2026-05-26
2026-05-26 14:16Z
HIGH

CVE-2026-48132 — Security: As a result, a specially crafted or malformed packet can cause the VPN processing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48132

The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic). CVSSv3.1 8.1 (HIGH)

CWECWE 125VNDSecurityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 14:16Z
HIGH

CVE-2026-48131 — VPN: This can cause the service to terminate unexpectedly, resulting in denial of service (temporary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48131

The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality). CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDVpnTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 13:00Z
HIGH

Sparkplug B Protocol Fuzzing with AI Assistance

Bishop Fox Labs·bishopfox.com

Bishop Fox released sparkplugFuzzer, an open-source security fuzzer for Sparkplug B, the dominant MQTT-based protocol in industrial control and SCADA environments. The tool systematically covers all 9 message types, 19 data types, and 87+ field paths defined by the Eclipse Sparkplug specification, with capabilities for type-mismatch testing, sequence manipulation, alias collision detection, and passive network discovery. The fuzzer was developed with AI assistance (Claude Code) to identify coverage gaps and harden the initial prototype into a production-ready tool.

SRFNetwork ApplianceTACTA0007TYPToolSTGDiscoverySTGInitial AccessTECT1046
78
Edit Score
2026-05-26
2026-05-26 08:16Z
HIGH

CVE-2026-8046 — The affected products insufficiently verify authorization when deleting user accounts.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8046

The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges. CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-26
2026-05-26 02:16Z
CRIT

CVE-2026-42496 — Archive\ \: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42496

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path. CVSSv3.1 9.1 (CRITICAL)

CWECWE 59VNDArchiveTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-26
2026-05-26 00:16Z
CRIT

CVE-2026-8376 — Perl Perl: versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8376

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller CVSSv3.1 9.8 (CRITICAL)

CWECWE 680TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-26
2026-05-26 00:00Z
CRIT

Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs published comprehensive detection engineering for Tycoon 2FA, a prolific PhaaS AiTM platform that bypasses MFA on Entra ID and Google Workspace by proxying authentication flows and intercepting post-MFA session tokens. The analysis maps two distinct operational tiers on Microsoft (kit relay + operator console) versus single-tier on Google, details evasion techniques (IP filtering, DevTools blocking, per-victim encryption), and provides detection rules exploiting cross-ASN pivots, Node.js user-agent signatures, and Graph API enumeration patterns. The kit persists on Microsoft via device-PRT registration that survives standard session revocation, requiring device deletion before token invalidation.

TACTA0001TACTA0006TACTA0007SRFIdentitySRFCloudSWEntra IdSWGoogle WorkspaceVNDMicrosoft
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-26
2026-05-26 00:00Z
CRIT

Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

Trend Micro Research·trendmicro.comin the wild

Trend Micro Research documented the ClearFake campaign's use of the EtherHiding technique to store malicious payloads and C&C routing instructions in BNB Smart Chain testnet smart contracts, bypassing traditional infrastructure takedown mechanisms. The attack chain delivers OS-specific payloads (SectopRAT and ACRStealer) via ClickFix social engineering overlays, with on-chain execution tracking confirming victim compromise in real time. Four linked smart contracts deployed from a single wallet have been operational for nearly a year, indicating a mature, long-running campaign now adopted by nation-state actors including North Korean UNC5342.

TACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWebTACTA0003TACTA0009
92
Edit Score
2026-05-26
2026-05-26 00:00Z
CRIT

Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs published comprehensive detection engineering research on Tycoon 2FA, the most prolific PhaaS AiTM platform targeting Entra ID and Google Workspace. The analysis maps two distinct operational tiers (kit relay + operator console on Microsoft; single-tier relay on Google), documents evasion techniques including IP filtering, DevTools blocking, and per-victim encryption, and ships detection rules for both platforms that identify token relay, post-compromise Graph API enumeration, and device-registration persistence. The kit remains active post-takedown with operators adapting to combine Tycoon tradecraft with OAuth Device Code flows.

TACTA0001TACTA0006TACTA0007SRFIdentitySRFCloudSWEntra IdSWGoogle WorkspaceVNDMicrosoft
92
Edit Score
2026-05-25
2026-05-25 23:16Z
HIGH

CVE-2026-48837 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48837

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-25
2026-05-25 23:16Z
HIGH

CVE-2026-45216 — Incorrect: Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45216

Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0. CVSSv3.1 8.8 (HIGH)

CWECWE 266TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 23:16Z
CRIT

CVE-2026-42774 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42774

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-25
2026-05-25 23:16Z
CRIT

CVE-2026-42773 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42773

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOne Store Manager allows Blind SQL Injection. This issue affects eMagicOne Store Manager: from n/a through 1.3.2. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-25
2026-05-25 20:16Z
HIGH

CVE-2026-48842 — Roundcube: Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48842

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDRoundcubeTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-25
2026-05-25 19:16Z
HIGH

CVE-2026-9482 — Such manipulation of the argument submit-url leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9482

A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 19:16Z
HIGH

CVE-2026-9481 — This manipulation of the argument submit-url causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9481

A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 19:16Z
HIGH

CVE-2026-9480 — Edimax: The manipulation of the argument submit-url results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9480

A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDEdimaxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 18:16Z
HIGH

CVE-2026-9479 — The manipulation of the argument submit-url leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9479

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the argument submit-url leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 18:16Z
CRIT

CVE-2026-9478 — Executing a manipulation of the argument enable can lead to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9478

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-25
2026-05-25 18:16Z
CRIT

CVE-2026-9477 — Performing a manipulation of the argument mac results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9477

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-25
2026-05-25 17:16Z
CRIT

CVE-2026-9476 — Totolink: Such manipulation of the argument admpass leads to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9476

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-25
2026-05-25 17:16Z
CRIT

CVE-2026-9475 — Totolink: This manipulation of the argument Comment causes os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9475

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument Comment causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-25
2026-05-25 15:16Z
HIGH

CVE-2026-9463 — This manipulation of the argument submit-url causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9463

A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 15:16Z
HIGH

CVE-2026-9462 — Edimax: The manipulation of the argument submit-url results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9462

A vulnerability was detected in Edimax EW-7438RPn 1.31. Affected by this vulnerability is the function formWpsProxyEnable of the file /goform/formWpsProxyEnable. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDEdimaxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-25
2026-05-25 15:16Z
HIGH

CVE-2018-25379 — Collectric: CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25379

Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthenticated attackers to manipulate database queries during authentication. Attackers can inject SQL code through the lang parameter in login requests to extract sensitive information from the database using time-based blind techniques. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDCollectricTYPVulnerability
8.2
CVSS v3.1
91
Edit Score