All coverage
Critical OS command injection in Splunk AI Toolkit (CVE-2026-20266, CVSS 9.1) lets admins run arbitrary host commands. Patch to 5.7.4 now. # Splunk # CVE # OSCommandInjection # Vulnerability # InfoSec # PatchNow # AISecurity https:// securityonline.info/splunk-ai- toolkit-cve-2026-20266/?utm_source=mastodon&utm_medium=jetpack_social
Splunk patches three critical embedded report flaws (CVE-2026-76310, CVSS 9.4) that let unauthenticated users affect system integrity. # Splunk # CVE # AccessControl # SplunkEnterprise # Vulnerability # InfoSec # PatchNow https:// securityonline.info/splunk-ent erprise-cve-2026-76310/?utm_source=mastodon&utm_medium=jetpack_social
Splunk patches CVE-2026-76404, a critical remote code execution flaw in the MCP Server app, plus 16 more bugs across its apps and add-ons. # Splunk # CVE # RemoteCodeExecution # RCE # MCPServer # Deserialization # InfoSec # PatchNow https:// securityonline.info/splunk-app s-cve-2026-76404/?utm_source=mastodon&utm_medium=jetpack_social
Splunk Patches Critical MCP Server RCE and 16 Other Security Flaws Across AI Toolkit, Kafka Apps Splunk has released security updates for 17 vulnerabilities affecting several apps and add-ons, including Splunk MCP Server, Splunk AI Toolkit, and Splunk Connect for Kafka. The most severe issue, tracked as CVE-2026-76404, is a critical remote code execution vulnerability with a CVSS score of 9.1. The
CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM https:// securityonline.info/cve-2026-4 7301-sccm-system-rce/?utm_source=mastodon&utm_medium=jetpack_social
A vm2 sandbox escape (CVE-2026-47686, CVSS 9.9) with public PoC lets attackers hijack the host. Two more critical flaws also patched. Update to 3.11.6. # vm2 # CVE202647686 # SandboxEscape # RCE # NodeJS # InfoSec https:// securityonline.info/vm2-sandbo x-escape-cve-2026-47686/?utm_source=mastodon&utm_medium=jetpack_social
A critical Dell PowerStore vulnerability, CVE-2026-67271 (CVSS 9.8), allows unauthenticated remote code execution via SMB. Two more flaws patched. # DellPowerStore # CVE202667271 # RCE # SMB # Storage # InfoSec http:// securityonline.info/dell-power store-vulnerability-cve-2026-67271/?utm_source=mastodon&utm_medium=jetpack_social
CVE-2026-63037: Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint Posted by Charles Zhang on Aug 20 Severity: moderate Affected versions: - Apache InLong 2.0.0 before 2.4.0 Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY
An Apache InLong SQL injection flaw, CVE-2026-63038, lets attackers inject SQL via multiple parameters. Two more bugs join it. Upgrade to 2.4.0. # ApacheInLong # SQLInjection # CVE # SSRF # InfoSec # OpenSource https:// securityonline.info/apache-inl ong-sql-injection-cve-2026-63038/?utm_source=mastodon&utm_medium=jetpack_social
Two critical Spring Integration vulnerabilities, CVE-2026-59307 and CVE-2026-59324, expose systems to remote code execution and data leakage. Update now. # SpringIntegration # CyberSecurity # CVE202659307 # CVE202659324 # Vulnerability https:// securityonline.info/spring-int egration-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
CISA has added two known vulnerabilities to the KEV catalogue. - CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability https://www. cve.org/CVERecord?id=CVE-2026- 72529 - CVE-2026-72530: TrueConf Server Code Injection Vulnerability https://www. cve.org/CVERecord?id=CVE-2026- 72530 # CISA Yesterday: Cisco: CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-2
Google patches CVE-2026-76017, a critical use-after-free in Chrome, among 7 security fixes. Update to 151.0.7922.173 or later now. # Chrome # CVE # UseAfterFree # Google # BrowserSecurity # InfoSec # PatchNow https:// securityonline.info/chrome-cve -2026-76017/?utm_source=mastodon&utm_medium=jetpack_social
CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now. # TrueConf # CVE # ExploitedInTheWild # PhantomCore # HeadMare # InfoSec # PatchNow https:// securityonline.info/trueconf-c ve-2026-72529-exploited/?utm_source=mastodon&utm_medium=jetpack_social
PoC exploit code for CVE-2026-52929, a Linux kernel SCTP flaw, is public. A video shows root privilege escalation on Ubuntu 26.04. # CVE202652929 # LinuxKernel # SCTP # PrivilegeEscalation # PoC # infosec https:// securityonline.info/cve-2026-5 2929-sctp-privilege-escalation/?utm_source=mastodon&utm_medium=jetpack_social
