CVE Radar
Welcome To CVE Radar

Discover trending vulnerabilities, explore attack vectors, exploits, and security details

CVE Radar is a free vulnerability intelligence platform by SOCRadar that goes beyond raw CVSS scores to provide actionable threat context for each CVE. Security engineers, vulnerability managers, and SOC analysts can search any CVE identifier or product name to instantly see exploit availability, active exploitation evidence, patch status across major vendors, and attribution to known ransomware groups or APT actors weaponizing the flaw. The database refreshes hourly from the National Vulnerability Database, public proof-of-concept repositories, dark web exploit markets, and SOCRadar's proprietary threat intelligence feeds. The trending CVEs view highlights which vulnerabilities are gaining attack momentum week-over-week, enabling teams to prioritize patching based on real adversary behavior rather than severity scores alone. No account or API key is required for lookups.

Top CVE Trend (Last 30 Days)
CVE-2026-63030
7.5/ 10
CVSS Score
83/ 100
SVRS Score
11.91M
Audience
188
Social Media
52
News
17
Repos
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
avatar
Attack Surface Management | Sn1perSecurity@Sn1perSecurity
13 days ago
wp2shell (CVE-2026-63030) is an unauthenticated RCE in WordPress Core 6.9.0-6.9.4 and 7.0.0-7.0.1. Get the Nuclei detection template and scan for it at scale with Sn1per. https://t.co/gqlXKr4qAG #attacksurface #attacksurfacemanagement #ASM #infosec #netsec https://t.co/Suumbc9Ck3
avatar
DFIR Radar@DFIR_Radar
13 days ago
CVE-2026-63030 (wp2shell) chains a REST API batch-route flaw with SQLi for unauthenticated RCE on default WordPress installs. Patch to 7.0.2 or 6.9.5 now; 6.8.6 fixes only the SQLi (CVE-2026-60137). #DFIR_Radar https://t.co/9LPOqMUFo7
avatar
/r/netsec@_r_netsec
13 days ago
wp2shell (CVE-2026-63030) update: public working exploit now available for the WordPress core pre-auth RCE https://t.co/OI6L8gcSD1
avatar
Zero Hunt@zerohuntai
13 days ago
wp2shell (CVE-2026-63030): unauthenticated RCE in WordPress Core — not a plugin. A REST batch route-confusion bug chained to a WP_Query SQL injection. Patched 7/17, public PoC 7/18. WordPress runs ~40% of the web. The actual fix 🧵 https://t.co/8hlfbyEhE5
avatar
Feng Xue@s0what
13 days ago
Kimi k3 repro of the wordpress RCE. The original thought for kimi was to read and brute force the admin password. #CVE-2026-63030 #wp2shell #Kimi3 #Wordpress https://t.co/6zWPKOCoJz
avatar
Humoud Almunawer حمود المناور@homoudalmonawer
13 days ago
The bugs: CVE-2026-63030 (unauthenticated RCE via the REST API) and CVE-2026-60137 (SQL injection). Both rated High, fixed in WordPress 7.0.2. Cloudflare's full advisory: https://t.co/bcjgeMkF0E
avatar
PCMedicalist@PCMedicalist
14 days ago
🟦 PCMedicalist Signal · Jul 18 CVE-2026-63030 is now in CISA KEV — Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy, a privileged function with no auth in front of it. We've built agent systems and on-chain infrastructure on Blue-Team discipline for 17 years. https://t.co/Y0Qrgkld60
avatar
PCMedicalist@PCMedicalist
14 days ago
🧠 Engineering & Research Digest (Jul 18) CVE-2026-63030 — CVE-2026-63030: wp2shell a Critical: patch CVE-2026-63030: wp2shell a Critical immediately — RCE exposure. Full digest 👇 — PCMedicalist Full digest 👇 via PCMedicalist
avatar
Aseem Shrey@AseemShrey
14 days ago
🚨 wp2shell : pre-auth RCE in WordPress core, reproduced end-to-end. Nested /batch/v1 "double confusion" · (CVE-2026-63030) → WP_Query SQLi · (CVE-2026-60137) → anonymous shell on a stock install. A couple of prompts later: · Opus 4.8 orchestrating, Sonnet agents https://t.co/vlwH7traXF
avatar
Dark Web Informer@DarkWebInformer
14 days ago
‼️ CVE-2026-63030: wp2shell, a critical remote code execution vulnerability in WordPress core Credit: @hash_kitten // @assetnote PoC 👇 https://t.co/X4jwoms2do
CVE-2026-60137
9.1/ 10
CVSS Score
94/ 100
SVRS Score
11.05M
Audience
125
Social Media
47
News
2
Repos
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
avatar
lee1981@lee1981b
13 days ago
🔥 CyberForge CVE of the Day CVE-2026-63030 + CVE-2026-60137 WP2Shell is a critical WordPress Core vulnerability chain combining REST route confusion with SQL injection. No account. No plugin. No user interaction. Potential result: database theft, admin takeover and RCE.
