Overview
Description
Statistics
- 2 Posts
- 11 Interactions
Fediverse
Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.
Some interesting attacks exploiting CVE-2026-10702 are shoring up:
https://thehackernews.com/2026/07/researchers-show-single-malicious.html?m=1
Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).
(Unclear if/how Firefox-ESR is affected)
Overview
- SolarWinds
- Web Help Desk
Description
Statistics
- 2 Posts
Fediverse
A SolarWinds Web Help Desk SAML authentication bypass, CVE-2026-28323, scores a critical CVSS 9.8. Update to 2026.2.1 to stay protected.
Overview
- codeigniter4
- CodeIgniter4
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-63222 - Path traversal in CodeIgniter. UploadedFile::move() unsanitized filename lets attackers write outside intended directory. CVSS 7.5. Update to 4.7.4 immediately. #CVE #CodeIgniter #infosec
So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.
Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)
Did people still use CodeIgniter?
Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.
Overview
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
Chrome CVE Report for the 2026-07-29 Stable channel: https://tbljrmp60k.joplinusercontent.com/shares/mIyA83WXtKANql5AEUYqwx
Top vulnerability types: Inappropriate Implementation (34.5%), Insufficient Input Validation (19%), Use After Free (13.4%)
Most affected components: XR (36), Chrome for iOS (35), Input Handling (33), ANGLE Graphics (30)
Largest bounty: $36,000 β CVE-2026-17657 (Use after free in Navigation)
Overview
- Phoenix Contact
- CHARX SEC-3150
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
π¨ A Cobalt Strike BOF targeting CVE-2026-49176 adds another exploitation method for the CVSS 7.8 Windows WalletService local privilege escalation vulnerability.
GitHub: https://github.com/777erp/CVE-2026-49176_BOF
The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.
Overview
- Toptech Systems
- RCU II+
Description
Statistics
- 1 Post
Fediverse
CVE-2026-12562 β Unauthenticated TCF debug interface in Phoenix Contact RCU II+ and Multiload II+ grants full root access. CVSS 8.8. No patch yet. Isolate devices and restrict network exposure. #CVE #PhoenixContact #infosec
Overview
Description
Statistics
- 2 Posts
Fediverse
Rockwell's own advisory says CVE-2021-22681 has no patch, ever, just "defense in depth." Five years unpatched, now weaponized against 30+ Minnesota towns running PLCs on consumer cellular modems nobody budgeted to secure.
https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know
Overview
Description
Statistics
- 1 Post
Overview
- zephyrproject
- zephyr
- zephyr
Description
Statistics
- 1 Post
Fediverse
Zephyr Bluetooth GATT client (versions 2.4.0 to <4.5.0) faces a HIGH severity use-after-free (CVE-2026-10685) in gatt_write_ccc_rsp(). Risk: memory corruption, crash, or attacker-driven flow. Patch pending β apply mitigations. https://radar.offseq.com/threat/cve-2026-10685-use-after-free-in-zephyrproject-zephyr-33ca6b79fde1e5b1 #OffSeq #Zephyr #Bluetooth #CVE