24h | 7d | 30d

Overview

  • GitLab
  • GitLab

12 Sep 2026
Published
12 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
11.12%

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Statistics

  • 11 Posts
  • 3 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Recent reports confirm a critical GitLab zero-day (CVE-2026-85706) exploited within 24 hours, alongside new EU Cyber Resilience Act mandates for 24-hour vulnerability reporting. Operational technology (OT) sectors face emerging ransomware threats. Meanwhile, leading AI developers advocate for a slowdown in development due to safety concerns, prompting market shifts. Geopolitically, the BRICS summit addressed rising global tensions and the "weaponization of technology."

#Cybersecurity #TechNews #Geopolitics

  • 0
  • 1
  • 0
  • 23h ago
Profile picture fallback

CRITICAL CISA KEV ALERT: CVE-2026-85706 targets GitLab CE/EE via path traversal in the repository commits API. Active exploitation verified. Access our TSUITE brief for SIEM detection queries and compensating controls to protect your CI/CD pipeline and isolate your secrets.

thecybermind.co/pcid

  • 0
  • 1
  • 0
  • 13h ago
Profile picture fallback

⚠️GitLab : CVE-2026-85706 est activement exploitée.

Une faille critique de traversée de répertoires permet à un attaquant non authentifié de lire des fichiers arbitraires sur le serveur.

Encore une vulnérabilité qui prend des chemins de traverse…
../../../../etc/ :dumpster_fire_gif: 👀

-->GitLab auto-hébergé exposé sur Internet : mise à jour rapide recommandée.

Correctifs : 19.1.8, 19.2.6 et 19.3.2.

La faille a déjà rejoint le catalogue KEV de la CISA, et ça commence clairement à renifler autour : watchTowr et plusieurs honeypots ont déjà vu passer des tentatives de probing.

Onyphe recense une bonne centaine d’instances vulnérables en CH aujourd'hui...

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

「パッチ適用後数日で、GitLabの完璧なバグが攻撃を受ける
/CISAは、WatchTowerがインターネットに接続されたサーバーを攻撃する悪意のある人物を発見したことから、攻撃が活発に行われていることを確認した。 」: #TheRegister

「CISAによると、攻撃者はGitLabの深刻な脆弱性を悪用しており、認証されていない悪意のある人物が脆弱なサーバーから任意のファイルを読み取ることができるようになっている。これは、GitLabが9月10日に修正プログラムをリリースした後も続いている。

米国サイバーセキュリティ・インフラストラクチャセキュリティ庁は、 既知の悪用された脆弱性カタログにCVE-2026-85706を追加しました 。

この脆弱性は、リポジトリのコミットAPIにおけるパストラバーサル攻撃のバグであり、GitLab Community EditionとEnterprise Editionの両方に影響します。」

theregister.com/security/2026/

#prattohome

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
🚨 Критическая уязвимость CVE-2026-85706 в GitLab! 🚨 Неаутентифицированный доступ к файлам, включая приватные ключи криптопроектов. Риск: компрометация исходников смарт-контрактов, API-токенов. Обновите GitLab до 19.1.8, 19.2.6 или 19.3.2! #GitLab #крипто #безопасность
  • 0
  • 1
  • 0
  • 6h ago
Profile picture fallback
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours securityaffairs.com/198945/hacki...
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
GitLab sotto attacco: falla CVSS 10 legge file senza autenticazione CISA conferma lo sfruttamento di CVE-2026-85706, falla GitLab CVSS 10 che permette di leggere f... https://www.ilsoftware.it/gitlab-sotto-attacco-falla-cvss-10-legge-file-senza-login/
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
GitLabのCVE-2026-85706、公開翌日にサイバー攻撃に悪用確認 CVSS 10.0、CISA KEVへ追加 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
CVE-2026-85706 enables unauthenticated arbitrary file reads via path traversal in GitLab repository commits API, affecting self-managed CE/EE and already being probed.
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
~Checkpoint~ Breaches, AI abuse, ransomware surge, and critical actively exploited flaws demand urgent patching. - IOCs: CVE-2026-85706, CVE-2026-81963, CVE-2026-85046 - #Ransomware #ThreatIntel #Vulnerabilities
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Cisco
  • Cisco Secure Email

14 Sep 2026
Published
15 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

Description

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Statistics

  • 11 Posts
  • 8 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

ayy lmao Cisco CVE-2026-76461
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.