avatar
DFIR Radar@DFIR_Radar
13 days ago
WordPress Core RCE chain "wp2shell" (CVE-2026-63030 + CVE-2026-60137) enables unauthenticated attackers to reach full admin compromise and remote code execution. Emergency patches shipped July 17, 2026. - CVE-2026-63030 is a REST API auth bypass in https://t.co/KzkwjUQoRj
avatar
ProtAAPP - Protege las AAPP@ProtAAPP
13 days ago
Investigadores de Assetnote han descubierto dos vulnerabilidades en WordPress (CVE-2026-63030 y CVE-2026-60137) que permiten a un atacante anónimo ejecutar código en sitios 6.9 y 7.0. Se recomienda actualizar a la versión 6.9.5 o 7.0.2 para mitigar el… https://t.co/PmjQmZDbF5 https://t.co/OTQRIPottz
avatar
PCMedicalist@PCMedicalist
13 days ago
📰 Security News Roundup (Jul 19) CVE-2026-60137 — Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits: patch Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits and verify the fix held. Full brief 👇 — PCMedicalist https://t.co/5KqDfKw1Dp
avatar
baguette@pwn2baguette
13 days ago
Le nom induit en erreur. Ce n'est pas un "admin to shell". C'est du zéro-clic, zéro-compte. CVE-2026-63030 + CVE-2026-60137, deux bugs chaînés dans WordPress core, trouvés par Searchlight Cyber / Assetnote.
avatar
ExploitGrid@exploitgrid
13 days ago
🚨 "wp2shell": unauthenticated pre-auth RCE in WordPress Core 6.9.0–7.0.1. REST API dispatcher bug (CVE-2026-63030) chained with WP_Query SQLi (CVE-2026-60137) = full web shell, no creds, no plugins. ~500M sites exposed. Full blog https://t.co/hYhohv3G0h #WordPress #CVE #InfoSec
avatar
Xploitzone@Xploitzone_01
13 days ago
⚠️ Critical WordPress Alert A chain of two core flaws, CVE-2026-63030 & CVE-2026-60137, can give attackers remote code execution without authentication. If you run WordPress, patch NOW. 🔗 https://t.co/lG7u70nf7z #WordPress #InfoSec #CVE https://t.co/aQxXqadssY
avatar
DFIR Radar@DFIR_Radar
13 days ago
CVE-2026-63030 (wp2shell) chains a REST API batch-route flaw with SQLi for unauthenticated RCE on default WordPress installs. Patch to 7.0.2 or 6.9.5 now; 6.8.6 fixes only the SQLi (CVE-2026-60137). #DFIR_Radar https://t.co/9LPOqMUFo7
avatar
Humoud Almunawer حمود المناور@homoudalmonawer
13 days ago
The bugs: CVE-2026-63030 (unauthenticated RCE via the REST API) and CVE-2026-60137 (SQL injection). Both rated High, fixed in WordPress 7.0.2. Cloudflare's full advisory: https://t.co/bcjgeMkF0E
avatar
Aseem Shrey@AseemShrey
14 days ago
🚨 wp2shell : pre-auth RCE in WordPress core, reproduced end-to-end. Nested /batch/v1 "double confusion" · (CVE-2026-63030) → WP_Query SQLi · (CVE-2026-60137) → anonymous shell on a stock install. A couple of prompts later: · Opus 4.8 orchestrating, Sonnet agents https://t.co/vlwH7traXF
CVE-2020-24030
9.8/ 10
CVSS Score
84/ 100
SVRS Score
4.77M
Audience
26
Social Media
0
News
1
Repos
ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data via token reuse. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "not exploitable in the current implementation. Tokens are properly expired, invalidated, and bound to session context. Attempts to alter the token payload to extend its validity do not affect server-side validation."
