2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51628 — Incorrect: access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51628

Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51626 — Incorrect: access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51626

Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51622 — Incorrect: access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51622

Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 20:18Z
CRIT

CVE-2026-51611 — Incorrect: access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51611

Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message. CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-28 18:37Z
INFO

v1.7.6

Sliver releases·github.com

Sliver v1.7.6 release includes bug fixes and stability improvements across implant execution, DNS handling, memory allocation bounds, and extension management. Notable fixes address nil pointer dereferences, unbounded PNG decoding, proxy header leaks, and WireGuard multiplayer mode defaults.

SWSliverVNDBishopfoxTYPTool
52
Edit Score
2w ago
2026-08-28 16:18Z
HIGH

CVE-2026-82227 — Contributor: SQL Injection in WPBulky <= 1.2.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82227

Contributor SQL Injection in WPBulky <= 1.2.2 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDContributorTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2w ago
2026-08-28 16:18Z
CRIT

CVE-2026-82078 — Papercut Papercut_mf: If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82078

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server proc CVSSv3.1 9.1 (CRITICAL) · EPSS 38th percentile

CWECWE 470VNDPapercutTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-08-28 16:18Z
CRIT

CVE-2026-81578 — Papercut Papercut_mf: This allows an unauthenticated remote attacker to modify certain system configurations.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81578

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations. CVSSv3.1 9.8 (CRITICAL) · EPSS 32th percentile

CWECWE 305VNDPapercutTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-28 16:18Z
HIGH

CVE-2026-50979 — A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50979

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter CVSSv3.1 8.1 (HIGH)

CWECWE 77TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-28 16:17Z
CRIT

CVE-2026-37751 — An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-37751

An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-28 16:17Z
CRIT

CVE-2026-37236 — grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-37236

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs. CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 639TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-08-28 14:57Z
HIGH

Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!

Metasploit Framework 6.5.3 release adds 16 new modules covering scanner capabilities for Drupal, PAN-OS, WordPress, and SCADA systems, plus exploit modules for Tenable Security Center, Flowise, CheckPoint, Langflow, Ruby on Rails, and SPIP. The release includes multiple RCE, LFI, and SQLi exploits alongside payload enhancements and bug fixes.

SRFApplicationSRFNetwork ApplianceSRFWebSWMetasploitSWDrupalSWWordpressSWLangflowSWFlowise
72
Edit Score
2w ago
2026-08-28 12:16Z
HIGH

CVE-2026-82245 — Budibase: before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82245

Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers with basic user privileges can access /api/global/license/* endpoints to disable premium features and downgrade deployments for all users. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDBudibaseTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-28 12:16Z
CRIT

CVE-2026-82244 — Budibase: versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82244

Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball. The server calls eval() on plugin JavaScript files without sandboxing in the main Node.js process, enabling attackers to exfiltrate environment variables and credentials with root privileges in default deployments. CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDBudibaseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 12:16Z
HIGH

CVE-2026-82240 — Budibase: Attackers can submit crafted requests to the user update API with builder.apps fields to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82240

Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate privileges and gain unauthorized builder access to other applications in the same tenant. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDBudibaseTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-28 12:16Z
HIGH

CVE-2026-82239 — Budibase: Attackers with BASIC role can submit crafted query requests with target table identifiers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82239

Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDBudibaseTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-08-28 12:16Z
HIGH

CVE-2026-82234 — SiYuan: Attackers can use DNS rebinding to answer the guard resolution with a public IP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82234

SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time without validating the connect-time resolution. Attackers can use DNS rebinding to answer the guard resolution with a public IP and the connect resolution with a private or metadata IP, bypassing the SSRF defense to access cloud instance metadata and internal services. CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDSiyuanTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-08-28 12:16Z
CRIT

CVE-2026-82222 — Deserialization: of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82222

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1. CVSSv3.1 10.0 (CRITICAL)

CWECWE 502TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-08-28 12:16Z
CRIT

CVE-2026-42007 — An attacker that has valid credentials can use a Sieve script with the editheader

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42007

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vu CVSSv3.1 9.1 (CRITICAL)

CWECWE 416TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-08-28 10:09Z
CRIT

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

Rapid7 Research·rapid7.comin the wild0day

PaperCut NG and MF are under active exploitation for a critical zero-day authentication bypass leading to remote code execution. The vulnerability chains an Apache Tapestry framework misconfiguration (bypassing authentication via Error/Exception pages) with JDBC SQL injection through external database lookup settings, ultimately executing arbitrary OS commands via H2 database INIT statements and Nashorn JavaScript. Emergency patches were released August 28, 2026 for versions 25 and 26; version 24 patch is pending.

SRFApplicationTACTA0001TACTA0002SRFWebSWPapercut MfSWPapercut NgVNDPapercutTYPResearch
95
Edit Score
2w ago
2026-08-28 08:16Z
HIGH

CVE-2026-80724 — Linux: In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80724

In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming writable vmclock_miscdev_mmap() rejects writable mappings of the shared vmclock ABI page with -EROFS, but leaves VM_MAYWRITE set. Userspace can map the page read-only and then upgrade it to writable with mprotect(), after which the guest can corrupt the host-written timekeeping data (sequence counter, UTC time, TSC offset) that the vmclock ABI defines CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-28 08:16Z
HIGH

CVE-2026-80723 — Linux: In the Linux kernel, the following vulnerability has been resolved: of: reserved_mem: prevent OOB

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80723

In the Linux kernel, the following vulnerability has been resolved: of: reserved_mem: prevent OOB when too many dynamic regions are defined On boot, fdt_scan_reserved_mem() saves each dynamically-placed /reserved-memory subnode into a local array of size MAX_RESERVED_REGIONS. If the device tree defines more than MAX_RESERVED_REGIONS dynamically-placed regions, fdt_scan_reserved_mem() writes past the end of the local array. Add a bounds check that logs an error and skips t CVSSv3.1 8.4 (HIGH)

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2w ago
2026-08-28 08:16Z
HIGH

CVE-2026-80722 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80722

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params before driver setup ieee80211_process_rx_twt_action() only partially validates a received S1G TWT setup frame before queueing it. An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup() with twt->length too short for the full struct ieee80211_twt_params. The individual path passes twt to drv_add_twt_setup(). Both the tracepoint and the driver CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-28 08:16Z
HIGH

CVE-2026-80721 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80721

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon references in iso_conn After iso_conn_del(), ISO sockets should not dereference the hcon any more. Currently, clearing iso_conn::hcon relies on iso_conn_del() releasing the last reference to the iso_conn. Simplify this by explicitly clearing conn->hcon in iso_conn_del(), to avoid more complex reasoning on races about who holds the last reference. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-08-28 08:16Z
CRIT

CVE-2026-80714 — Linux: In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80714

In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before their destination exists. When the destination is later added, ip_vs_bind_dest() copies connection flags from the destination into cp->flags. IP_VS_CONN_F_ONE_PACKET connections are not synced. If a synced connection inherits IP_VS_CONN_F_ONE_PACKET while it is already hashed, expiry can treat it as a one-packet CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score