian threat, while Hamas is reportedly plotting attacks in Gaza for October 7th. In cybersecurity, ASOS experienced a cloud breach via its Snowflake platform, and active exploitation of a critical Atlassian flaw (CVE-2026-21589) has begun. An FBI breach was also linked to a contractor error. Microsoft is hosting an AI-focused Surface event today.

#Cybersecurity #Geopolitics #TechNews

  • 1
  • 0
  • 0
  • 10h ago
Profile picture fallback

CVE-2026-21589 exploitation is underway against Atlassian servers after researchers published arbitrary file read PoC and technical details.

securityonline.info/cve-2026-2

  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

Atlassian disclosed CVE-2026-21589 on Oct. 5, a critical flaw (CVSS 9.3) affecting eight self-hosted Data Center products that lets an unauthenticated attacker read specific files in each product’s web application root. The attacker must already know a file’s exact name and path and cannot list directory contents, The Hacker News reports. thehackernews.com/2026/10/crit

  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback

Atlassian Data Center flaw draws exploitation attempts within two hours of public details

Attackers began attempting to exploit the critical Atlassian Data Center flaw (CVE-2026-21589) within two hours of public details emerging, The Hacker News reports. The rapid move from disclosure to exploitation attempts shows how fast the patching window is closing. thehackernews.com/2026/10/atla

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

An unauthenticated attacker can exploit CVE-2026-21589 to access specific files in the application's web root directory if they know the file's exact name and path. bleepingcomputer.com/news/secu

  • 0
  • 0
  • 1
  • 13h ago
Profile picture fallback

🚨 Rapid Response: CVE-2026-21589 (CVSS 9.3) is a critical arbitrary file access vulnerability affecting eight Atlassian Data Center products, including Confluence, Jira, Bitbucket, and Bamboo.

Censys currently detects 95,366 Internet-facing hosts and 431,502 web properties running affected products after excluding assets labeled as honeypots. This is product exposure, not a confirmed-vulnerable count.
Atlassian has released fixes for all eight products.

Full Censys ARC advisory: censys.com/advisory/cve-2026-2

  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback

Critical Atlassian File Access Flaw Draws Attacks Across Eight Products esecurityplanet.com/news/news-

  • 0
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication.
  • 2
  • 6
  • 0
  • 14h ago
Profile picture fallback
~Akamai~ Unauthenticated path traversal lets attackers read files and credentials; patch self-hosted products immediately. - IOCs: CVE-2026-21589, 3000990 v1 - #Atlassian #CVE202621589 #ThreatIntel
  • 0
  • 2
  • 0
  • 6h ago
Profile picture fallback
This is from CVE-2026-21589, https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/ The "::" gets replaced with "/" by some weird sanitation method, read more about it in the writeup. [2/3]
  • 0
  • 1
  • 0
  • 20h ago
Profile picture fallback
CVE-2026-21589 enables unauthenticated arbitrary file access in multiple Atlassian Data Center products, requiring exact file paths and fixed by specific version patches.
  • 0
  • 1
  • 1
  • 19h ago
Profile picture fallback
~Certeu~ Unauthenticated attackers can access known files; patch internet-facing systems urgently. - IOCs: CVE-2026-21589 - #Atlassian #CVE202621589 #ThreatIntel
  • 0
  • 1
  • 0
  • 14h ago
Profile picture fallback
Atlassian CVE-2026-21589 Flaw Exposes Files in Jira and Confluence Data Center https://gbhackers.com/atlassian-cve-2026-21589-flaw/
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
Atlassian: CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products URL: confluence.atlassian.com/security/cve... Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv4.0: 9.3
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589) (Atlassian、Data Center製品の重大なファイルアクセス脆弱性に即時対応を要請) #HelpNetSecurity (Oct 6) www.helpnetsecurity.com/2026/10/06/a...
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Threat actors are exploiting CVE-2026-21589 to gain arbitrary file access in multiple Atlassian Data Center products, prompting patches and mitigations.
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Scans for Atlassian vulnerablity (CVE-2026-21589) https://isc.sans.edu/diary/33406
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
📢 CVE-2026-21589 : Lecture de fichiers arbitraire pré-auth sur Atlassian Jira, Confluence et plus Cet article présente une analyse technique approfondie de CVE-2026-21589, une vulnérabilité critique divulguée par Atlassian dans… 🟢 vérification factuelle haute #Atlassian #Confluence #Cyberveille
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
Atlassian、JiraやConfluenceなどにCVSS 9.3の脆弱性「CVE-2026-21589」―認証なしで特定ファイルへアクセス可能 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
~Cybergcca~ Seven advisories issued; Atlassian CVE-2026-21589 is actively exploited. - IOCs: CVE-2026-21589, CVE-2026-59346, CVE-2026-59347 - #CVE #CyberSecurity #ThreatIntel
  • 0
  • 1
  • 0
  • 10h ago