CVE-2026-77176 lets a malicious operator mount arbitrary guest rootfs paths in Kata Containers Confidential Containers setups. Update to Kata 4.1.0. # CVE202677176 # KataContainers # ConfidentialContainers # CloudSecurity # genpolicy # infosec https:// securityonline.info/cve-2026-7 7176-kata-containers-guest-rootfs/?utm_source=mastodon&utm_medium=jetpack_social
Four Spring Security vulnerabilities were disclosed, led by CVE-2026-59270 (CVSS 9.4). Attackers can read or modify entries in the in-memory directory. # SpringSecurity # CVE202659270 # LDAP # WebAuthn # DPoP # AppSec https:// securityonline.info/spring-sec urity-vulnerabilities-cve-2026-59270/?utm_source=mastodon&utm_medium=jetpack_social
CVE-2026-69836, a CVSS 10 Entra ID remote code execution flaw, was exploited in the wild. Microsoft has fully mitigated it server-side. # CVE202669836 # EntraID # RemoteCodeExecution # Microsoft # CloudSecurity # RCE https:// securityonline.info/cve-2026-6 9836-entra-id-rce/?utm_source=mastodon&utm_medium=jetpack_social
CVE-2026-19586 (CVSS 9.3) is a pre-authentication OS command injection flaw in Omada gateways. TP-Link has released fixed firmware. # Omada # TPLink # CVE202619586 # CommandInjection # OpenVPN # NetworkSecurity https:// securityonline.info/cve-2026-1 9586-omada-command-injection/?utm_source=mastodon&utm_medium=jetpack_social
CVE-2026-77647, a CVSS 9.8 unauthenticated RCE in SPIP before 4.4.20, is exploited in the wild. Update now. # SPIP # CVE202677647 # RCE # ExploitedInTheWild # CMS # WebSecurity https:// securityonline.info/cve-2026-7 7647-spip-rce/?utm_source=mastodon&utm_medium=jetpack_social
CISA confirmed active exploitation of CVE-2026-33824, an unauthenticated Windows IKE double-free flaw patched in April, ordering federal agencies to remediate within three days. # CVE202633824 # Windows # CISA # IKE # Vulnerability https:// meterpreter.org/cve-2026-33824 -windows-ike-exploited/?utm_source=mastodon&utm_medium=jetpack_social
🔴 EXPLOITED TrueConf Server has two exploited flaws (CVE-2026-72529/72530) that chain over port 4307 to code execution on the host. Affects self-hosted TrueConf before 5.5.5 / 5.4.9 / 5.3.9. Now CISA KEV-listed. Patch, then hunt. CISA added two actively exploited TrueConf Server flaws (CVE-2026-72529, CVE-2026-72530) to its KEV catalog.
🔴 EXPLOITED TrueConf Server has two exploited flaws (CVE-2026-72529/72530) that chain over port 4307 to code execution on the host. Affects self-hosted TrueConf before 5.5.5 / 5.4.9 / 5.3.9. Now CISA KEV-listed. Patch, then hunt. https:// suriq.io/blog/trueconf-server- flaws-cisa-kev-exploited # CVE # CloudSecurity # CISAKEV # infosec
IBM AIX vulnerabilities include remote code execution flaws rated up to CVSS 9.9. Patch AIX 7.2, 7.3, and PowerVM VIOS 4.1 now. # IBMAIX # RCE # VIOS # Vulnerability # PatchNow # InfoSec https:// securityonline.info/ibm-aix-vu lnerabilities-rce/?utm_source=mastodon&utm_medium=jetpack_social
🔴 EXPLOITED SPIP, a widely used open-source website system, has a critical flaw (CVE-2026-77806, CVSS 9.8) that lets anyone run commands on the server with no login. It's being exploited now. Sites patched only to 4.4.20 are still exposed. Fix: update to SPIP 4.4.21. https:// suriq.io/blog/spip-unauthentic ated-rce-cve-2026-77806 # CVE # infosec # cybersecurity
CVE-2026-69836 | 10.0 Critical | Remote Code Execution Vulnerability impacting Entra ID → An unauthenticated attacker could send specially crafted serialized data to Entra ID to achieve remote code execution without user interaction. → Microsoft has confirmed this vulnerability was exploited in the wild prior to disclosure and has already fully mitigated the issue on its infrastructure; no custome
Apache CloudStack patched 20 flaws. CVE-2026-50112, a critical bug, allows cross-tenant remote code execution as root on KVM hypervisor hosts. # ApacheCloudStack # CVE202650112 # RCE # KVM # CloudSecurity # IaaS https:// securityonline.info/cve-2026-5 0112-cloudstack-rce/?utm_source=mastodon&utm_medium=jetpack_social
CVE-2026-19598, a CVSS 9.8 flaw in the Pods WordPress plugin, enables complete site takeover. Wordfence is already blocking attacks in the wild. # Pods # CVE202619598 # WordPress # PrivilegeEscalation # SiteTakeover # WebSecurity https:// securityonline.info/cve-2026-1 9598-pods-site-takeover/?utm_source=mastodon&utm_medium=jetpack_social
