24h | 7d | 30d

Overview

  • Cisco
  • Cisco Secure Firewall Management Center (FMC)

04 Mar 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
35.95%

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

Statistics

  • 11 Posts
  • 14 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Cisco Talos warns of Cisco FMC vulnerabilities actively exploited in the wild. Attackers chain CVE-2026-20079 and CVE-2026-20316 to deploy ransomware.

securityonline.info/cisco-fmc-

  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by threat actors deploying malware, web shells, and ransomware. Customers are strongly urged to apply security patches immediately to prevent unauthorized access and potential compromise.
blog.talosintelligence.com/fmc

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks.
  • 5
  • 6
  • 1
  • 11h ago
Profile picture fallback
Cisco confirms CVE-2026-20079, a CVSS 10 unauthenticated auth bypass in Secure FMC, is exploited in the wild. No workaround; patch only. CISA added it to KEV, federal deadline Sept 12. Cisco's exploitation timeline conflicts with earlier IOC disclosure.
  • 0
  • 2
  • 0
  • 8h ago
Profile picture fallback
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks(Cisco、Secure FMCの重大脆弱性CVE-2026-20079が攻撃で悪用されていることを確認) #BleepingComputer (Sep 9) www.bleepingcomputer.com/news/securit...
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
Cisco confirms active exploitation of CVE-2026-20079, a max-severity auth bypass in Secure FMC that can grant root via crafted HTTP requests. Affects Secure Firewall Management Center and Security Cloud Control Firewall Management. #Cisco
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
シスコ、Secure FMCの脆弱性CVE-2026-20079が攻撃で悪用されたことを確認 | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47674/
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
@talosintelligence.com Attackers exploit Cisco FMC flaws for root access, Cyclops Blink, and Qilin ransomware. - IOCs: 89[.]34[.]96[.]56, 208[.]123[.]119[.]215, 104[.]218[.]165[.]253 - #CVE202620079 #CVE202620316 #ThreatIntel
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Google
  • Chrome

09 Sep 2026
Published
10 Sep 2026
Updated

CVSS
Pending
EPSS
0.29%

Description

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Statistics

  • 10 Posts
  • 8 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

Google Chrome

Google is aware that an exploit for CVE-2026-87491 exists in the wild.

chromereleases.googleblog.com/

  • 2
  • 1
  • 0
  • 20h ago
Profile picture fallback

The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. thehackernews.com/2026/09/chro

  • 0
  • 0
  • 1
  • 20h ago
Profile picture fallback

⚠️ CRITICAL: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google patched CVE-2026-87491, a zero-day out-of-bounds write in Chrome's V8 engine actively exploited in the wild. Attackers can execute arbitrary code within the browser sandbox via crafted HTML, potentially compromising any user visiting a malicious page. This is the seventh exploited Chrome zer…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

Earlier this month, @volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). Volexity observed threat actors it tracks as UTA0560 and JungleBamboo using variations of the same exploits to deliver different malware implants. These implants ranged from a JScript backdoor (GRIMWEDGE) to a fake Google Gemini Chrome extension (LONGTALE).

Read the full analysis of the exploit chain and post-exploitation tradecraft here: volexity.com/blog/2026/09/09/m
 

  • 3
  • 2
  • 0
  • 15h ago

Bluesky

Profile picture fallback
Google patched 230 security vulnerabilities in Chrome, including CVE-2026-87491, an actively exploited V8 out-of-bounds bug enabling sandbox escape and arbitrary code execution.
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Chrome 153 stable patches 230 vulnerabilities, including exploited zero-day CVE-2026-87491, and addresses multiple critical and high-severity issues across V8, WebGL, and Cast.
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Chrome zero-day CVE-2026-87491 in V8 is being exploited in the wild. Google fixed 230 Chrome flaws, including critical WebGL and Cast bugs. #Chrome #V8 #WebGL
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Chrome 153, falla zero-day già sfruttata: bisogna aggiornare subito Google corregge CVE-2026-87491 in Chrome 153: lo zero-day colpisce V8 ed è già sfruttato in attacchi real... https://www.ilsoftware.it/chrome-153-chiude-zero-day-usato-negli-attacchi/
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
~Cisa~ CISA added four actively exploited Fortinet, Citrix, Chromium, and Cisco vulnerabilities to its KEV Catalog. - IOCs: CVE-2025-25249, CVE-2026-19490, CVE-2026-87491 - #CVE #Cybersecurity #ThreatIntel
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • WebPros
  • cPanel

