2w ago
2026-09-01 00:00Z
CRIT

Ungentlemanly behavior: Insights into a ransomware operation

Sophos X-Ops·news.sophos.comCVE-2024-55591in the wild

Sophos CTU analyzed 15 intrusions by GOLD SHERWOOD affiliates operating The Gentlemen ransomware-as-a-service scheme, documenting a repeatable playbook combining VPN/firewall exploitation, rapid privilege escalation via native Windows utilities, legitimate tool abuse (Rclone, Restic, MinIO Client), BYOVD-based EDR killing, and ransomware deployment within 24-48 hours. The group has escalated from <20 monthly victims in late 2025 to 169 in July 2026, demonstrating operational maturity and affiliate recruitment success.

SRFApplicationTACTA0004TACTA0005TACTA0001SRFNetworkTACTA0006TACTA0007TACTA0003
88
Edit Score
2w ago
2026-08-31 23:16Z
CRIT

CVE-2026-83524 — The manipulation leads to command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83524

A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.9 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 23:16Z
CRIT

CVE-2026-82971 — QVidium: This manipulation of the argument ipaddr causes command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82971

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects CVSSv3.1 10.0 (CRITICAL)

CWECWE 74CWECWE 77VNDQvidiumTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 22:17Z
CRIT

CVE-2026-82954 — Dokploy: The manipulation of the argument path results in path traversal.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82954

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.9 (CRITICAL)

CWECWE 22VNDDokployTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 22:17Z
HIGH

CVE-2026-82882 — Devtron: through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82882

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDDevtronTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 22:17Z
HIGH

CVE-2026-77348 — Wallos: Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77348

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cURL proxying (CURLOPT_PROXY = '' + CURLOPT_NOPROXY = '*'). However, Wallos ships a second, near-identical, unauthenticated logo-image search endpoint — endpoints/payments/search.php — that was not given the same hardening. It still passes the CVSSv3.1 8.2 (HIGH)

CWECWE 918CWECWE 441CWECWE 1188VNDWallosTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 22:00Z
CRIT

Chamilo LMS... It's raining 0days, hallelujah, it's raining 0days

Quarkslab disclosed 11 0-day vulnerabilities in Chamilo LMS affecting the latest version, including unauthenticated SQL injection (CVE-2026-61600), pre-auth email hijacking via AJAX endpoint (CVE-2026-61600 chain), and unsafe deserialization in course backup import (CVE-2026-70647) that enables arbitrary file write. The researchers demonstrated a complete pre-auth RCE chain: extract admin reset token via blind SQLi, hijack admin email, reset password, create malicious course, modify serialized backup metadata to place webshell in web root, and import to achieve code execution.

SRFApplicationTACTA0001TACTA0002SRFWebTACTA0003SWChamiloTYPVulnerabilitySTGExecution
95
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-83596 — WebKitGTK: Processing malicious web content can cause memory corruption due to improper memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83596

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. CVSSv3.1 8.8 (HIGH)

CWECWE 120VNDWebkitgtkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-82908 — MSI: Performing a manipulation of the argument count/elementSize results in integer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82908

A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 190CWECWE 189VNDMsiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-82228 — Bypass: Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82228

Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 290VNDBypassTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-82226 — PHP: Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82226

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-81892 — EasyAdmin: From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81892

EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query parameter on the kernel.controller event. The swap happens after Symfony's security firewall has already evaluated access_control against the original dashboard URL CVSSv3.1 8.1 (HIGH)

CWECWE 862CWECWE 639CWECWE 863VNDEasyadminTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-81891 — Because the .phtml, .phar, .php5, and .php3 extensions are absent from mime.types, the staticMimeMap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81891

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent from mime.types, the staticMimeMap entries that map them to text/x-php are not applied, and allowPutMime() permits extraction even when uploadDeny blocks text/x-php CVSSv3.1 8.1 (HIGH)

CWECWE 434TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-81889 — Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81889

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates $info['ip'], but get_remote_contents() selects fsock_get_contents(), which connects to $arr['host'] and performs a second DNS resolution. An attacker able to submit a URL upload can use DNS rebinding to have the CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81780 — Arbitrary: Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81780

Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 434VNDArbitraryTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81779 — Validation: Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81779

Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48. CVSSv3.1 10.0 (CRITICAL)

CWECWE 1284TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81763 — SQL: Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81763

Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81756 — SQL: Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81756

Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-81293 — SQL: Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81293

Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-81287 — Subscriber: SQL Injection in Charitable <= 1.8.12.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81287

Subscriber SQL Injection in Charitable <= 1.8.12.1 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-79408 — An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79408

An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-75458 — POST: An authenticated teacher user (role=2) can delete an administrator account (role=3), constituting a vertical

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75458

The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID and then executes getUserById(id), setDeleted(true), updateByIdFilter() in sequence, without any validation of whether the current user has the authority to delete the target user. An authenticated teacher user (role=2) can delete an administrator account (role=3), constituting a verti CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDPostTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
HIGH

CVE-2026-61641 — Wallos: From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61641

Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email as verified (email_verified). When Wallos is configured against an IdP that lets a user present an arbitrary or unverified email (multi-tenant IdPs, IdPs with open self-registration, or any IdP the at CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDWallosTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 21:17Z
CRIT

CVE-2026-38577 — Admin: Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38577

Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 20:17Z
CRIT

CVE-2026-51740 — Incorrect: access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51740

Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score