CVE-2026-75501 exposes an unauthenticated UPnP service on Calix routers. Public details and PoC code show how attackers bypass NAT and firewall protections. # CVE202675501 # Calix # UPnP # RouterSecurity # NAT # IoTSecurity https:// securityonline.info/cve-2026-7 5501-calix-upnp-nat-bypass/?utm_source=mastodon&utm_medium=jetpack_social
CVE-2026-77806, a CVSS 9.8 SPIP unauthenticated RCE, is exploited in the wild. A public Metasploit module and full details are now available. # CVE202677806 # SPIP # RCE # ExploitedInTheWild # Metasploit # CMS https:// securityonline.info/cve-2026-7 7806-spip-unauthenticated-rce/?utm_source=mastodon&utm_medium=jetpack_social
⚪️ CVE Pitfalls: Identifying Bogus Vulnerabilities and Building Exploits with ChatGPT 🗨️ What do we look at first when we come across yet another CVE? That’s right—the severity rating, i.e., the CVSS score. However, this number does not always reflect the vulnerability’s real-world risk. In this article, I’ll use examples to show how that can happen and discuss other issues with CVEs… 🔗 https://
CVE-2026-49849 (CRITICAL): 4xmen xShop <3.0.4 lets authenticated admins upload dangerous files, leading to remote code execution 🛡️. Patch to 3.0.4 now. https:// radar.offseq.com/threat/cve-20 26-49849-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-4xmen-xshop-bbb8f71dbe4a15a6 # OffSeq # CVE202649849 # remotecodeexecution # infosec
CVE-2026-77415 (CRITICAL, CVSS 9.3) in jsonata-js (<1.8.8, <2.2.1): Attackers can chain object-integrity flaws to achieve arbitrary code execution. Patch to 1.8.8/2.2.1 ASAP. Details: https:// radar.offseq.com/threat/cve-20 26-77415-cwe-94-improper-control-of-generation-of-code-code-injection-in-jsonata-js-jsonata-b49c30a44f0e9211 # OffSeq # jsonata # security # vuln
CRITICAL: CVE-2026-77414 in jsonata-js (<1.8.8, <2.2.1) enables remote code execution via code injection (CWE-94). Update to 1.8.8/2.2.1 now. No workaround. Details: https:// radar.offseq.com/threat/cve-20 26-77414-cwe-94-improper-control-of-generation-of-code-code-injection-in-jsonata-js-jsonata-247817ff13af01bb # OffSeq # CVE202677414 # infosec # security
jsonata-js (<1.8.8, <2.2.0) is affected by CRITICAL CVE-2026-77413 (CVSS 9.3) due to a code injection flaw in the lookup function. Attackers can execute arbitrary code remotely. Upgrade to 1.8.8 or 2.2.0+ ASAP. https:// radar.offseq.com/threat/cve-20 26-77413-cwe-94-improper-control-of-generation-of-code-code-injection-in-jsonata-js-jsonata-43a95a44c76d7f7e # OffSeq # CVE # infosec # security
CVE-2026-61539: CRITICAL RCE in xorbitsai Xinference <=2.5.0 — attacker-controlled input reaches Python eval(), enabling unauthenticated code execution. Patch to 2.7.0. CVSS: 10.0 🛡️ https:// radar.offseq.com/threat/cve-20 26-61539-cwe-95-improper-neutralization-of-directives-in-dynamically-evaluated-code-eval-03188a31614e6f78 # OffSeq # CVE202661539 # infosec # remotecodeexecution
CVE-2026-78136: HIGH severity eval injection in chirpmyradio CHIRP (<39178db). Malicious CSV data can trigger arbitrary code execution. No patch yet — avoid untrusted files. Full details: https:// radar.offseq.com/threat/cve-20 26-78136-cwe-95-improper-neutralization-of-directives-in-dynamically-evaluated-code-eval-1763cf4fec8c29f0 # OffSeq # chirpmyradio # Vulnerability # InfoSec
A critical EverShop account takeover flaw, CVE-2026-72843, exposes systems to an eCommerce platform vulnerability. Update to version 2.2.1 immediately. # EverShop # CyberSecurity # CVE202672843 # Vulnerability # eCommerce https:// securityonline.info/evershop-c ve-2026-72843-account-takeover/?utm_source=mastodon&utm_medium=jetpack_social
Critical GitLab vulnerability CVE-2026-19478 lets unauthenticated attackers delete public projects. It is exploited in the wild with public PoC. # GitLab # CVE202619478 # Vulnerability # InfoSec # CyberSecurity # PatchNow https:// securityonline.info/gitlab-cve -2026-19478/?utm_source=mastodon&utm_medium=jetpack_social
📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17) See more at https:// secdb.nttzen.cloud/dashboard Total CVEs: Severity: - Critical: 515 - High: 1465 - Medium: 1011 - Low: 196 - None: 372 Status: - : 66 - Analyzed: 407 - Awaiting Analysis: 323 - Deferred: 288 - Modified: 30 - Received: 1755 - Rejected: 84 - Undergoing Analysis: 606 CISA KEVs: - CISA-2026:0817 ( https:// secdb.nttzen.cloud