Overview

  • SonicWall
  • SMA1000

07 Oct 2026
Published
07 Oct 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

Statistics

  • 11 Posts
  • 15 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Chat, is it bad if your zero-trust VPN device forwards network requests without auth? Asking for thousands of friends.

SonicWall SMA1000 devices have a SSRF vulnerability that needs patching.

ifin.network/t/cve-2026-102255

  • 7
  • 8
  • 0
  • 8h ago
Profile picture fallback

SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)

SonicWall has patched four vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances, including CVE-2026-102255, which could let remote unauthenticated attackers direct the appliance to issue requests on their behalf and perform unauthorized operations. The vendor says there is currently no evidence of in-the-wild exploitation, but attackers' track record with similar flaws suggests it could come soon. helpnetsecurity.com/2026/10/07

  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. bleepingcomputer.com/news/secu

  • 0
  • 0
  • 1
  • 14h ago
Profile picture fallback
SonicWall patched a CVSS 10 pre-auth SSRF flaw in SMA1000 appliances that could let unauthenticated attackers reach internal functions. SonicWall released hotfixes for four vulnerabilities in its SMA1000 remote access appliances, including a critical flaw tracked as CVE-2026-102255 (CVSS score of 10.0. The issue is a pre-authentication SSRF bug in the WorkPlace portal that could […]
SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

🚨 Rapid Response: SonicWall has patched a critical CVSS 10.0 pre-authentication SSRF in SMA1000 appliances (CVE-2026-102255).

Censys detects 5,966 Internet-exposed hosts and 39,310 web properties running SMA1000/Secure Mobile Access after excluding honeypot-labeled systems. This indicates product presence, not confirmed-vulnerable systems.

Full Censys ARC advisory: censys.com/advisory/cve-2026-1

  • 0
  • 0
  • 1
  • 5h ago

Bluesky

Profile picture fallback
SonicWall SMA1000 Vulnerability CVE-2026-102255: Critical Pre-Auth SSRF Flaw (SonicWall SMA1000にCVSS 10.0の重大な脆弱性、認証なしで内部機能へのアクセスが可能) #SecurityOnline (Oct 7) securityonline.info/sonicwall-sm...
  • 0
  • 0
  • 1
  • 19h ago
Profile picture fallback
SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255) 📖 Read more: www.helpnetsecurity.com/2026/10/07/s... #cybersecurity #cybersecuritynews #enterprise #MSP #securityupdate #vulnerability
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
SonicWall warns of max severity SSRF flaw in SMA1000 gateways - https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/ CVE-2026-102255対象のSMA1000シリーズアプライアンス、日本にも12台見えてるのか
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

02 Oct 2026
Published
07 Oct 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.50%

KEV

Description

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Statistics

  • 6 Posts

Last activity: 15 hours ago

Fediverse

Profile picture fallback

CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

Microsoft has released out-of-band security updates for Exchange Server to fix CVE-2026-96940, a high-severity (CVSS 8.8) weak authorization flaw that can let an authenticated attacker gain higher privileges. Microsoft assesses exploitation as more likely, SecurityAffairs reports. securityaffairs.com/200476/sec