09 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.0
CRITICAL (9.9)
EPSS
Pending

KEV

Description

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

Statistics

  • 6 Posts
  • 4 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

I can't imagine trying to manage cPanel on the public Internet in 2026, especially on shared systems.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

  • 0
  • 4
  • 0
  • 14h ago
Profile picture fallback

Critical cPanel Vulnerability (CVE-2026-67401): How an EmailTrack SQL Injection Grants Root Access

A critical cPanel EmailTrack SQL injection vulnerability, CVE-2026-67401, can allow authenticated attackers to escalate to root and take over an entire hosting server

thecybersecguru.com/news/cve-2

  • 0
  • 0
  • 0
  • 19h ago

Bluesky

Profile picture fallback
cPanel Fixes Critical Flaw That Could Give Attackers Root Access cPanel has patched CVE-2026-67401, a security flaw that could allow an authenticated hosting account to create files and execute code as root on affected servers.
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
cPanel patched CVE-2026-67401 in EmailTrack, where a mail-privileged account could create files and potentially escalate to root on affected servers. Fixed builds are available across supported release lines. #cPanel #WHM #CVE202667401
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
cPanel EmailTrack CVE-2026-67401 Scanner / Mitigation https://packetstorm.news/files/230936
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
cPanel & WHMのEmailTrackにSQLインジェクション脆弱性「CVE-2026-67401」、root権限でコード実行のおそれ rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Microsoft
  • Microsoft Malware Protection Engine

14 Aug 2026
Published
09 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.56%

KEV

Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".

Statistics

  • 4 Posts
  • 3 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CRITICAL: ShieldCrash zero-day (CVE-2026-69414) exploits Microsoft Defender on patched Windows (Sept 2026), enabling privilege escalation to System and SAM dumping. No patch yet. Monitor for Defender anomalies. radar.offseq.com/threat/new-sh

  • 0
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak. github.com/MSNightmare/... #infosec #cybersecurity #redteam #pentest #windows
  • 1
  • 2
  • 0
  • 21h ago
Profile picture fallback
ShieldCrash PoC enables arbitrary SYSTEM file read on all supported Windows desktop versions, bypassing Microsoft Defender patch for CVE-2026-69414 (ShieldBreak).
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
ShieldCrash Windows Defender CVE-2026-69414 Patch Bypass https://packetstorm.news/files/231047 #exploit
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Adobe
  • Adobe Commerce

07 Sep 2026
Published
09 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
2.15%

Description

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Statistics

  • 4 Posts
  • 2 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

Magento : la faille zero-day StyleSmuggler est corrigée, mais des boutiques sont déjà piratées it-connect.fr/magento-adobe-co #ActuCybersécurité #Cybersécurité #Vulnérabilité #Adobe

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback

CVE-2026-75650 Adobe Commerce Zero-Day: Patch Isn’t Enough esecurityplanet.com/threats/ne

  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

Critical CVE-2026-75650 alert for Adobe Commerce and Magento. Active CISA KEV exploitation requires immediate template parsing audits and endpoint hardening. Access our technical forensic brief to secure your enterprise perimeter today.

thecybermind.co/8in9

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
🚨 CVE-2026-75650 (critical-severity) affects Magento Open Source 2.4.4 through 2.4.9. Unauthenticated template injection leads to RCE, no user interaction needed. Actively exploited in the wild. Apply the VULN-39341 hotfix via Composer, no version upgrade yet. More: buff.ly/rMKge9t
  • 0
  • 2
  • 0
  • 11h ago

Overview

  • checkpoint
  • Quantum Security Gateway

09 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

Statistics

  • 4 Posts
  • 18 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback

It has been :zero_percent: days since an ASN.1 decoding vuln.

It has been :zero_percent: days since an overflow vuln in a corp VPN.

It has been :zero_percent: days since a vuln with "Quantum" in the system name.

