24h | 7d | 30d

Overview

  • Atlassian
  • Bamboo Data Center

05 Oct 2026
Published
07 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
1.76%

KEV

Description

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.

Statistics

  • 24 Posts
  • 221 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

OK, this is an innovative directory traversal vuln:
GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1

This is from CVE-2026-21589, labs.watchtowr.com/you-wont-he

The "::" gets replaced with "/" by some weird sanitation method, read more about it in the writeup.

Tagging @nynbinary for humorous memeing.

  • 103
  • 103
  • 0
  • 15h ago
Profile picture fallback

Daily Briefing: Church Cyberattacks Expose Member Data, Plus 3 Stories raymondtec.com/2026/10/church-

South Korean churches investigate breaches exposing member and donation data. Plus a critical Atlassian flaw, FICO layoffs, and Google’s new nuclear-power deal.

#TechNews #ArtificialIntelligenceAI #Atlassian #CVE202621589 #databreach #DataCenters #FICO

  • 1
  • 0
  • 0
  • 10h ago
Profile picture fallback

Recent developments include the US evacuating B-1 bombers from the UK due to an Iranian threat, while Hamas is reportedly plotting attacks in Gaza for October 7th. In cybersecurity, ASOS experienced a cloud breach via its Snowflake platform, and active exploitation of a critical Atlassian flaw (CVE-2026-21589) has begun. An FBI breach was also linked to a contractor error. Microsoft is hosting an AI-focused Surface event today.

#Cybersecurity #Geopolitics #TechNews

  • 1
  • 0
  • 0
  • 5h ago
Profile picture fallback

CVE-2026-21589 exploitation is underway against Atlassian servers after researchers published arbitrary file read PoC and technical details.

securityonline.info/cve-2026-2

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

Atlassian disclosed CVE-2026-21589 on Oct. 5, a critical flaw (CVSS 9.3) affecting eight self-hosted Data Center products that lets an unauthenticated attacker read specific files in each product’s web application root. The attacker must already know a file’s exact name and path and cannot list directory contents, The Hacker News reports. thehackernews.com/2026/10/crit

  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

Atlassian Data Center flaw draws exploitation attempts within two hours of public details

Attackers began attempting to exploit the critical Atlassian Data Center flaw (CVE-2026-21589) within two hours of public details emerging, The Hacker News reports. The rapid move from disclosure to exploitation attempts shows how fast the patching window is closing. thehackernews.com/2026/10/atla

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

An unauthenticated attacker can exploit CVE-2026-21589 to access specific files in the application's web root directory if they know the file's exact name and path. bleepingcomputer.com/news/secu

  • 0
  • 0
  • 1
  • 7h ago
Profile picture fallback

🚨 Rapid Response: CVE-2026-21589 (CVSS 9.3) is a critical arbitrary file access vulnerability affecting eight Atlassian Data Center products, including Confluence, Jira, Bitbucket, and Bamboo.

Censys currently detects 95,366 Internet-facing hosts and 431,502 web properties running affected products after excluding assets labeled as honeypots. This is product exposure, not a confirmed-vulnerable count.
Atlassian has released fixes for all eight products.