  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback

Microsoft Exchange : la faille CVE-2026-96940 permet de lire les boîtes aux lettres des autres utilisateurs it-connect.fr/exchange-server- #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft

  • 0
  • 0
  • 0
  • 17h ago

Bluesky

Profile picture fallback
CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely https://securityaffairs.com/200476/security/cve-2026-96940-microsoft-fixes-high-severity-exchange-server-flaw.html
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely (MicrosoftがExchange Serverの高深刻度脆弱性を緊急修正、悪用可能性「高い」と評価) #SecurityAffairs (Oct 6) securityaffairs.com/200476/secur...
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
📢 [VULN] Microsoft Exchange : la faille CVE-2026-96940 permet de lire les boîtes aux lettres des autres utilisateurs Microsoft vient de publier, en dehors de son calendrier habituel, un correctif pour une faille de sécurité Exchange Server qui permet à un utilisat… #Vulnérabilité #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Exchange Server : la CVE-2026-96940 (CVSS 8,8) permet à un utilisateur authentifié de lire les e-mails de ses collègues. Microsoft a publié un correctif hors bande, Exchange Online est déjà protégé. Pour les serveurs sur site, versions et KB ici : www.it-connect.fr/exchange-ser...
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.08%

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Statistics

  • 5 Posts
  • 3 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

eSentire tracks four clusters behind CVE-2026-88771 exploitation, planting NetScaler web shells and backdoor accounts. Learn how to detect them.

securityonline.info/cve-2026-8

  • 1
  • 0
  • 0
  • 13h ago
Profile picture fallback

@pndc Perl is back... well at least in some circles -> labs.watchtowr.com/oh-look-the (also a very funny read aside from the perl reference)

Jokes aside, good luck with the interview

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
~Malpedia~ Autonomous C2 mass-exploits vulnerable NetScaler devices for root access and agent deployment. - IOCs: 45[.]143[.]130[.]195, /tmp/[.]nsagent, /s/ - #CVE202688771 #Malware #ThreatIntel
  • 0
  • 1
  • 0
  • 10h ago
Profile picture fallback
CVE-2026-88771: Citrix NetScaler Zero-Day Attack Clusters
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
~Asec~ Attackers exploited perimeter devices, poisoned packages, and hijacked identity sessions for persistence and expansion. - IOCs: CVE-2026-88771, CVE-2026-88772, CVE-2026-20079 - #IdentityAttack #SupplyChain #ThreatIntel #WebShell
  • 0
  • 1
  • 0
  • 22h ago

Overview

  • NetScaler
  • ADC

04 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.59%

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 19 hours ago

Fediverse

Profile picture fallback

Vorfall-Lagebild: Citrix NetScaler: Zero-Day CVE-2026-88779 wird aktiv

Nach 24 Stunden: was bekannt ist, was offen ist und was wahrscheinlich passiert ist – Citrix NetScaler: Zero-Day CVE-2026-88779 wird aktiv ausgenutzt – SAML-G


ot-cyber.de/blog/vorfall-lageb

  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback

Citrix reveals CVE-2026-88779, a critical memory overflow flaw in NetScaler SAML configurations leading to DoS, following recent RCE zero-day attacks.

meterpreter.org/citrix-netscal

  • 0
  • 1
  • 0
  • 19h ago

Bluesky

Profile picture fallback
The latest update for #Sophos includes "Understanding Asymmetric Routing Risks in Modern Firewall Deployments" and "Citrix NetScaler vulnerability (CVE-2026-88779) in active exploitation". #cybersecurity #antivirus #malware https://opsmtrs.com/487u2e2
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • The Document Foundation
  • LibreOffice

05 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
HIGH (8.5)
EPSS
0.14%

KEV

Description

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.

Statistics

  • 3 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

A Locally exploitable vunerability in older versions of LibreOffice Calc is being Hyped.
Claims are LO is unsafe to use.

NOT TRUE, keep LibreOffice updated please read.

cvetodo.com/cve/CVE-2026-63277

Update to version 26.2.5 or newer as soon as possible.