sec.cloudapps.cisco.com/securi

  • 3
  • 3
  • 0
  • 17h ago
Profile picture fallback

「Ciscoのセキュアメールゲートウェイの脆弱性が実際に悪用され、ルート権限でのコマンド実行が可能になる 」: #TheHackerNews

「スコは、Cisco Secure Email Gateway向けAsyncOSソフトウェアに影響を与える新たな重大な脆弱性が、実際に悪用されていると警告した。

CVE-2026-76461 として追跡されているこの脆弱性は 、CVSSスコアが10.0点満点中9.8点です。これは、メール解析ロジックにおける検証の不備が原因で、認証されていないリモート攻撃者が、基盤となるオペレーティングシステム上でroot権限で任意のコマンドを実行できる可能性があるとされています。

シスコは月曜日の勧告で、「攻撃者は、悪意のあるSQL文を含む細工された電子メールメッセージを影響を受けるデバイスに送信することで、この脆弱性を悪用する可能性がある」 と述べた 。」

thehackernews.com/2026/09/cisc

#prattohome

  • 1
  • 1
  • 0
  • 1h ago
Profile picture fallback

CRITICAL CISA KEV ALERT: CVE-2026-76461 targets Cisco Secure Email Gateway via SQL injection, granting root-level RCE. Active exploitation verified. Access our TSUITE brief for SIEM queries and hardening steps to secure your email perimeter.

thecybermind.co/al1f

  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

No one else seems to have noticed the Cisco exploited zero-day:

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability

cisa.gov/news-events/alerts/20

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

CVE-2026-76461 (CVSS 9.8) is a Cisco Secure Email Gateway vulnerability exploited in the wild. SQL injection grants root command execution. Patch now.

securityonline.info/cve-2026-7

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

CRITICAL (CVSS 9.8): CVE-2026-76461 in Cisco AsyncOS for Secure Email Gateway lets unauthenticated attackers execute commands as root via crafted emails. Patch status unknown — monitor Cisco’s updates. radar.offseq.com/threat/a-vuln

  • 0
  • 0
  • 0
  • 6h ago

Bluesky

Profile picture fallback
~Cisa~ CISA added an actively exploited Cisco Secure Email Gateway SQL injection flaw to its KEV Catalog. - IOCs: CVE-2026-76461 - #CVE-2026-76461 #Cisco #ThreatIntel
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
CVE-2026-76461 in Cisco Secure Email Gateway AsyncOS is a remotely exploitable, unauthenticated root-command zero-day actively used in attacks.
  • 0
  • 0
  • 1
  • 4h ago
Profile picture fallback
Cisco Secure Email GatewayにおけるSQLインジェクションの脆弱性(CVE-2026-76461)に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260027.html
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
📢 [VULN] ⚠️Injection SQL exploitée dans Cisco Secure Email Gateway - CVE-2026-76461 Le 14 septembre 2026 à 16 h 00 UTC, Cisco a publié deux avis de sécurité sur sa passerelle de messagerie. #CVE #Cyberveille
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Microsoft
  • Windows 10 Version 1607

11 Aug 2026
Published
14 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.38%

KEV

Description

Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.

Statistics

  • 1 Post
  • 64 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback

Microsoft today released an out of band update that includes a security update to a vulnerability they first patched in August. I guess the first patch didn't work broadly enough or introduced more flaws (or both). According to MS, though, there aren't any signs this vulnerability is actively being exploited. MS just says "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix."

support.microsoft.com/en-us/se

msrc.microsoft.com/update-guid

  • 26
  • 38
  • 0
  • 12h ago

Overview

  • vitejs
  • vite

07 Apr 2026
Published
17 Aug 2026
Updated

CVSS v4.0
HIGH (8.2)
EPSS
2.00%

KEV

Description

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.