Full Censys ARC advisory: censys.com/advisory/cve-2026-2

  • 0
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication.
  • 1
  • 5
  • 0
  • 8h ago
Profile picture fallback
~Akamai~ Unauthenticated path traversal lets attackers read files and credentials; patch self-hosted products immediately. - IOCs: CVE-2026-21589, 3000990 v1 - #Atlassian #CVE202621589 #ThreatIntel
  • 0
  • 2
  • 0
  • 1h ago
Profile picture fallback
CVE-2026-21589 is a critical unauthenticated arbitrary file access flaw in multiple Atlassian Data Center products, requiring immediate patching or isolation.
  • 0
  • 1
  • 0
  • 19h ago
Profile picture fallback
This is from CVE-2026-21589, https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/ The "::" gets replaced with "/" by some weird sanitation method, read more about it in the writeup. [2/3]
  • 0
  • 1
  • 0
  • 14h ago
Profile picture fallback
CVE-2026-21589 enables unauthenticated arbitrary file access in multiple Atlassian Data Center products, requiring exact file paths and fixed by specific version patches.
  • 0
  • 1
  • 1
  • 14h ago
Profile picture fallback
~Certeu~ Unauthenticated attackers can access known files; patch internet-facing systems urgently. - IOCs: CVE-2026-21589 - #Atlassian #CVE202621589 #ThreatIntel
  • 0
  • 1
  • 0
  • 8h ago
Profile picture fallback
Using #Atlassian products like #Confluence, #Jira or #Bitbucket on-premise? Critical vulnerability CVE-2026-21589 (CVSS 9.3) lets unauthenticated attackers read known web-root files across 8 Atlassian products. Patch affected self-hosted instances now! 👇
  • 0
  • 0
  • 1
  • 23h ago
Profile picture fallback
Atlassian CVE-2026-21589 Flaw Exposes Files in Jira and Confluence Data Center https://gbhackers.com/atlassian-cve-2026-21589-flaw/
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
Atlassian: CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products URL: confluence.atlassian.com/security/cve... Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv4.0: 9.3
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589) (Atlassian、Data Center製品の重大なファイルアクセス脆弱性に即時対応を要請) #HelpNetSecurity (Oct 6) www.helpnetsecurity.com/2026/10/06/a...
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Threat actors are exploiting CVE-2026-21589 to gain arbitrary file access in multiple Atlassian Data Center products, prompting patches and mitigations.
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
Scans for Atlassian vulnerablity (CVE-2026-21589) https://isc.sans.edu/diary/33406
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
~Cybergcca~ Seven advisories issued; Atlassian CVE-2026-21589 is actively exploited. - IOCs: CVE-2026-21589, CVE-2026-59346, CVE-2026-59347 - #CVE #CyberSecurity #ThreatIntel
  • 0
  • 1
  • 0
  • 5h ago

Overview

  • SonicWall
  • SMA1000

07 Oct 2026
Published
07 Oct 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

Statistics

  • 10 Posts
  • 11 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Chat, is it bad if your zero-trust VPN device forwards network requests without auth? Asking for thousands of friends.

SonicWall SMA1000 devices have a SSRF vulnerability that needs patching.

ifin.network/t/cve-2026-102255

  • 5
  • 6
  • 0
  • 2h ago
Profile picture fallback

SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)

SonicWall has patched four vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances, including CVE-2026-102255, which could let remote unauthenticated attackers direct the appliance to issue requests on their behalf and perform unauthorized operations. The vendor says there is currently no evidence of in-the-wild exploitation, but attackers' track record with similar flaws suggests it could come soon. helpnetsecurity.com/2026/10/07

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. bleepingcomputer.com/news/secu

  • 0
  • 0
  • 1
  • 8h ago
Profile picture fallback
SonicWall patched a CVSS 10 pre-auth SSRF flaw in SMA1000 appliances that could let unauthenticated attackers reach internal functions. SonicWall released hotfixes for four vulnerabilities in its SMA1000 remote access appliances, including a critical flaw tracked as CVE-2026-102255 (CVSS score of 10.0. The issue is a pre-authentication SSRF bug in the WorkPlace portal that could […]
SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback

🚨 Rapid Response: SonicWall has patched a critical CVSS 10.0 pre-authentication SSRF in SMA1000 appliances (CVE-2026-102255).

Censys detects 5,966 Internet-exposed hosts and 39,310 web properties running SMA1000/Secure Mobile Access after excluding honeypot-labeled systems. This indicates product presence, not confirmed-vulnerable systems.

Full Censys ARC advisory: censys.com/advisory/cve-2026-1

  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
SonicWall SMA1000 Vulnerability CVE-2026-102255: Critical Pre-Auth SSRF Flaw (SonicWall SMA1000にCVSS 10.0の重大な脆弱性、認証なしで内部機能へのアクセスが可能) #SecurityOnline (Oct 7) securityonline.info/sonicwall-sm...
  • 0
  • 0
  • 1
  • 14h ago
Profile picture fallback
SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255) 📖 Read more: www.helpnetsecurity.com/2026/10/07/s... #cybersecurity #cybersecuritynews #enterprise #MSP #securityupdate #vulnerability
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
SonicWall warns of max severity SSRF flaw in SMA1000 gateways - https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/ CVE-2026-102255対象のSMA1000シリーズアプライアンス、日本にも12台見えてるのか
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