avatar
JPC_WebTahiti@JPC_WebTahiti
2 days ago
Since 2020, 1 person has handled GNOME security reports. Not writing the fixes. The routing. Who gets told, when it goes public, which CVE number it gets. He stops taking new reports on November 1 and clears the rest by December. The role is open. He blogged about it.
avatar
intel@intel
2 days ago
Does the thought of AI finding and exploiting vulnerabilities that have been in the code for years keep you up at night? CVE-2026-4747, a 17-year-old remote code execution vulnerability in @FreeBSD, was autonomously exploited by Mythos. Here’s the good news to help you sleep https://t.co/nwBFQBpy0h
avatar
itarutomy@itarutomy
3 days ago
セキュリティ責任者(CISO)専用の業務基盤を掲げるPulse Security AIがステルスを解除し、Foundation Capital主導・Zetta Venture https://t.co/e5Gl7AdVyx
avatar
rst_cloud@rst_cloud
3 days ago
#threatreport #MediumCompleteness Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria | 29-07-2026 Source: https://t.co/AsIk8IZmcF Key details below ↓ 💀Threats: Dysphoria, Jackskid, Fbot, 🎯Victims: Iot devices, Routers, Gateways, Ip cameras, https://t.co/UqhFQZaAhc
avatar
fad_777@fad_777
3 days ago
ثغرة واحدة قبل المصادقة قد تعني سيطرة كاملة. بحث أمني على Liferay CE 7.0.3 GA4 أعاد تنفيذ RCE بصلاحيات root ضمن فئة CVE 2020 7961، مع 16 نتيجة إضافية. Pre auth RCE as root is a critical reminder: legacy enterprise platforms need continuous validation, not only patch tracking.
avatar
cybermsi@cybermsi
4 days ago
CVE Surge and NVD Infrastructure Crisis. 45,207 vulnerabilities logged this year, and the database meant to track them is breaking down. The U.S. National Vulnerability Database has recorded 45,207 CVEs year-to-date in 2026, already on pace to double last year's full-year total
avatar
BugsAggregator@BugsAggregator
4 days ago
[491191069] Vulnerability: CVE-2020-8910 affecting GitOnBorg::chrome-internal::chrome::zine-exp https://t.co/5giPbizdas
avatar
CTITraffic@CTITraffic
4 days ago
intrusiontruth: A recovered PLA 8th Technical Reconnaissance Bureau (Unit 61046) eDiary exposes APT15 espionage against governments across Africa and the Middle East, the African Union, and the Royal Thai Armed Forces. Access via Exchange CVE-2020-0688. https://t.co/Ujrl19tNtS
avatar
DFIR_Radar@DFIR_Radar
4 days ago
APT15 is the PLA Cyberspace Force's 8th Technical Reconnaissance Base. Leaked eDiary files tie years of Chinese 🇨🇳 military cyber operations directly to a unit designation, victims, and tooling. Key details: - Intrusion Truth traced RedRelay (also tracked as ORBWEAVER), a https://t.co/OJqEUIfAcZ
avatar
Dinosn@Dinosn
4 days ago
Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings (Kimi k3 on raptor) https://t.co/QSg5yFZsnp
CVE-2026-4747
8.8/ 10
CVSS Score
84/ 100
SVRS Score
4.47M
Audience
4
Social Media
6
News
0
Repos
Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow. Notably, this does not require the client to authenticate itself first. As kgssapi.ko's RPCSEC_GSS implementation is vulnerable, remote code execution in the kernel is possible by an authenticated user that is able to send packets to the kernel's NFS server while kgssapi.ko is loaded into the kernel. In userspace, applications which have librpcgss_sec loaded and run an RPC server are vulnerable to remote code execution from any client able to send it packets. We are not aware of any such applications in the FreeBSD base system.
