2d ago
2026-09-11 15:17Z
HIGH

CVE-2026-38056 — A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38056

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians CVSSv3.1 8.8 (HIGH)

CWECWE 862TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 14:17Z
HIGH

CVE-2026-89212 — XML: A flaw resulting in XML external entity (XXE) was found in Akana API Platform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89212

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions. CVSSv3.1 8.6 (HIGH)

CWECWE 611TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2d ago
2026-09-11 14:17Z
CRIT

CVE-2026-71644 — Robotics: An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71644

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the drone enters IDLE CVSSv3.1 9.8 (CRITICAL)

CWECWE 843VNDRoboticsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-09-11 14:17Z
HIGH

CVE-2026-71416 — Headroom: compresses data before the data reaches a large language model.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71416

Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the CVSSv3.1 8.8 (HIGH)

CWECWE 287CWECWE 1385VNDHeadroomTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 13:35Z
CRIT

Metasploit Wrap Up: This One Goes to Sixteen!

Metasploit 6.5.4 release adds 16 new modules including 10 exploit modules, with 5 targeting CISA KEV-listed vulnerabilities. Modules cover critical RCE chains in SonicWall SMA1000, PaperCut NG/MF, JetBrains TeamCity, and Next.js, plus novel Kerberos relay (ESC8) and Windows persistence techniques. Four bug fixes address race conditions, payload selection, DNS handling, and module regressions.

SRFApplicationTACTA0004TACTA0005TACTA0001TACTA0002SRFNetworkSRFWebTACTA0003
92
Edit Score
2d ago
2026-09-11 13:33Z
HIGH

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

Rapid7 Research·rapid7.com

Rapid7 research documents the fragmentation of fraud-as-a-service (FaaS) marketplaces from centralized platforms (Xleet, Blackpass, Infodig, Styx) into smaller, invitation-only shops across Telegram and P2P channels. The analysis maps the complete fraud supply chain—infrastructure provisioning, account acquisition, and money laundering services—and correlates marketplace offerings to MITRE's new Fraud Fighting Framework (F3). Key trend: marketplaces are democratizing fraud tooling for novice actors while pivoting toward AI-platform credentials and localized SIM/VoIP infrastructure.

TACTA0005SRFNetworkTACTA0006SRFWebTYPResearchTYPThreat IntelSTGCred AccessEXPAuth Bypass
72
Edit Score
2d ago
2026-09-11 13:18Z
CRIT

CVE-2026-84390 — A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84390

A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here> CVSSv3.1 9.8 (CRITICAL)

CWECWE 540TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2d ago
2026-09-11 13:18Z
CRIT

CVE-2026-80462 — Chef: A vulnerability in the Chef Automate API gateway and identity validation path may allow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80462

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 306VNDChefTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2d ago
2026-09-11 13:00Z
CRIT

CVE-2026-82329: Unauthenticated Administrative Access in JFrog Artifactory via an Empty Cluster Join Key

Bishop Fox Labs·bishopfox.comCVE-2026-82329in the wild

CVE-2026-82329 is a critical unauthenticated authentication bypass in self-managed JFrog Artifactory (CVSS 9.8) affecting versions below 7.111.21 and multiple other branches. The vulnerability stems from JFrog Access registering an empty string as a valid cluster join key on default installations, allowing attackers to forge JWT tokens and obtain permanent admin-scoped credentials via a single unauthenticated POST request. The flaw was exploited in the wild within days of disclosure, and CISA added it to the KEV catalog with a forensic triage requirement.

SRFApplicationTACTA0001SWArtifactoryVNDJfrogTYPVulnerabilitySTGInitial AccessTECT1190EXPAuth Bypass
92
Edit Score
2d ago
2026-09-11 12:16Z
CRIT

CVE-2026-89259 — Hugo: From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89259

Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As a result, the restrictions intended by the fix for GHSA-x597-9fr4-5857 could still be bypassed, allowing a Node tool invoked during a build to read and write files outside the project's working directory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 250VNDHugoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-09-11 12:16Z
HIGH

CVE-2026-89256 — AVideo: through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89256

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video owner can inject malicious scripts via the bookmark name parameter, and every visitor of that video executes the payload in the AVideo origin. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDAvideoTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 12:16Z
HIGH

CVE-2026-89255 — AVideo: through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89255

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inject malicious JavaScript by submitting a crafted public key, which executes in an administrator's session when viewing the user's profile tab. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDAvideoTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 12:16Z
HIGH

CVE-2026-89254 — AVideo: through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89254

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. Administrators can inject malicious scripts via the add.json.php endpoint that execute when viewing extra info pages or profile forms that render the typeToHTML function. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDAvideoTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 12:16Z
HIGH

CVE-2026-89253 — WWBN: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89253

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() validates it only with filter_var(..., FILTER_VALIDATE_URL), which accepts strings such as http://evil.example/"onmouseover=alert(document.domain)//, while getDonationLink() applies only strip_tags() and does not encode double quotes. plugin/Cust CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDWwbnTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 12:16Z
HIGH

CVE-2026-89249 — AVideo: through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89249

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in wallet_log.information. Administrators viewing pending withdrawal requests in pendingRequests.php execute the stored markup in their session, allowing attackers to perform administrative actions via same-origin fetch requests. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDAvideoTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 12:16Z
HIGH

CVE-2026-89243 — WWBN: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89243

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permission can inject malicious HTML and JavaScript that executes in the browser when other administrators access the user manager interface. CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDWwbnTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2d ago
2026-09-11 09:17Z
HIGH

CVE-2026-80469 — An attacker may achieve arbitrary code execution on a target system by uploading a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80469

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is required. CVSSv3.1 8.3 (HIGH)

CWECWE 347TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2d ago
2026-09-11 08:16Z
HIGH

CVE-2026-89178 — WeenyGenius: WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89178

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker. CVSSv3.1 8.8 (HIGH)

CWECWE 940VNDWeenygeniusTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 08:16Z
HIGH

CVE-2026-89177 — WeenyGenius: Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89177

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations. CVSSv3.1 8.8 (HIGH)

CWECWE 757VNDWeenygeniusTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 08:16Z
HIGH

CVE-2026-89176 — WeenyGenius: WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89176

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can disrupt normal classroom operations, whereas impersonating a teacher can induce student computers to initiate connections, thereby gaining remote control over the student endpoints. CVSSv3.1 8.8 (HIGH)

CWECWE 306VNDWeenygeniusTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 07:16Z
HIGH

CVE-2026-85677 — Gutenverse: The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85677

The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in the browser of any administrator who reviews the comment queue, and of any visitor to the post once the comment is approved. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDGutenverseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 07:16Z
HIGH

CVE-2026-73784 — HPE: A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73784

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user. CVSSv3.1 8.8 (HIGH)

CWECWE 347VNDHpeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 07:16Z
CRIT

CVE-2026-14563 — WordPress: The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14563

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-09-11 07:16Z
CRIT

CVE-2026-14560 — WordPress: The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14560

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the server. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDWordpressTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2d ago
2026-09-11 07:16Z
CRIT

CVE-2026-14559 — WordPress: The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14559

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score