Tag
Multiple Vulnerabilities in PHP Runtime Environment
Multiple vulnerabilities across several PHP versions allow remote attackers to cause denial-of-service, access sensitive data, and compromise data integrity.
Multiple Vulnerabilities in PaperCut Software
4 CVEsPaperCut has released security updates addressing critical vulnerabilities including remote code execution, unauthorized data access, and XSS across PaperCut Hive and PaperCut NG/MF platforms.
Security Policy Bypass in Forcepoint Security Engine (NGFW)
1 CVEForcepoint has disclosed CVE-2026-12974, a security policy bypass vulnerability affecting multiple versions of the Forcepoint Security Engine (NGFW) that requires urgent administrative review and patching.
Vulnerabilities in Erlang/OTP
2 CVEsMultiple security vulnerabilities identified in Erlang/OTP across various version branches require immediate patching to mitigate potential risks.
Critical Vulnerabilities Patched in Cisco FMC, ISE, and Nexus Dashboard
2 TTPs 3 CVEsCisco has released emergency patches for dozens of critical vulnerabilities across Identity Services Engine (ISE), Secure Firewall Management Center (FMC), and Nexus Dashboard, including several flaws currently exploited in the wild.
CSRF Vulnerability in phpList Mass Subscriber Removal
1 TTP 1 CVEphpList versions prior to 3.6.17 are vulnerable to CSRF, allowing an attacker to force an authenticated administrator to delete or blacklist subscribers without authorization.
Hard-coded Cryptographic Keys in Wärtsilä FOS-Onboard
2 TTPsWärtsilä FOS-Onboard version 5.07.0923.01 contains hard-coded cryptographic keys in the Update Controller and robot testing framework that could facilitate unauthorized code execution, update deployment, and credential theft.
Multiple Critical Vulnerabilities in MongoDB Drivers and Core Server
3 CVEsMultiple vulnerabilities across MongoDB drivers and the Core Server identified on September 10-11, 2026, pose risks of remote denial-of-service, unauthorized data access, and integrity compromise.
Critical Security Updates for Ivanti Endpoint Manager Mobile, Neurons for ITSM, and Sentry
2 CVEsIvanti released security patches for multiple products, including Endpoint Manager Mobile, Neurons for ITSM, and Sentry, addressing vulnerabilities identified as CVE-2026-18851 and CVE-2026-83527.
Arbitrary Command Execution in Snipe-IT Backup Restoration
1 rule 14 TTPs 1 CVESnipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.
Multiple Vulnerabilities in strongSwan
Multiple vulnerabilities, including remote code execution and security policy bypass, have been disclosed in strongSwan versions prior to 6.1.0.
Multiple Vulnerabilities in SonicWall Network Security Manager
SonicWall Network Security Manager (NSM) versions prior to 4.3.1-R4 contain multiple vulnerabilities, including CVE-2026-78327, CVE-2026-78328, and CVE-2026-81939, that allow for remote code execution, privilege escalation, and security policy bypass.
Cisco Releases Patches for Critical Infrastructure Vulnerabilities
2 TTPs 5 CVEsCisco has issued security advisories for unpatched S/MIME vulnerabilities in Secure Email and critical RCE and authentication bypass flaws across its IOS XR, Nexus, and VoIP phone product lines.
Critical Vulnerabilities in Progress Telerik UI for ASP.NET AJAX
2 CVEsProgress Software has patched two vulnerabilities, including path traversal (CVE-2026-18672) and input tampering (CVE-2026-19219), in Telerik UI for ASP.NET AJAX versions prior to 2026.3.812.
Multiple Vulnerabilities in Curl
Multiple vulnerabilities were discovered in the Curl library (versions 7.44.0 through 8.21.x), potentially allowing attackers to compromise data integrity, confidentiality, or bypass security policies.
Security Constraint Bypass in VMware Tanzu Spring Framework
1 CVEA vulnerability in VMware Tanzu Spring Framework identified as CVE-2024-38816 allows a remote, unauthenticated attacker to bypass security restrictions.
SSRF Vulnerability in SiYuan via DNS Rebinding
2 rules 6 TTPs 1 CVESiYuan versions prior to 3.8.1 are vulnerable to server-side request forgery through a DNS rebinding attack, enabling unauthorized access to cloud metadata services and internal network resources.
Security Vulnerabilities in Plesk Management Interface and Extensions
2 CVEsWebPros has released security updates for Plesk and its Migrator and Site Import extensions to address critical vulnerabilities CVE-2026-65642 and CVE-2026-65647.