avatar
The Circuitry@thecircuitry_
2 days ago
17-year-old CVE-2026-4747 remote code execution flaw in FreeBSD was autonomously exploited by Mythos. https://t.co/ye5rTfTRDN
avatar
Intel@intel
2 days ago
Does the thought of AI finding and exploiting vulnerabilities that have been in the code for years keep you up at night? CVE-2026-4747, a 17-year-old remote code execution vulnerability in @FreeBSD, was autonomously exploited by Mythos. Here’s the good news to help you sleep https://t.co/nwBFQBpy0h
avatar
zahradeen@zahradeenu7
3 days ago
The speed at which autonomous systems can unearth legacy bugs like CVE-2026-4747 definitely shifts the threat landscape. When AI can weaponize a 17-year-old stack-based buffer overflow in core kernel code almost instantly, relying solely on traditional patch cycles feels like
avatar
13.02 JB Countdown ⌛@dieramires
19 days ago
FreeBSD just got hit with a 17-year-old RCE bug (CVE-2026-4747), found and exploited autonomously by an AI. PS4 runs on a customized FreeBSD kernel. Nobody's confirmed a PS4 exploit chain from this - but we might be in for some big surprises soon. ps4 13.02 jb hen homebrew https://t.co/dznR6EEFbi
CVE-2026-16232
9.1/ 10
CVSS Score
82/ 100
SVRS Score
3.26M
Audience
95
Social Media
33
News
0
Repos
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
avatar
CTI Academy@CTIAcademy
3 days ago
CVE-2026-16232: a public proof of concept now exists for an actively exploited Check Point management bypass. Check Point patched the flaw on July 22, 2026 and disclosed that it had already been exploited as a zero-day against a handful of customers. CISA added it to the Known https://t.co/pikVT9uqhv
avatar
INFOSEC.WATCH@InfosecDotWatch
3 days ago
Check Point confirmed CVE-2026-16232 exploitation against directly exposed management systems. Patch the management plane, restrict Trusted Clients, remove public exposure, and review token plus admin activity.
avatar
Cybersecurity News Alerts@secureblognews
3 days ago
🚨 CRITICAL ZERO-DAY ALERT: CVE-2026-16232 is under active exploitation targeting Check Point gateways. Check impacted versions, attack vectors, and urgent patching mitigations now: https://t.co/Lcyfh7KFWX #CyberSecurity #ZeroDay #InfoSec
avatar
Xavier Rivera@XavierRiveraX
3 days ago
Check Point patched CVE-2026-16232, a 9.3-severity SmartConsole authentication bypass exploited as a zero-day against Security Management and Multi-Domain Security Management servers. A broken trust boundary let attackers forge the server's identity to mint a valid admin login
avatar
The Daily Tech Feed@dailytechonx
3 days ago
A critical zero-day vulnerability (CVE-2026-16232) in Check Point's SmartConsole allows unauthenticated attackers to gain full admin access. A proof-of-concept has been released, and active exploitation is confirmed. Organizations must apply patches immediately and restrict https://t.co/yYVIanS5dg
avatar
ro0TCr4k@ro0TCr4k
3 days ago
A critical authentication bypass flaw (CVE-2026-16232) in Check Point SmartConsole is actively exploited, granting attackers full admin access. RootCrak's autonomous scanning proactively identifies such severe configuration weaknesses and vulnerabilities before they are https://t.co/RG3XRokPAL
avatar
Cyber Security News@The_Cyber_News
3 days ago
⚠️ Check Point SmartConsole 0-Day Exploited to Gain Full Administrator Access - PoC Released Source: https://t.co/AHSFdXuBPJ A critical authentication bypass in SmartConsole that was actively exploited as a zero-day before patches were available. Tracked as CVE-2026-16232, the https://t.co/TZZ12ZPSfz
avatar
The Hacker News@TheHackersNews
3 days ago
🚨 Public PoC released for CVE-2026-16232, an actively exploited Check Point SmartConsole authentication bypass. The flaw lets unauthenticated attackers obtain full admin access to Security Management Server and MDS systems. See how it works: https://t.co/Wq2sCvKLCi
avatar
pdnuclei-bot@pdnuclei_bot
4 days ago
🚨 CVE-2026-16232 - critical 🚨 Check Point Security Management Server - SmartConsole Authentication Bypass > An authentication bypass vulnerability in the Check Point SmartConsole login process ... 👾 https://t.co/o0u43jBi3W @pdnuclei #Nuclei...