02 Oct 2026
Published
07 Oct 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.50%

KEV

Description

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Statistics

  • 7 Posts

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

Microsoft has released out-of-band security updates for Exchange Server to fix CVE-2026-96940, a high-severity (CVSS 8.8) weak authorization flaw that can let an authenticated attacker gain higher privileges. Microsoft assesses exploitation as more likely, SecurityAffairs reports. securityaffairs.com/200476/sec

  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

Microsoft Exchange : la faille CVE-2026-96940 permet de lire les boîtes aux lettres des autres utilisateurs it-connect.fr/exchange-server- #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)(Exchange Serverの緊急アップデート、他ユーザーのメール閲覧につながる高深刻度脆弱性を修正) #HelpNetSecurity (Oct 5) www.helpnetsecurity.com/2026/10/05/e...
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely https://securityaffairs.com/200476/security/cve-2026-96940-microsoft-fixes-high-severity-exchange-server-flaw.html
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely (MicrosoftがExchange Serverの高深刻度脆弱性を緊急修正、悪用可能性「高い」と評価) #SecurityAffairs (Oct 6) securityaffairs.com/200476/secur...
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
📢 [VULN] Microsoft Exchange : la faille CVE-2026-96940 permet de lire les boîtes aux lettres des autres utilisateurs Microsoft vient de publier, en dehors de son calendrier habituel, un correctif pour une faille de sécurité Exchange Server qui permet à un utilisat… #Vulnérabilité #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Exchange Server : la CVE-2026-96940 (CVSS 8,8) permet à un utilisateur authentifié de lire les e-mails de ses collègues. Microsoft a publié un correctif hors bande, Exchange Online est déjà protégé. Pour les serveurs sur site, versions et KB ici : www.it-connect.fr/exchange-ser...
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.08%

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Statistics

  • 5 Posts
  • 3 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

eSentire tracks four clusters behind CVE-2026-88771 exploitation, planting NetScaler web shells and backdoor accounts. Learn how to detect them.

securityonline.info/cve-2026-8

  • 1
  • 0
  • 0
  • 8h ago
Profile picture fallback

@pndc Perl is back... well at least in some circles -> labs.watchtowr.com/oh-look-the (also a very funny read aside from the perl reference)

Jokes aside, good luck with the interview

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
~Malpedia~ Autonomous C2 mass-exploits vulnerable NetScaler devices for root access and agent deployment. - IOCs: 45[.]143[.]130[.]195, /tmp/[.]nsagent, /s/ - #CVE202688771 #Malware #ThreatIntel
  • 0
  • 1
  • 0
  • 5h ago
Profile picture fallback
CVE-2026-88771: Citrix NetScaler Zero-Day Attack Clusters
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
~Asec~ Attackers exploited perimeter devices, poisoned packages, and hijacked identity sessions for persistence and expansion. - IOCs: CVE-2026-88771, CVE-2026-88772, CVE-2026-20079 - #IdentityAttack #SupplyChain #ThreatIntel #WebShell
  • 0
  • 1
  • 0
  • 17h ago

Overview

  • NetScaler
  • ADC

04 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.59%

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 13 hours ago

Fediverse

Profile picture fallback

Vorfall-Lagebild: Citrix NetScaler: Zero-Day CVE-2026-88779 wird aktiv

Nach 24 Stunden: was bekannt ist, was offen ist und was wahrscheinlich passiert ist – Citrix NetScaler: Zero-Day CVE-2026-88779 wird aktiv ausgenutzt – SAML-G


ot-cyber.de/blog/vorfall-lageb

  • 1
  • 0
  • 0
  • 16h ago
Profile picture fallback

Citrix reveals CVE-2026-88779, a critical memory overflow flaw in NetScaler SAML configurations leading to DoS, following recent RCE zero-day attacks.

meterpreter.org/citrix-netscal

  • 0
  • 1
  • 0
  • 13h ago

Bluesky

Profile picture fallback
The latest update for #Sophos includes "Understanding Asymmetric Routing Risks in Modern Firewall Deployments" and "Citrix NetScaler vulnerability (CVE-2026-88779) in active exploitation". #cybersecurity #antivirus #malware https://opsmtrs.com/487u2e2
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Dell
  • System Update

06 Oct 2026
Published
06 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
0.63%

KEV

Description

Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends customers upgrade at the earliest opportunity.

