24h | 7d | 30d

Overview

  • jfrog
  • artifactory

27 Jul 2026
Published
12 Sep 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.89%

Description

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Statistics

  • 3 Posts

Last activity: 11 hours ago

Fediverse

Profile picture fallback

CRITICAL CISA KEV ALERT: CVE-2026-42016 targets JFrog Artifactory via incorrect authorization and token scope flaws. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to secure your software pipelines.

thecybermind.co/4u1b

  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

Attackers are chaining three JFrog Artifactory bugs to plant admin backdoors 

Multiple threat actors have been chaining three JFrog Artifactory vulnerabilities, CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329, in active exploitation confirmed between August 15 and September 8, using two of the bugs together to extract an anonymous-user token and escalate it to admin privileges, or…

itnerd.blog/2026/09/14/attacke

  • 0
  • 0
  • 1
  • 11h ago

Overview

  • Linux
  • Linux

11 Sep 2026
Published
13 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.13%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: ipmi: Remove all sysfs files on registration failure ipmi_add_smi() creates the nr_users and nr_msgs files before trying to create the maintenance_mode file. If that last creation fails, the error path removes only nr_users before dropping the final reference to the interface. Remove nr_msgs as well so no sysfs attribute embedded in the freed interface remains registered.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CVE-2026-81006 Linux kernel ipmi: failed registration leaves sysfs files on freed memory, risking use-after-free. CVSS N/A, patch status unknown. Update your kernel now. valtersit.com/cve/CVE-2026-810 #CVE #Linux #infosec

  • 2
  • 0
  • 0
  • 5h ago

Overview

  • Nintendo
  • Nintendo Switch

10 Sep 2026
Published
11 Sep 2026
Updated

CVSS v4.0
HIGH (7.0)
EPSS
0.16%

KEV

Description

A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic. This issue affects Nintendo Switch: before 23.0.0.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 19 hours ago

Fediverse

Profile picture fallback

Discover the dangerous Nintendo Switch QR code vulnerability (CVE-2026-82079) allowing hackers to execute code. Learn how system update 23.0.0 fixes it.

meterpreter.org/nintendo-switc

  • 1
  • 0
  • 0
  • 19h ago

Overview

  • moment
  • moment

15 Sep 2026
Published
15 Sep 2026
Updated

CVSS v3.1
MEDIUM (5.9)
EPSS
Pending

KEV

Description

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale().

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 3 hours ago

Bluesky

Profile picture fallback
🚨 Medium-severity security fix in moment@2.31.0 just released! Patches CVE-2026-17495: moment vulnerable to Path Traversal via crafted non-string locale name github.com/moment/momen...
  • 0
  • 2
  • 1
  • 3h ago

Overview

  • Apple
  • iOS and iPadOS

11 May 2026
Published
12 May 2026
Updated

CVSS
Pending
EPSS
0.12%

KEV

Description

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access user-sensitive data.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 19 hours ago

Fediverse

Profile picture fallback

Sequoia 15.7.7 broke a critical shortcut I use. Terra says "Apple’s Shortcuts security fix for CVE-2026-28993,"

It doesn't always fail, just most of the time.

It feels like I run into something of this nature every day now.

  • 0
  • 1
  • 0
  • 19h ago

Overview

  • ModelTC
  • LightLLM
  • LightLLM

14 Sep 2026
Published
14 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config Server port and send a malicious serialized payload with a __reduce__ method to execute arbitrary code with Config Server process privileges.

Statistics

  • 1 Post

Last activity: 21 hours ago

Fediverse

Profile picture fallback

CVE-2026-90919: ModelTC LightLLM <=1.2.0 faces CRITICAL RCE risk. Unauthenticated /visual_register WebSocket lets attackers send malicious pickle data, leading to code execution. Patch or restrict access fast. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 21h ago

Overview

  • KGUARD
  • KGUARD_firmware

09 Sep 2026
Published
09 Sep 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
1.08%

KEV

Description

Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR. The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity. The vulnerability was reported to affect firmware dating from 2016, while firmware released after 2017 appears to mitigate the issue by restricting the affected service to the localhost interface (127.0.0.1) instead of exposing it on all interfaces (0.0.0.0). The affected-device list reported by Netlab includes many D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, and D99xx variants and several associated hardware revisions The exploit is included in some version of rapperbot and exploited in 2026. This assignment has been made to document the active exploitation and lack of documentation from the vendor.

Statistics

  • 1 Post

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-87827 (CVSS 10) is a KGUARD DVR vulnerability exploited by the Mirai botnet for unauthenticated RCE and complete device compromise.

securityonline.info/cve-2026-8

  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Apache Software Foundation
  • Apache Syncope
  • org.apache.syncope.core:syncope-core-spring

14 Sep 2026
Published
14 Sep 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a valid low-privileges JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Statistics

  • 1 Post

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-78330 | CRITICAL: Apache Syncope vuln allows admin escalation if JWKS is exposed and JWT auth used. Affects 3.0.0-M0 – 3.0.16, 4.0.0-M0 – 4.0.7, 4.1.0-M0 – 4.1.2. Upgrade to 4.0.8/4.1.3 to mitigate. Details: radar.offseq.com/threat/incorr

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • D-Link
  • DI-8400

15 Sep 2026
Published
15 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
Pending

KEV

Description

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

Statistics

  • 1 Post

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Stack-based buffer overflow (CVE-2026-91001, CVSS 9.4) in D-Link DI-8400 (16.07) exposes devices to RCE. Exploit code is public. Restrict management access until fix. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • AWS
  • Amazon SSM Agent

10 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.36%

KEV

Description

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address. To remediate this issue, users should upgrade to version 3.3.4851.0 or later.

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture fallback
AWS SSM Agent の脆弱性(CVE-2026-89049) の被害があったかどうかを CloudTrail で確認する方法 https://zenn.dev/cscloud_blog/articles/4d6e13b853109e
  • 0
  • 0
  • 0
  • 9h ago
Showing 11 to 20 of 84 CVEs