The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic).
CVSSv3.1 8.1 (HIGH)
CWECWE 125VNDSecurityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 14:16Z
HIGH
CVE-2026-48131 — VPN: This can cause the service to terminate unexpectedly, resulting in denial of service (temporary
The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality).
CVSSv3.1 8.1 (HIGH)
CWECWE 122VNDVpnTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 13:00Z
HIGH
Sparkplug B Protocol Fuzzing with AI Assistance
Bishop Fox Labs·bishopfox.com
Bishop Fox released sparkplugFuzzer, an open-source security fuzzer for Sparkplug B, the dominant MQTT-based protocol in industrial control and SCADA environments. The tool systematically covers all 9 message types, 19 data types, and 87+ field paths defined by the Eclipse Sparkplug specification, with capabilities for type-mismatch testing, sequence manipulation, alias collision detection, and passive network discovery. The fuzzer was developed with AI assistance (Claude Code) to identify coverage gaps and harden the initial prototype into a production-ready tool.
The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.
CVSSv3.1 8.1 (HIGH)
CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 02:16Z
CRIT
CVE-2026-42496 — Archive\ \: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.
A subsequent open through the extracted name reads or writes the attacker chosen path.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 59VNDArchiveTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-26
2026-05-26 00:16Z
CRIT
CVE-2026-8376 — Perl Perl: versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.
A caller
CVSSv3.1 9.8 (CRITICAL)
CWECWE 680TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-26
2026-05-26 00:00Z
CRIT
Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace
Elastic Security Labs·elastic.coin the wild
Elastic Security Labs published comprehensive detection engineering for Tycoon 2FA, a prolific PhaaS AiTM platform that bypasses MFA on Entra ID and Google Workspace by proxying authentication flows and intercepting post-MFA session tokens. The analysis maps two distinct operational tiers on Microsoft (kit relay + operator console) versus single-tier on Google, details evasion techniques (IP filtering, DevTools blocking, per-victim encryption), and provides detection rules exploiting cross-ASN pivots, Node.js user-agent signatures, and Graph API enumeration patterns. The kit persists on Microsoft via device-PRT registration that survives standard session revocation, requiring device deletion before token invalidation.
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
Trend Micro Research·trendmicro.comin the wild
Trend Micro Research documented the ClearFake campaign's use of the EtherHiding technique to store malicious payloads and C&C routing instructions in BNB Smart Chain testnet smart contracts, bypassing traditional infrastructure takedown mechanisms. The attack chain delivers OS-specific payloads (SectopRAT and ACRStealer) via ClickFix social engineering overlays, with on-chain execution tracking confirming victim compromise in real time. Four linked smart contracts deployed from a single wallet have been operational for nearly a year, indicating a mature, long-running campaign now adopted by nation-state actors including North Korean UNC5342.
Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace
Elastic Security Labs·elastic.coin the wild
Elastic Security Labs published comprehensive detection engineering research on Tycoon 2FA, the most prolific PhaaS AiTM platform targeting Entra ID and Google Workspace. The analysis maps two distinct operational tiers (kit relay + operator console on Microsoft; single-tier relay on Google), documents evasion techniques including IP filtering, DevTools blocking, and per-victim encryption, and ships detection rules for both platforms that identify token relay, post-compromise Graph API enumeration, and device-registration persistence. The kit remains active post-takedown with operators adapting to combine Tycoon tradecraft with OAuth Device Code flows.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection.
This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8.
CVSSv3.1 8.5 (HIGH)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection.
This issue affects JetEngine: from n/a through 3.8.8.1.
CVSSv3.1 9.3 (CRITICAL)
CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-25
2026-05-25 23:16Z
CRIT
CVE-2026-42773 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOne Store Manager allows Blind SQL Injection.
This issue affects eMagicOne Store Manager: from n/a through 1.3.2.
CVSSv3.1 9.3 (CRITICAL)
CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-25
2026-05-25 20:16Z
HIGH
CVE-2026-48842 — Roundcube: Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
CVSSv3.1 8.1 (HIGH)
CWECWE 89VNDRoundcubeTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-25
2026-05-25 19:16Z
HIGH
CVE-2026-9482 — Such manipulation of the argument submit-url leads to stack-based buffer overflow.
A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSSv3.1 8.8 (HIGH)
CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 19:16Z
HIGH
CVE-2026-9481 — This manipulation of the argument submit-url causes stack-based buffer overflow.
A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSSv3.1 8.8 (HIGH)
CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 19:16Z
HIGH
CVE-2026-9480 — Edimax: The manipulation of the argument submit-url results in stack-based buffer overflow.
A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSSv3.1 8.8 (HIGH)
CWECWE 121CWECWE 119VNDEdimaxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 18:16Z
HIGH
CVE-2026-9479 — The manipulation of the argument submit-url leads to stack-based buffer overflow.
A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the argument submit-url leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSSv3.1 8.8 (HIGH)
CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 18:16Z
CRIT
CVE-2026-9478 — Executing a manipulation of the argument enable can lead to os command injection.
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-25
2026-05-25 18:16Z
CRIT
CVE-2026-9477 — Performing a manipulation of the argument mac results in os command injection.
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-25
2026-05-25 17:16Z
CRIT
CVE-2026-9476 — Totolink: Such manipulation of the argument admpass leads to os command injection.
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 77CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-25
2026-05-25 17:16Z
CRIT
CVE-2026-9475 — Totolink: This manipulation of the argument Comment causes os command injection.
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument Comment causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 77CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-25
2026-05-25 15:16Z
HIGH
CVE-2026-9463 — This manipulation of the argument submit-url causes stack-based buffer overflow.
A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSSv3.1 8.8 (HIGH)
CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 15:16Z
HIGH
CVE-2026-9462 — Edimax: The manipulation of the argument submit-url results in stack-based buffer overflow.
A vulnerability was detected in Edimax EW-7438RPn 1.31. Affected by this vulnerability is the function formWpsProxyEnable of the file /goform/formWpsProxyEnable. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSSv3.1 8.8 (HIGH)
CWECWE 121CWECWE 119VNDEdimaxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 15:16Z
HIGH
CVE-2018-25379 — Collectric: CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter
Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthenticated attackers to manipulate database queries during authentication. Attackers can inject SQL code through the lang parameter in login requests to extract sensitive information from the database using time-based blind techniques.
CVSSv3.1 8.2 (HIGH)