Configure LibreOffice to disable or restrict external data source links, especially those referencing remote locations.

Educate users, your kids to avoid opening untrusted documents.

Difficult as kids and students may receive docs from schools.

  • 0
  • 0
  • 0
  • 20h ago

Bluesky

Profile picture fallback
LibreOffice e OpenOffice: un foglio Calc può eseguire codice senza avviso macro LibreOffice corregge CVE-2026-63277, una falla JDBC che permet... https://www.ilsoftware.it/libreoffice-e-openoffice-un-foglio-calc-puo-eseguire-codice-senza-avviso-macro/
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
LibreOffice Calcにコード実行の脆弱性 CVE-2026-63277―PoC公開、悪意ある表計算ファイルを開くだけでJavaコード実行の恐れ rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Veeam
  • Backup and Replication

07 Oct 2026
Published
07 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.36%

KEV

Description

This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.

Statistics

  • 2 Posts
  • 8 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 from 10/6

CVE-2025-64393 (9.4 critical) low-privileged RCE

veeam.com/kb4934

  • 4
  • 4
  • 0
  • 10h ago

Bluesky

Profile picture fallback
Veeam Backup & Replication Vulnerability: Critical RCE Flaw CVE-2025-64393 (Veeam Backup & Replicationに重大なRCE脆弱性、低権限ユーザーからバックアップサーバー侵害の恐れ) #SecurityOnline (Oct 7) securityonline.info/veeam-backup...
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Cisco
  • Cisco Finesse

07 Oct 2026
Published
07 Oct 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
Pending

KEV

Description

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated with the affected device.

Statistics

  • 2 Posts
  • 6 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

There are 14 Cisco security advisories that came out today. sec.cloudapps.cisco.com/securi

A lot of 9.8 and even 10.0 across multiple products. While there's no mention of exploitation, there's zero-day disclosure pre-patch for Cisco Finesse Server-Side Request Forgery Vulnerability CVE-2026-20362 (7.2)

The Cisco PSIRT is aware that a public announcement is available for the vulnerability that is described in this advisory.

sec.cloudapps.cisco.com/securi

  • 3
  • 3
  • 0
  • 10h ago
Profile picture fallback

A Cisco Finesse vulnerability, SSRF flaw CVE-2026-20362, has been publicly disclosed. Fixes arrive in early 2027, with no workarounds.

securityonline.info/cisco-fine

  • 0
  • 0
  • 0
  • Last hour

Overview

  • Dell
  • System Update

06 Oct 2026
Published
06 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
0.63%

KEV

Description

Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends customers upgrade at the earliest opportunity.

Statistics

  • 2 Posts

Last activity: 17 hours ago

Fediverse

Profile picture fallback

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell is urging customers to patch a critical flaw (CVE-2026-86360, CVSS 9.6) in its System Update (DSU) tool, warning the path traversal vulnerability can let attackers run code as root. Affected PowerEdge systems should be patched as soon as possible, SecurityAffairs reports. securityaffairs.com/200458/sec

  • 0
  • 0
  • 0
  • 17h ago

Bluesky

Profile picture fallback
Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) (Dell System Updateの重大な脆弱性、攻撃者がroot権限を取得可能) #HelpNetSecurity (Oct 6) www.helpnetsecurity.com/2026/10/06/d...
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Cisco
  • Cisco NX-OS Software

07 Oct 2026
Published
07 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes resulting in a reload and DoS condition.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CVE-2026-76485: CRITICAL (CVSS 9.8) vulnerability in Cisco NX-OS NGOAM allows remote code execution or DoS via crafted packets. Disable NGOAM if unused. Awaiting official patch. Details: radar.offseq.com/threat/a-vuln

  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback

Four critical Cisco Nexus vulnerabilities, including CVE-2026-76485 and CVE-2026-76465 (CVSS 9.8), allow root RCE on NX-OS switches. Patch now.

securityonline.info/cisco-nexu

  • 0
  • 1
  • 0
  • 9h ago
Showing 1 to 10 of 70 CVEs