24h | 7d | 30d

Overview

  • rails
  • rails

30 Jul 2026
Published
31 Jul 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.70%

KEV

Description

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

Statistics

  • 8 Posts
  • 18 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

RE: ruby.social/@flavorjones/11700

The Rails security team published attack details and -- more importantly -- tools and agent skills to run a forensic investigation to help you determine if you were exploited. Be careful out there.

discuss.rubyonrails.org/t/cve-

  • 11
  • 7
  • 0
  • 18h ago

Bluesky

Profile picture fallback
~Akamai~ Unauthenticated RCE in Ruby on Rails Active Storage via libvips allows arbitrary file read and secret extraction. - IOCs: CVE-2026-66066 - #CVE2026 #RCE #threatintel
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Ruby on RailsのActive Storageにおけるリモートコード実行につながる脆弱性(CVE-2026-66066)に関する注意喚起 #JPCERTCC (Jul 30) www.jpcert.or.jp/at/2026/at26...
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
KindaRails2Shell(CVE-2026-66066)-Active Storage経由で認証不要のRCEが可能なRails緊急脆弱性、PoCは現時点で非公開もAI利用で数時間以内に作成可能と発見者が警告 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
[26.05] dawarich: bump rails to 8.0.5.1 to fix CVE-2026-66066 https://github.com/NixOS/nixpkgs/pull/547197 #security
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
相変わらずリスクの高い脆弱性がどんどん見つかるな。「本脆弱性が悪用された場合、遠隔の第三者が細工したファイルをアップロードすることによって、サーバー上のファイルや認証情報を読み取り、リモートコード実行に至る可能性があります。」とのこと。 Ruby on RailsのActive Storageにおけるリモートコード実行につながる脆弱性(CVE-2026-66066)に関する注意喚起 www.jpcert.or.jp/at/2026/at26...
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Ruby on RailsのActive Storageにおけるリモートコード実行につながる脆弱性(CVE-2026-66066)に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260021.html
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
~Cybergcca~ Canadian Cyber Centre issued 3 advisories covering SolarWinds SAML bypass, Rails RCE, and Google Chrome vulnerabilities. - IOCs: CVE-2026-28323, CVE-2026-66066 - #CVE2026 #ThreatIntel #VulnManagement
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • JetBrains
  • TeamCity

27 Jul 2026
Published
28 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.65%

KEV

Description

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Statistics

  • 7 Posts
  • 1 Interaction

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CRITICAL: JetBrains TeamCity On-Premises (all versions) vulnerable to CVE-2026-63077 — auth bypass enables remote code execution via HTTPS. Patch to 2025.11.7/2026.1.3 or apply plugin for 2017.1+. TeamCity Cloud unaffected. radar.offseq.com/threat/jetbra

  • 0
  • 0
  • 0
  • 19h ago

Bluesky

Profile picture fallback
CVE-2026-63077 could let unauthenticated attackers bypass TeamCity checks and run OS commands; JetBrains patched all on-premises versions.
  • 0
  • 1
  • 0
  • 1h ago
Profile picture fallback
CVE-2026-63077 enables unauthenticated HTTP/S exploitation of TeamCity On-Premises to bypass authentication and execute remote code with server privileges.
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
JetBrains disclosed CVE-2026-63077, a critical auth bypass in TeamCity On-Premises that can lead to remote code execution over HTTPS. Fixed in 2025.11.7 and 2026.1.3. #JetBrains #TeamCity #CVE-2026-63077
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
JetBrains emitiu um aviso urgente sobre uma vulnerabilidade crítica no TeamCity On-Premises que pode ser aproveitada para execução remota de código. A falha é registada sob CVE-2026-63077. #alerta #falha #teamcity
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
Critical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077) #patchmanagement
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
🚨A critical JetBrains TeamCity vulnerability CVE-2026-63077 could allow unauthenticated RCE on Internet-facing servers. Censys sees ~4,500 TeamCity web properties. ▪️No active exploitation has been reported by JetBrains. ▪️Patches are available https://bit.ly/45DhGIQ
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Cisco
  • Cisco Secure Firewall Management Center (FMC)

29 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
0.79%

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Statistics

  • 6 Posts
  • 1 Interaction

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Nutzt wer das Cisco Secure Firewall Management Center (FMC)? Da ist eine Backdoor mit festen Zugangsdaten durch Cyberkriminelle, die das ausnutzen, aufgeflogen. Patchen ist angesagt - und die FMC sollte nicht per Internet erreichbar sein.
borncity.com/blog/2026/07/30/b

  • 1
  • 0
  • 0
  • 20h ago
Profile picture fallback

Critical advisory: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to hard-coded credential abuse. Review active threat vectors, network access lockdowns, and system hardening playbooks to protect your perimeter. thecybermind.co/bkur

  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

Executive alert: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to active exploitation via hard-coded credentials. Review enterprise exposure metrics, zero-trust segmentation, and board-level risk mitigation strategies today. thecybermind.co/jily

  • 0
  • 0
  • 0
  • 6h ago

Bluesky

Profile picture fallback
Cisco FMCの脆弱性、ゼロデイ攻撃で悪用される(CVE-2026-20316) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/46948/
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Cisco FMCの静的認証情報が攻撃者によって悪用される脆弱性(CVE-2026-20316) Cisco FMC static credentials exploited by attackers (CVE-2026-20316) #HelpNetSecurity (Jul 30) www.helpnetsecurity.com/2026/07/30/c...
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Backdoor (CVE-2026-20316) in Cisco Firewall wird ausgenutzt
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

