Overview
- IBM
- Langflow OSS
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Fediverse
The Arris BGW210-700 vulnerability, CVE-2026-16771, is an authentication bypass in AT&T's gateway. A LAN user can read the WiFi password.
#Arris #BGW210700 #ATT #CVE202616771 #AuthenticationBypass #CyberSecurity
Overview
- openremote
- openremote
Description
Statistics
- 1 Post
Fediverse
An OpenRemote vulnerability, CVE-2026-66013 (CVSS 9.3), enables unauthenticated asset takeover. Full advisory details are now public. Patch to 1.26.2.
#OpenRemote #CVE202666013 #IoTSecurity #AssetTakeover
https://securityonline.info/openremote-cve-2026-66013/?utm_source=mastodon&utm_medium=jetpack_social
Overview
- VMware
- Cloud Foundation
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
Teils kritische Schwachstellen (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) in VMware by Broadcom-Produkten (VMware ESX, vCenter, Workstation, Fusion). Updates sind laut Adversory vorhanden.
https://borncity.com/blog/2026/07/31/vmware-schwachstelle-u-a-in-esx-erlaubt-ausbruch-aus-vms/
Overview
- VMware
- Cloud Foundation
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
Teils kritische Schwachstellen (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) in VMware by Broadcom-Produkten (VMware ESX, vCenter, Workstation, Fusion). Updates sind laut Adversory vorhanden.
https://borncity.com/blog/2026/07/31/vmware-schwachstelle-u-a-in-esx-erlaubt-ausbruch-aus-vms/
Overview
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.
CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.
CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.
https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj
#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
Overview
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.
CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.
CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.
https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj
#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Fediverse
Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.
#OpenAM #RCE #IAM #CVE202662379
https://securityonline.info/openam-cve-2026-62379/?utm_source=mastodon&utm_medium=jetpack_social
Overview
- IBM
- WebSphere Application Server
Description
Statistics
- 1 Post
Fediverse
Four IBM WebSphere vulnerabilities are fixed, including a 9.8 pre-auth RCE (CVE-2026-14512) and a 9.4 SSRF (CVE-2026-14529). Patch now.
#IBMWebSphere #CVE202614512 #SSRF #RCE #Vulnerability #InfoSec