Cross-Site Scripting Vulnerability in Element maps-ng
1 CVEA stored cross-site scripting (XSS) vulnerability in the si-map component of Element maps-ng allows unauthenticated attackers to execute arbitrary scripts in a victim's browser via crafted map pin tooltips.
Multiple Vulnerabilities in Google Chrome and Microsoft Edge
1 TTP 2 CVEsMultiple vulnerabilities in Google Chrome and Microsoft Edge allow remote, unauthenticated attackers to achieve arbitrary code execution, bypass sandbox protections, and perform information disclosure.
Multiple Vulnerabilities in Oracle Hyperion
2 CVEsOracle has disclosed a series of 25 vulnerabilities affecting Hyperion, enabling remote, anonymous, or authenticated attackers to compromise system confidentiality, integrity, and availability.
Mattermost Security Update for CVE-2026-9816
1 CVEMattermost has released critical security patches for multiple versions to address vulnerabilities tracked under CVE-2026-9816.
Multiple Vulnerabilities in WordPress
1 CVE 1 IOCMultiple vulnerabilities, including CVE-2026-64638, affect WordPress versions prior to 7.0.3, enabling privilege escalation, data breaches, and Server-Side Request Forgery (SSRF).
Critical Security Vulnerabilities in Progress MarkLogic Server
5 CVEs 2 IOCsProgress Software has released a security bulletin addressing ten critical vulnerabilities, including CVE-2026-7326 through CVE-2026-9203, affecting MarkLogic Server versions prior to 11.3.6 and 12.0.3.
Multiple Vulnerabilities in Nextcloud Products
Multiple vulnerabilities, including CVE-2026-61527 and CVE-2026-61545, affect Nextcloud Server and Mail components, posing risks to data confidentiality and security policy enforcement.
Vulnerabilities in MISP cti-transmute
3 IOCsThe MISP project has patched multiple security vulnerabilities in the cti-transmute tool, including arbitrary file/network access and improper authorization controls for user management.
Multiple Vulnerabilities in GitLab
5 CVEsMultiple security vulnerabilities identified in GitLab CE and EE versions 19.x can result in remote denial of service, data confidentiality breaches, and reflected cross-site scripting.
Progress Software Security Advisory Addresses Multiple Vulnerabilities
5 CVEsProgress Software has issued a security advisory (AV26-755) addressing multiple vulnerabilities, identified by CVEs CVE-2026-59686 through CVE-2026-59690, across several of its products including ECS Connection Manager, LoadMaster, MOVEit WAF, Multi Tenant, and Object Scale Connection Manager, with specific versions prior to various patch levels being vulnerable, urging administrators to apply necessary updates to secure their systems.
Information Published for CVE-2026-64191
1 CVEInformation has been published regarding CVE-2026-64191, which addresses an issue in the i2c stub related to rejecting I2C block transfers with invalid lengths.
Juniper Networks Releases Security Advisories for Multiple Vulnerabilities, Including Heap Buffer Overflow and Memory Leak
2 TTPs 1 CVEJuniper Networks has released security advisories to address multiple vulnerabilities across several products, including Juniper cRPD, CTPView, Network Director, Junos OS, Junos OS Evolved, Junos OS on MX Series with SPC3 and SRX Series, and Junos Space, with key vulnerabilities like a heap buffer overflow (CVE-2020-7450) and a memory leak (CVE-2026-33799) potentially leading to arbitrary code execution or denial of service.
Multiple Vulnerabilities in Google Chrome (CVE-2026-13774 through CVE-2026-13895)
5 CVEs 5 IOCsMultiple vulnerabilities, including CVE-2026-13774 through CVE-2026-13895, have been discovered in Google Chrome, allowing an attacker to cause an unspecified security problem on affected Windows, Linux, and macOS systems by exploiting these flaws.
Progress Security Advisory (AV26-552) Addressing Multiple Critical Vulnerabilities
3 rules 1 TTP 5 CVEs 4 IOCsProgress released critical security advisories between June 2 and 4, 2026, addressing multiple vulnerabilities, including CVE-2026-7312, CVE-2026-7198, CVE-2026-7195, CVE-2026-7201, CVE-2026-7313, CVE-2026-8037, and CVE-2026-33691, in Sitefinity CMS, Sitefinity Insight, and Progress Kemp LoadMaster, which could lead to various impacts if exploited, necessitating immediate patching.