Statistics

  • 3 Posts

Last activity: 12 hours ago

Fediverse

Profile picture fallback

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell is urging customers to patch a critical flaw (CVE-2026-86360, CVSS 9.6) in its System Update (DSU) tool, warning the path traversal vulnerability can let attackers run code as root. Affected PowerEdge systems should be patched as soon as possible, SecurityAffairs reports. securityaffairs.com/200458/sec

  • 0
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
Dell System Updateに重大な脆弱性CVE-2026-86360、未認証の攻撃者がroot権限でコード実行の可能性 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) (Dell System Updateの重大な脆弱性、攻撃者がroot権限を取得可能) #HelpNetSecurity (Oct 6) www.helpnetsecurity.com/2026/10/06/d...
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Veeam
  • Backup and Replication

07 Oct 2026
Published
07 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.36%

KEV

Description

This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.

Statistics

  • 2 Posts
  • 6 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 from 10/6

CVE-2025-64393 (9.4 critical) low-privileged RCE

veeam.com/kb4934

  • 3
  • 3
  • 0
  • 4h ago

Bluesky

Profile picture fallback
Veeam Backup & Replication Vulnerability: Critical RCE Flaw CVE-2025-64393 (Veeam Backup & Replicationに重大なRCE脆弱性、低権限ユーザーからバックアップサーバー侵害の恐れ) #SecurityOnline (Oct 7) securityonline.info/veeam-backup...
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • The Document Foundation
  • LibreOffice

05 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
HIGH (8.5)
EPSS
0.14%

KEV

Description

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.

Statistics

  • 2 Posts

Last activity: 11 hours ago

Fediverse

Profile picture fallback

A Locally exploitable vunerability in older versions of LibreOffice Calc is being Hyped.
Claims are LO is unsafe to use.

NOT TRUE, keep LibreOffice updated please read.

cvetodo.com/cve/CVE-2026-63277

Update to version 26.2.5 or newer as soon as possible.

Configure LibreOffice to disable or restrict external data source links, especially those referencing remote locations.

Educate users, your kids to avoid opening untrusted documents.

Difficult as kids and students may receive docs from schools.

  • 0
  • 0
  • 0
  • 14h ago

Bluesky

Profile picture fallback
LibreOffice e OpenOffice: un foglio Calc può eseguire codice senza avviso macro LibreOffice corregge CVE-2026-63277, una falla JDBC che permet... https://www.ilsoftware.it/libreoffice-e-openoffice-un-foglio-calc-puo-eseguire-codice-senza-avviso-macro/
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Google
  • Chrome

06 Oct 2026
Published
07 Oct 2026
Updated

CVSS
Pending
EPSS
0.35%

KEV

Description

Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Chrome 155 patches 247 vulnerabilities, including 4 CRITICAL use-after-free bugs (CVE-2026-106382, - 106197, - 106358, - 106347) across Chromecast, Browser, Navigation & Track. Update on Windows, macOS & Linux. No active exploits. radar.offseq.com/threat/chrome

  • 1
  • 0
  • 0
  • 9h ago
Profile picture fallback

The Chrome 155 security update fixes 247 flaws, including critical use after free bugs CVE-2026-106382 and CVE-2026-106197. Update now.

securityonline.info/chrome-155

  • 1
  • 0
  • 0
  • 19h ago

Overview

  • ASUS
  • Router

07 Oct 2026
Published
07 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.32%

KEV

Description

Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

Statistics

  • 2 Posts

Last activity: 15 hours ago

Fediverse

Profile picture fallback

ASUS Router XSS (CVE-2026-14911, CRITICAL, CVSS 9.3): Remote attackers can exploit improper input neutralization to execute scripts, alter settings, or cause DoS if visited by authenticated users. No patch yet. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

Four ASUS router vulnerabilities are fixed, including critical XSS flaw CVE-2026-14911 and code execution bug CVE-2026-19386. Update firmware now.

securityonline.info/asus-route

  • 0
  • 0
  • 0
  • 18h ago
Showing 1 to 10 of 74 CVEs