2w ago
2026-09-01 13:19Z
CRIT

CVE-2026-51744 — Incorrect: access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51744

Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:19Z
CRIT

CVE-2026-51743 — Incorrect: access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51743

Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-09-01 13:19Z
CRIT

CVE-2026-51741 — Incorrect: access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51741

Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:18Z
CRIT

CVE-2026-18765 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18765

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 12:17Z
CRIT

CVE-2026-84200 — Kyverno: When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84200

Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that matches the second exception's name pattern (e.g., '*ingress*'). This can be used to circumvent policies such as one blocking hostPath volumes. Fixed in v1.13.0. CVSSv3.1 9.0 (CRITICAL)

CWECWE 284VNDKyvernoTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2w ago
2026-09-01 12:17Z
HIGH

CVE-2026-84189 — LibreNMS: An administrator who points the Oxidized URL at an attacker-controlled server (SSRF) can cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84189

LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An administrator who points the Oxidized URL at an attacker-controlled server (SSRF) can cause it to return malicious JSON, resulting in stored/persistent cross-site scripting affecting all users who view any device's showconfig tab. Fixed in 26.7.0. CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDLibrenmsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 12:17Z
HIGH

CVE-2026-84187 — AVideo: contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84187

AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with schedule identifiers. Attackers can exploit the unguarded RTMP callback endpoint to modify scheduled broadcast status fields by supplying fabricated stream keys matching the pattern -ps-<N>, silently canceling any scheduled live broadcast without credentials or authoriz CVSSv3.1 8.2 (HIGH)

CWECWE 284VNDAvideoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-09-01 12:17Z
HIGH

CVE-2026-83595 — AVideo: contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83595

AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers can navigate a victim's browser to a malicious URL with API parameters to delete videos, deactivate accounts, or modify playlists without user interaction. CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDAvideoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 12:17Z
HIGH

CVE-2026-76111 — Dell: PowerStore contains an Incorrect Authorization vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76111

Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 12:17Z
CRIT

CVE-2026-18550 — Nokri: The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18550

The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to insufficient reset token validation in the `nokri_reset_password()` function, which allows empty attacker-supplied reset tokens to match empty or unset `sb_password_forget_token` user meta values. This makes it possible for unauthenticated attackers to reset the password of any user, including administrators CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDNokriTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 10:17Z
HIGH

CVE-2026-59681 — A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59681

A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the configured host. Auth::AuthConf in src/lib/auth/authconf.rb assembles the Samba net ads join, net ads lookup -S and net ads testjoin invocations by interpolating configuration values into a single command string and passing that string to Open3.popen2 / Open3.capture2, which causes Ruby to run it through CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 10:17Z
HIGH

CVE-2026-59680 — An OS command injection vulnerability was found in yast2-users.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59680

An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to format_days_after_epoch(). That helper interpolated the value into a shell command executed via Ruby backticks without quoting or escaping. Impact: an administrator wh CVSSv3.1 8.0 (HIGH)

CWECWE 78CWECWE 1287TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2w ago
2026-09-01 10:01Z
CRIT

Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586

Horizon3.ai·horizon3.aiCVE-2026-9586in the wild

Horizon3 discovered and disclosed CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox leading to remote code execution via the /pa endpoint. The vulnerability was patched in version 8.4.0.2 on July 14, 2026, but active exploitation in the wild was observed by August 30, 2026, with attackers targeting approximately 4,000 internet-exposed instances. The attack chain involves XML parsing of phone notification messages, direct SQL concatenation of the PhoneIP field, and execution as a PostgreSQL superuser.

SRFApplicationTACTA0001TACTA0002SRFNetworkSWSwitchvoxVNDSangomaTYPResearchTYPVulnerability
92
Edit Score
2w ago
2026-09-01 07:00Z
HIGH

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Kaspersky Securelist·securelist.com

Kaspersky discovered NodeRabbit and PollCat, two previously undocumented Node.js and JavaScript-based RATs deployed by Mirage Kitten APT group targeting aviation and FinTech sectors across Middle East and Africa. The malware is delivered via trojanized coding challenge archives distributed through fake recruiter outreach on job platforms, with three NodeRabbit variants showing progressive sophistication including sandbox evasion, proxy support, and dual persistence mechanisms via VS Code extensions and Git hooks.