They are all the same vuln.

nvd.nist.gov/vuln/detail/cve-2

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

  • 7
  • 9
  • 0
  • 17h ago
Profile picture fallback

CRITICAL CVE-2026-85103 in Check Point Quantum Security Gateway: Heap-based buffer overflow in VPN certificate ASN.1 decoding allows unauthenticated RCE. Patch pending — monitor vendor. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 19h ago
Profile picture fallback

Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103.

securityonline.info/checkpoint

  • 1
  • 0
  • 0
  • 18h ago
Profile picture fallback

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

community.checkpoint.com/t5/Ge

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • SAP_SE
  • SAP Extended Passport (EPP) Processing

08 Sep 2026
Published
08 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.32%

KEV

Description

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

Statistics

  • 5 Posts
  • 1 Interaction

Last activity: 17 hours ago

Fediverse

Profile picture fallback

The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP security company Onapsis, it has been codenamed OVERPASS. thehackernews.com/2026/09/sap-

  • 1
  • 0
  • 1
  • 20h ago
Profile picture fallback

SAP OVERPASS CVE-2026-44756: CVSS 10.0 Kernel RCE Explained

SAP OVERPASS CVE-2026-44756 is a CVSS 10.0 kernel flaw enabling unauthenticated RCE. Learn the attack path, S4GET risks and patching steps

thecybersecguru.com/news/sap-o

  • 0
  • 0
  • 0
  • 20h ago

Bluesky

Profile picture fallback
CVE-2026-44756 (OVERPASS) is a remotely exploitable, unauthenticated SAP kernel memory corruption flaw in EPP processing that enables arbitrary OS command execution with SAP admin privileges.
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
~Certeu~ Unauthenticated remote exploitation enables OS command execution; patch SAP Notes 3747649 and 3759472. - IOCs: CVE-2026-44756, CVE-2026-58240 - #CVE #SAP #ThreatIntel
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Palo Alto Networks
  • Cloud NGFW

10 Sep 2026
Published
10 Sep 2026
Updated

CVSS v4.0
HIGH (7.2)
EPSS
Pending

KEV

Description

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . Panorama is impacted by this vulnerability.

Statistics

  • 4 Posts
  • 25 Interactions

Last activity: 14 hours ago

Fediverse

Profile picture fallback

RE: infosec.exchange/@cR0w/1172419

Seriously, maybe take a good look at CVE-2026-0310.

CVSS-BT: 7.2 / **CVSS-B: 9.2** (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red)

  • 1
  • 0
  • 0
  • 15h ago
Profile picture fallback

A new PAN-OS buffer overflow flaw, tracked as CVE-2026-0310, exposes firewalls to remote code execution. Patch your network devices immediately.

securityonline.info/pan-os-buf

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
Paloaltoの脆弱性情報 「CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing (Severity: HIGH)」が公開されました。 → https://security.paloaltonetworks.com/CVE-2026-0310
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • F5
  • BIG-IP

15 Oct 2025
Published
31 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.21%

Description

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 8 hours ago

Bluesky

Profile picture fallback
Hackers deployed a Linux rootkit on F5 BIG-IP APM devices, keeping a web shell in memory to evade file-based detection. The campaign is linked to CVE-2025-53521 and PoisonedRefresh. #F5BIGIPAPM #CVE202553521 #PoisonedRefresh
  • 0
  • 1
  • 0
  • 20h ago
Profile picture fallback
Malware hides a PHP web shell in memory on F5 BIG-IP APM appliances, evading disk-based checks and linking activity to CVE-2025-53521.
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Sophos found F5 BIG-IP APM malware injecting a PHP web shell into memory, leaving disk files clean. Linked to CVE-2025-53521 and c05d5254, with indicators like apm_css.php3 and full_wt.php3. #F5 #BIGIPAPM #CVE202553521
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
F5 BIG-IP APM侵害後にLinuxルートキットを展開 メモリ内Webシェル PoisonedRefresh:CVE-2025-53521-Sophos-解析 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Fortinet
  • FortiSwitchManager

13 Jan 2026
Published
10 Sep 2026
Updated

CVSS v3.1
HIGH (7.4)
EPSS
0.76%

Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

Statistics

  • 3 Posts

Last activity: 2 hours ago

Bluesky

Profile picture fallback
🚨 New research from the SOCRadar Threat Research Unit! CVE-2025-25249 is being actively exploited to deploy PivotC2, a FortiGate-focused Node.js RAT. 30K+ targets. 178 confirmed infections. AI-assisted development, tunneling & autonomous post-exploitation. Read more 👇 socradar.io/blog/cve-202...
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
Threat actors exploit CVE-2025-25249 in Fortinet devices to deploy PivotC2 RAT, enabling post-exploitation capabilities and data theft, prompting urgent patching.
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
~Cisa~ CISA added four actively exploited Fortinet, Citrix, Chromium, and Cisco vulnerabilities to its KEV Catalog. - IOCs: CVE-2025-25249, CVE-2026-19490, CVE-2026-87491 - #CVE #Cybersecurity #ThreatIntel
  • 0
  • 0
  • 0
  • 12h ago
Showing 1 to 10 of 90 CVEs