Statistics

  • 2 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

The Vite development server vulnerability CVE-2026-39364 is exploited in mass scanning for credential harvesting. F5 Labs logged 32,000 events. Patch now.

securityonline.info/vite-cve-2

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

「ハッカーがViteの開発サーバーを標的にAWSとAzureの機密情報を盗み出す 」: #BLEEPINGCOMPUTER

「インターネットに公開されているVite開発サーバーを標的とした大規模なスキャンキャンペーンが、AWSおよびAzure環境からクラウド認証情報と設定を盗み出そうとしている。

この攻撃は、Vite バージョン 7.1.0 から 7.3.2、および 8.x ブランチの 8.0.5 より前のバージョンにおいて、ファイルの読み取り/アクセス制御を回避できる深刻な脆弱性である CVE-2026-39364 を悪用するものです。

この脆弱性は4月7日に公表され、認証されていない攻撃者がHTTP GETリクエストのクエリパラメータを操作することで、セキュリティ制限を回避し、通常はアクセスできないはずの場所から平文のファイルを取得できるというものである。」

bleepingcomputer.com/news/secu

#prattohome

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • stellarwp
  • The Events Calendar

12 Sep 2026
Published
14 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.78%

KEV

Description

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execute code on the server. This is exploitable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that allows an unauthenticated commenter to immediately view their own pending comment, delivering the injected block markup to the vulnerable code path before any moderation occurs. This does require comments to be enabled and visible on events.

Statistics

  • 2 Posts

Last activity: 5 hours ago

Fediverse

Profile picture fallback

A critical The Events Calendar vulnerability is exploited in the wild. Patch The Events Calendar vulnerability now to stop remote code execution.

securityonline.info/the-events

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-78006) The Events Calendar Remote Code Execution via #PHP Object Injection" and "Introducing the CyCognito MCP Server: Full Exposure Context, On Demand". #cybersecurity #AttackSurfaceManagement #EASM https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Gitea
  • Gitea

26 Aug 2026
Published
08 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
86.78%

Description

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Statistics

  • 2 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

A critical Gitea RCE vulnerability exploited in wild attacks exposes servers. Patch this Gitea RCE vulnerability now to prevent full system compromise.

securityonline.info/gitea-rce-

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
Acronis TRU uncovered a multinational campaign in which Red Heron, a Chinese-speaking threat actor, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. www.acronis.com/en/tru/posts...
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts

Last activity: 1 hour ago

Bluesky

Profile picture fallback
CVE-2026-51990 in Sogou Input Method enables a one-click exploit that injects command-line arguments and uses an outdated, unsandboxed Chromium engine to execute system-level code.
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
中国系アクターがTencent製ソフトの重大な欠陥を悪用し、バックドア「GrayRabbit」を展開(CVE-2026-51990) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47725/
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Adobe
  • Adobe Commerce

07 Sep 2026
Published
09 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
2.15%

Description

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Statistics

  • 2 Posts

Last activity: 17 hours ago

Bluesky

Profile picture fallback
🚨 This week’s Threat Alert covers CVE-2026-75650 (StyleSmuggler), a critical RCE affecting Adobe Commerce & Magento. Exploited before the patch, it escalated to mass scanning, with 500+ IPs observed. Read the full analysis and protection recommendations: www.crowdsec.net/vulntracking...
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
~Akamai~ Unauthenticated RCE in Adobe Commerce/Magento is actively exploited; patch APSB26-146. - IOCs: CVE-2026-75650, StyleSmuggler - #CVE202675650 #RCE #ThreatIntel
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • crawlab-team
  • crawlab

14 Sep 2026
Published
14 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.

Statistics

  • 1 Post
  • 11 Interactions

Last activity: 14 hours ago

Fediverse

Profile picture fallback

Go fuck with some crawlers.

nvd.nist.gov/vuln/detail/cve-2

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.

  • 4
  • 7
  • 0
  • 14h ago

Overview

  • jfrog
  • artifactory

28 Aug 2026
Published
03 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
7.67%

Description

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Statistics

  • 3 Posts

Last activity: 12 hours ago

Fediverse

Profile picture fallback

Attackers are chaining three JFrog Artifactory bugs to plant admin backdoors 

Multiple threat actors have been chaining three JFrog Artifactory vulnerabilities, CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329, in active exploitation confirmed between August 15 and September 8, using two of the bugs together to extract an anonymous-user token and escalate it to admin privileges, or…

itnerd.blog/2026/09/14/attacke

  • 0
  • 0
  • 1
  • 12h ago

Bluesky

Profile picture fallback
Another excellent writeup by my colleague Nate Robb, this one analyzing an auth bypass affecting JFrog Artifactory (CVE-2026-82329)! bishopfox.com/blog/cve-202...
  • 0
  • 0
  • 0
  • 23h ago
Showing 1 to 10 of 84 CVEs