SRFApplicationTACTA0005TACTA0001TACTA0003TACTA0011SRFSupply ChainVNDKasperskyTYPResearch
82
Edit Score
2w ago
2026-09-01 06:16Z
CRIT

CVE-2026-83772 — Cobham: The manipulation of the argument sender/recipients results in command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83772

A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender/recipients results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.9 (CRITICAL)

CWECWE 74CWECWE 77VNDCobhamTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-09-01 05:17Z
HIGH

CVE-2026-19806 — Support: The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19806

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the `guest_ticket_login()` function and its `p` parameter. This is due to the site-wide AES-256-CBC encryption key being derived from only three two-digit `wp_rand(10, 99)` values and a Unix timestamp via `md5()` — yielding approximatel CVSSv3.1 8.8 (HIGH)

CWECWE 287VNDSupportTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 03:16Z
CRIT

CVE-2026-75865 — WPLP: The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA &

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75865

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDWplpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 03:16Z
HIGH

CVE-2026-65643 — Cpanel Cpanel: Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65643

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root. CVSSv3.1 8.8 (HIGH) · EPSS 48th percentile

CWECWE 95VNDCpanelVNDEvalTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 00:00Z
CRIT

Ungentlemanly behavior: Insights into a ransomware operation

Sophos X-Ops·news.sophos.comCVE-2024-55591in the wild

Sophos CTU analyzed 15 intrusions by GOLD SHERWOOD affiliates operating The Gentlemen ransomware-as-a-service scheme, documenting a repeatable playbook combining VPN/firewall exploitation, rapid privilege escalation via native Windows utilities, legitimate tool abuse (Rclone, Restic, MinIO Client), BYOVD-based EDR killing, and ransomware deployment within 24-48 hours. The group has escalated from <20 monthly victims in late 2025 to 169 in July 2026, demonstrating operational maturity and affiliate recruitment success.

SRFApplicationTACTA0004TACTA0005TACTA0001SRFNetworkTACTA0006TACTA0007TACTA0003
88
Edit Score
2w ago
2026-08-31 23:16Z
CRIT

CVE-2026-83524 — The manipulation leads to command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83524

A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.9 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 23:16Z
CRIT

CVE-2026-82971 — QVidium: This manipulation of the argument ipaddr causes command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82971

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects CVSSv3.1 10.0 (CRITICAL)

CWECWE 74CWECWE 77VNDQvidiumTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 22:17Z
CRIT

CVE-2026-82954 — Dokploy: The manipulation of the argument path results in path traversal.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82954

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.9 (CRITICAL)

CWECWE 22VNDDokployTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 22:17Z
HIGH

CVE-2026-82882 — Devtron: through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82882

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDDevtronTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 22:17Z
HIGH

CVE-2026-77348 — Wallos: Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77348

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cURL proxying (CURLOPT_PROXY = '' + CURLOPT_NOPROXY = '*'). However, Wallos ships a second, near-identical, unauthenticated logo-image search endpoint — endpoints/payments/search.php — that was not given the same hardening. It still passes the CVSSv3.1 8.2 (HIGH)

CWECWE 918CWECWE 441CWECWE 1188VNDWallosTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 22:00Z
CRIT

Chamilo LMS... It's raining 0days, hallelujah, it's raining 0days

Quarkslab disclosed 11 0-day vulnerabilities in Chamilo LMS affecting the latest version, including unauthenticated SQL injection (CVE-2026-61600), pre-auth email hijacking via AJAX endpoint (CVE-2026-61600 chain), and unsafe deserialization in course backup import (CVE-2026-70647) that enables arbitrary file write. The researchers demonstrated a complete pre-auth RCE chain: extract admin reset token via blind SQLi, hijack admin email, reset password, create malicious course, modify serialized backup metadata to place webshell in web root, and import to achieve code execution.

SRFApplicationTACTA0001TACTA0002SRFWebTACTA0003SWChamiloTYPVulnerabilitySTGExecution
95
Edit Score