14 May 2026
Published
19 Jun 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
5.64%

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Statistics

  • 3 Posts
  • 3 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

Russian state-sponsored group Laundry Bear is actively exploiting a zero-day XSS vulnerability (CVE-2026-42897) in Exchange OWA to deploy OWAReaper backdoor. Targets include U.S. and European government entities and private sector organizations. Successful exploitation grants persistent mailbox acc…

threatnoir.com/focus

  • 1
  • 1
  • 0
  • 11h ago

Bluesky

Profile picture fallback
TA488 exploits CVE-2026-42897 in Microsoft Exchange/OWA to deliver OWAReaper, gaining persistent access and stealing credentials from unpatched systems.
  • 0
  • 1
  • 0
  • 5h ago
Profile picture fallback
Laundry Bearによる新たなMicrosoft Exchange攻撃は、メール開封時にトリガーされる(CVE-2026-42897) Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897) #HelpNetSecurity (Jul 30) www.helpnetsecurity.com/2026/07/30/c...
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • codeigniter4
  • CodeIgniter4

31 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.49%

KEV

Description

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory. Applications are impacted when they validate uploads using is_image or mime_in without an independent safe extension check (such as ext_in on patched versions), save uploaded files using the client-supplied filename, and place uploads in a web-accessible directory where PHP files can execute. This issue is fixed in version 4.7.4.

Statistics

  • 3 Posts

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CVE-2026-63223 - Critical arbitrary file upload in CodeIgniter. Bypass of is_image/mime_in validation can lead to RCE. CVSS 9.8. Update to 4.7.4 immediately. #CVE #CodeIgniter #infosec

valtersit.com/cve/CVE-2026-632

  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • ruvnet
  • ruflo

09 Jul 2026
Published
09 Jul 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.48%

KEV

Description

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns. This issue is fixed in version 3.16.3.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

CVE-2026-59726 in Ruflo AI orchestration platform allows unauthenticated remote code execution via an exposed Model Context Protocol bridge. Attackers can steal API keys, access user conversations, and corrupt AI memory without any credentials. Any organization running Ruflo is immediately exploita…

threatnoir.com/focus

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
RufRoot: The MCP Bridge Vulnerability That Turns Agents Into Rogue Admins (CVE-2026-59726) #appsec
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Adobe
  • Adobe Campaign Classic

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.54%

KEV

Description

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Statistics

  • 2 Posts

Last activity: 14 hours ago

Fediverse

Profile picture fallback

Adobe Campaign Classic flaw CVE-2026-48449 scores a perfect CVSS 10.0 and allows arbitrary code execution. Update to build 9398 now.

securityonline.info/adobe-camp

  • 0
  • 0
  • 0
  • 17h ago

Bluesky

Profile picture fallback
Adobe Campaign Classicの脆弱性CVE-2026-48449は、CVSS 10.0レベルでコード実行を可能にする Adobe Campaign Classic CVE-2026-48449 Enables Code Execution at CVSS 10.0 #DailyCyberSecurity (Jul 31) securityonline.info/adobe-campai...
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • PHP Group
  • PHP
  • ext-pgsql

30 Jul 2026
Published
31 Jul 2026
Updated

CVSS v4.0
HIGH (8.1)
EPSS
0.39%

KEV

Description

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

Statistics

  • 2 Posts

Last activity: 14 hours ago

Fediverse

Profile picture fallback

A PHP SQL injection flaw, CVE-2026-17543, was patched alongside two memory bugs. Update to PHP 8.2.33, 8.3.33, 8.4.24, or 8.5.9 now.

securityonline.info/php-sql-in

  • 0
  • 0
  • 0
  • 17h ago

Bluesky

Profile picture fallback
PHPのSQLインジェクション脆弱性CVE-2026-17543が最新リリースで修正されました PHP SQL Injection Flaw CVE-2026-17543 Patched in Latest Release #DailyCyberSecurity (Jul 31) securityonline.info/php-sql-inje...
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Microsoft
  • Azure Cosmos DB

30 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.49%

KEV

Description

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Azure Cosmos DB suffers a CRITICAL improper access control vulnerability (CVE-2026-66803) allowing unauthorized remote code execution. No patch yet — restrict network access & monitor Microsoft advisories. radar.offseq.com/threat/improp

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

CVE-2026-66803 - Critical improper access control in Azure Cosmos DB allows remote code execution. CVSS 10. No patch yet - apply mitigations immediately. #CVE #Azure #infosec

valtersit.com/cve/CVE-2026-668

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Linux
  • Linux

21 May 2026
Published
24 Jul 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.72%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ]

Statistics

  • 3 Posts
  • 11 Interactions

Last activity: 18 hours ago

Fediverse

Profile picture fallback

ICYMI, GhostLock (CVE-2026-43499) is now patched in AlmaLinux production repos for 8, 9, and 10.

Update your kernel and reboot to protect against this unprivileged local root/container escape vulnerability! almalinux.org/blog/2026-07-09-

  • 0
  • 0
  • 1
  • 19h ago
Profile picture fallback

Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.

Some interesting attacks exploiting CVE-2026-10702 are shoring up:

thehackernews.com/2026/07/rese

Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).

(Unclear if/how Firefox-ESR is affected)

#infosec

  • 4
  • 7
  • 0
  • 18h ago
Showing 1 to 10 of 50 CVEs