Overview
- Innotim Software, Telecommunications and Consulting Trade Ltd. Co.
- Logsign SIEM
Description
Statistics
- 1 Post
Fediverse
CVE-2026-17561: Logsign SIEM <6.4.108 faces CRITICAL code injection (CWE-94, CVSS 9.8). Exploitable remotely, no patch yet. Full system compromise possible. Monitor for updates. https://radar.offseq.com/threat/cve-2026-17561-cwe-94-improper-control-of-generation-of-code-code-injection-in-innotim-software-30d176d2929ded6e #OffSeq #CVE202617561 #SIEM #Vuln #BlueTeam
Overview
Description
Statistics
- 1 Post
Overview
- bank-vaults
- vault-secrets-webhook
Description
Statistics
- 1 Post
Fediverse
bank-vaults vault-secrets-webhook is impacted by CVE-2026-54725 (CRITICAL, CVSS 9.6). SSRF flaw lets attackers exfiltrate ServiceAccount JWTs via attacker-controlled Vault addresses. Update to 1.23.1 ASAP. https://radar.offseq.com/threat/cve-2026-54725-cwe-918-server-side-request-forgery-ssrf-in-bank-vaults-vault-secrets-webhook-ec0efb4a3e2ca6ff #OffSeq #Kubernetes #SSRF #CloudSecurity
Overview
- Jcharis
- Machine-Learning-Web-Apps
Description
Statistics
- 1 Post
Fediverse
ZAST.AI identified and verified CVE-2026-3962, a reflected XSS issue in Machine-Learning-Web-Apps.
Machine-Learning-Web-Apps is an open-source repository covering Flask, Streamlit, and related machine learning web app patterns.
Project: https://github.com/Jcharis/Machine-Learning-Web-Apps
Key facts:
The vulnerable path is the POST /preview flow.
User input from request.form['newtext'] is passed into render_template(...).
ZAST.AI verified the reflection path as a real browser-facing XSS result.
This case is a useful reminder that preview and demo features still sit on the output boundary. If untrusted content is reflected into the response, the browser treats it as part of the attack surface.
Technical details: https://github.com/Jcharis/Machine-Learning-Web-Apps/issues/15
Overview
- Red Hat
- Red Hat Enterprise Linux 10
- pipewire
Description
Statistics
- 1 Post
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 2 Posts
Overview
Description
Statistics
- 1 Post
Fediverse
CVE-2026-62246 - Kamaji tenant isolation bypass. Lossy name normalization lets tenants read, modify, or destroy other tenants' Kubernetes data. CVSS 8.5. Update to 26.7.4-edge immediately. #CVE #Kubernetes #infosec
Overview
Description
Statistics
- 1 Post
Overview
- fast-uri
- fast-uri
Description
Statistics
- 2 Posts
Fediverse
🚨 High-severity security fix in fast-uri@4.1.2 just released!
Patches CVE-2026-18446, fast-uri vulnerable to host confusion via backslash authority introducer
https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7
Overview
- IBM
- Langflow OSS
Description
Statistics
- 1 Post