avatar
Daily CyberSecurity@Daily_CyberSec
4 days ago
CVE-2026-16232 is a SmartConsole authentication bypass in Check Point Security Management. Exploited in the wild, with a public PoC now available. #CheckPoint #SmartConsole #CVE202616232 #AuthenticationBypass #ZeroDay #CyberSecurity https://t.co/Ka2rPgh0Hd
CVE-2026-45659
8.8/ 10
CVSS Score
77/ 100
SVRS Score
3.08M
Audience
121
Social Media
50
News
0
Repos
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
avatar
CVE Brief@DailyCVEBrief
26 days ago
DEEP DIVE — CVE-2026-45659: an authenticated deserialization RCE in on-prem Microsoft SharePoint, CVSS 8.8. Microsoft called exploitation less likely; CISA added it to KEV on active abuse. A low-priv Site Member account is enough to run code. https://t.co/189gc1KyDR
avatar
AlphaHunt Converge@alphahunt_io
26 days ago
#CTI Brief for 2026-07-06 Control-plane risk is still the cyber signal to watch. CISA’s newest KEV remains SharePoint CVE-2026-45659, now past its remediation clock, while LiteLLM CVE-2026-42271 sits at EPSS 99.57% and can turn low-privilege AI-gateway access into host command
avatar
HackerStorm@hackerstorm
26 days ago
Weekly #CISA KEV Update (6 July 2026) CISA added 1 new Known Exploited Vulnerability to the KEV Catalog this week: 🔹 CVE-2026-45659 – Microsoft SharePoint Server ⚠️ Active exploitation confirmed 🎯 Remote Code Execution ⏱️ Immediate remediation recommended Our latest analysis https://t.co/usGjrOMv2I
avatar
Es Geeks@EsGeeks
27 days ago
🚨 CISA confirma explotación activa de RCE en SharePoint Server (CVE-2026-45659). Solo se necesitan permisos básicos de Site Member. Parche desde mayo, pero ya lo están usando en la vida real. Si tienes SharePoint on-premise: revisa parches YA. #SharePoint #CISA #CVE #Empresas https://t.co/QdlrnJS8Dw
avatar
Carlos Fynn@fynn_JourX
27 days ago
SharePoint CVE-2026-45659 active exploitation p… is the kind of management-plane bug defenders should move on fast. It combines active exploitation with security exposure and auth bypass risk in FortiClient EMS. When endpoint management infrastructure is exposed, the b…
avatar
Lucas@lucasverdan
27 days ago
SharePoint CVE-2026-45659 active exploitation p… is already being exploited, and Fortinet says the FortiClient EMS flaw carries security exposure and auth bypass risk. If you run 7.4.5 or 7.4.6, treat it as exposed management-plane risk and hotfix now.
avatar
Lucas@lucasverdan
27 days ago
🛑 SharePoint CVE-2026-45659 active exploitation puts on-prem servers on u… CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Details → https://t.co/DjxT4dttNT
avatar
JParticle 🇨🇦🇺🇦@JParticle0
27 days ago
Active Exploitation Alert: Critical Microsoft SharePoint Server RCE Vulnerability CVE-2026-45659 Added to CISA KEV Catalog https://t.co/LfYO8fWARK
avatar
CiberBaur@BotBauR
30 days ago
Acaba de confirmarse: La agencia de seguridad cibernética de EE. UU., CISA, agregó una vulnerabilidad de Microsoft SharePoint Server a su catálogo de vulnerabilidades explotadas conocidas, CVE-2026-45659, con una puntuación CVSS de 8.8. El fallo es una vulnerabilidad de https://t.co/tsfCLZ72Z1
avatar
Merge News@mergenewsapp
30 days ago
CISA warns of an actively exploited Microsoft SharePoint vulnerability (CVE-2026-45659) allowing arbitrary code execution. Patch immediately. #cisa #microsoft #sharepoint #vulnerability
SOCRadar LogoExtended Threat Intelligence
Free Trial

Stay ahead with proactive cyber threat warnings

Discover how SOCRadar's all-in-one platform can help protect your digital assets with extended threat intelligence, digital risk protection, and attack surface management.

