2w ago
2026-08-31 14:17Z
CRIT

CVE-2026-51675 — Incorrect: access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51675

Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 14:17Z
CRIT

CVE-2026-51674 — Incorrect: access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51674

Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 14:17Z
CRIT

CVE-2026-51672 — Incorrect: access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51672

Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 14:17Z
CRIT

CVE-2026-51670 — Incorrect: access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51670

Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-31 14:17Z
CRIT

CVE-2026-51669 — Incorrect: access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51669

Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 13:18Z
CRIT

CVE-2026-82695 — The manipulation results in missing authentication.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82695

A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 10.0 (CRITICAL)

CWECWE 306CWECWE 287TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 13:18Z
CRIT

CVE-2026-82694 — Tenda: The manipulation leads to missing authentication.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82694

A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used. CVSSv3.1 10.0 (CRITICAL)

CWECWE 306CWECWE 287VNDTendaTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-08-31 13:18Z
CRIT

CVE-2026-82693 — Tenda: Executing a manipulation can lead to missing authentication.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82693

A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 10.0 (CRITICAL)

CWECWE 306CWECWE 287VNDTendaTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 13:18Z
CRIT

CVE-2026-82692 — Performing a manipulation of the argument alias/username/password/volume_location results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82692

A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. CVSSv3.1 9.9 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 13:18Z
HIGH

CVE-2026-5956 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5956

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects Site Management Panel: through 15062026. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 13:17Z
HIGH

CVE-2026-12894 — An attacker who can provide or influence the template text can exploit this bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12894

A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive Java internal functions when processing certain data types like Enums. An attacker who can provide or influence the template text can exploit this bypass to take control of the server by executing unautho CVSSv3.1 8.8 (HIGH)

CWECWE 1336TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 13:00Z
MED

Traefik | Version Through 3.7.11

Bishop Fox Labs·bishopfox.comCVE-2026-PENDING

Bishop Fox disclosed a vulnerability in Traefik reverse proxy (versions 2.8.2–2.11.55 and 3.0.0–3.7.11) where the request read timeout setting is not applied to HTTP/3 connections, allowing unauthenticated remote attackers to hold requests open indefinitely and exhaust upstream connection pools. The timeout is enabled by default (60 seconds) and documented without protocol qualification, creating a silent bypass on HTTP/3. Traefik Labs patched the issue in versions 2.11.56 and 3.7.12 within 12 days of disclosure.

SRFApplicationSRFNetwork ApplianceTACTA0040SWTraefikVNDTraefik LabsTYPVulnerabilitySTGImpactSTApatched
72
Edit Score
2w ago
2026-08-31 12:17Z
CRIT

CVE-2026-82691 — Such manipulation of the argument f_ups_ip leads to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82691

A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. CVSSv3.1 9.1 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 12:17Z
CRIT

CVE-2026-82690 — This manipulation of the argument f_dev causes os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82690

A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. CVSSv3.1 9.1 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 12:17Z
CRIT

CVE-2026-82689 — The manipulation of the argument upIsoRootPath results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82689

A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. CVSSv3.1 9.9 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 11:16Z
HIGH

CVE-2026-82876 — Phison: PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82876

Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitrary RSA key pairs, sign modified firmware with the private key, embed the matching modulus in the signature segment, and the controller accepts the tampered firmware as valid. CVSSv3.1 8.2 (HIGH)

CWECWE 347VNDPhisonTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-08-31 11:16Z
CRIT

CVE-2026-82688 — The manipulation of the argument f_sharename/f_target/f_name leads to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82688

A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. CVSSv3.1 9.1 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 11:16Z
HIGH

CVE-2026-82680 — Executing a manipulation can lead to out-of-bounds write.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82680

A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_file.cgi of the component Multipart Handler. Executing a manipulation can lead to out-of-bounds write. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-31 10:16Z
CRIT

CVE-2026-49003 — Attackers: can exploit command injection vulnerabilities to delete core system runtime files, causing the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49003

Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP, thereby tampering with critical system parameters and triggering abnormal operation of the entire power system. CVSSv3.1 9.6 (CRITICAL)

CWECWE 287VNDAttackersTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2w ago
2026-08-31 10:00Z
HIGH

Simulating legitimate Active Directory services on the network: the case of GPO exploitation

Synacktiv·synacktiv.comCVE-2026-54121CVE-2016-3223

Synacktiv published research on simulating authenticated Active Directory services (LDAP and SMB) on internal networks to enable GPO and container exploitation. The work extends prior GPOddity and OUned tooling by implementing a multiplexing SMB server in Scapy that properly handles multiple concurrent sessions over a single TCP connection—a capability missing from previous impacket-based implementations. The research demonstrates practical exploitation of gPCFileSysPath poisoning and gPLink attribute manipulation to achieve lateral movement and privilege escalation.

SRFApplicationTACTA0004SRFNetworkTACTA0008SWImpacketSWActive DirectorySWScapyTYPResearch
78
Edit Score
2w ago
2026-08-31 10:00Z
HIGH

ValleyRAT masquerading as adware

Kaspersky Securelist·securelist.comin the wild

Kaspersky researchers discovered ValleyRAT, a sophisticated backdoor distributed via a trojanized QN Wallpaper adware installer that masquerades as legitimate software (DingTalk, Chrome, Tencent Meeting). The malware uses DLL sideloading via libcef.dll to achieve code execution, implements anti-analysis techniques including Windows Defender disablement and process marking as critical, and provides full remote access capabilities including keylogging, clipboard theft, and module loading. Over 100,000 detections across 1,500+ users primarily in China and India are attributed to Silver Fox APT group.

SRFApplicationSRFOsTACTA0005TACTA0001TACTA0006TACTA0007TACTA0003TACTA0009
78
Edit Score
2w ago
2026-08-31 09:17Z
CRIT

CVE-2026-82874 — ToolJet: before v3.16.208 fails to validate that authenticated users belong to the organization specified

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82874

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract victim organization IDs from public app endpoints, then exploit schema operation endpoints to disclose table schemas, plant malicious tables, corrupt existing schemas, or permanently destroy victim data w CVSSv3.1 9.9 (CRITICAL)

CWECWE 639VNDTooljetTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2w ago
2026-08-31 09:17Z
CRIT

CVE-2026-82872 — ToolJet: before v3.16.208 fails to validate that the path organizationId matches the authenticated user's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82872

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests. CVSSv3.1 9.1 (CRITICAL)

CWECWE 639VNDTooljetTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-31 09:17Z
CRIT

CVE-2026-82870 — ToolJet: before v3.16.208 fails to validate organizationId ownership in database write and destroy routes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82870

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing organization-resolving guards to permanently delete tables, insert arbitrary data, and modify schemas across tenant boundaries on shared instances. CVSSv3.1 9.6 (CRITICAL)

CWECWE 639VNDTooljetTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2w ago
2026-08-31 09:17Z
HIGH

CVE-2026-82862 — Hulumi: Attackers can place malicious files in the workspace to execute arbitrary code during local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82862

Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution. CVSSv3.1 8.4 (HIGH)

CWECWE 426VNDHulumiTYPVulnerability
8.4
CVSS v3.1
92
Edit Score