CVE-2026-20316
5.3/ 10
CVSS Score
55/ 100
SVRS Score
2.88M
Audience
42
Social Media
19
News
0
Repos
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
avatar
HACKLIDO@hacklido
2 days ago
CISA Adds Cisco Secure Firewall Zero-Day (CVE-2026-20316) to Known Exploited Vulnerabilities Catalog https://t.co/cDHfd9pQNs
avatar
Julio Bandeira de Melo@juliobmelo
2 days ago
CISA added CVE-2026-20316 (Cisco Secure Firewall Management Center) to the KEV catalog with active exploitation evidence. The federal deadline under BOD 26-04 is August 1. The part that extends beyond federal agencies is straightforward: every organization using Cisco FMC now has
avatar
Wayne Markovich@markovichio
2 days ago
CVE-2026-20316 in Cisco Secure FMC is being actively exploited. Remote unauthenticated login to your firewall management plane is about as bad as it gets for perimeter control. Any AVD deployment with Cisco FMC in the network path needs this treated as emergency patching. (via
avatar
安全堂@anzendo
3 days ago
CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability. CVSS 5.3 https://t.co/JhXkqPEzo2
avatar
moton@moton
3 days ago
Cisco FMC Vulnerability CVE-2026-20316 Exploited - https://t.co/j1ZB635LP7
avatar
Erik Nonaka@enetechnologys2
3 days ago
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. https://t.co/kWwidhQ7S6 #Cisco #Vulnerability
avatar
Daily CyberSecurity@Daily_CyberSec
3 days ago
A Cisco FMC vulnerability, CVE-2026-20316, is exploited in the wild. Static credentials let attackers log in. CISA added it to KEV — patch now. #Cisco #CVE202620316 #FMC #KEV #Vulnerability #InfoSec https://t.co/AqV5e4WnCE
avatar
Trube Technologies@trubetech
3 days ago
Cisco warns of a high-severity FMC static credential vulnerability (CVE-2026-20316) being actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. Read the full analysis and guidance here: https://t.co/VEJ5sPHRyG
avatar
VulDB 🛡@vuldb
3 days ago
Attention, elevated activities detected targeting Cisco Secure Firewall Management Center (CVE-2026-20316) https://t.co/Wb6wRrSRE3
avatar
CISA Cyber@CISACyber
3 days ago
🛡️We added Cisco Secure Firewall Management Center use of hard-coded password vulnerability CVE-2026-20316 to our KEV Catalog. Visit https://t.co/2EEdX3edvs & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/gbGCyvQLYf
CVE-2026-50522
9.8/ 10
CVSS Score
90/ 100
SVRS Score
2.85M
Audience
90
Social Media
31
News
3
Repos
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
avatar
xer0dayz@xer0dayz
3 days ago
CVE-2026-50522: critical unauthenticated RCE in on-prem SharePoint Server (2016/2019/SE). Get the Nuclei detection template and scan at scale with Sn1per. https://t.co/iX35uDWlGF #infosec #netsec #bugbounty #redteam #offsec #infosecurity #CVE #exploit #CVE-2026-50522 https://t.co/6Vg5WTK60s
avatar
Attack Surface Management | Sn1perSecurity@Sn1perSecurity
3 days ago
CVE-2026-50522: critical unauthenticated RCE in on-prem SharePoint Server (2016/2019/SE). Get the Nuclei detection template and scan at scale with Sn1per. https://t.co/JwqujgcCVW #infosec #netsec #bugbounty #redteam #offsec #infosecurity #CVE #exploit #CVE-2026-50522 https://t.co/2xVnojKbUp
avatar
dbugs@ptdbugs
3 days ago
A PoC/exploit has been discovered for vulnerability CVE-2026-50522 PT ID: PT-2026-58208 Vendor: Microsoft Product: Microsoft SharePoint Enterprise Server 2016 Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute
avatar
DFIR Radar@DFIR_Radar
8 days ago
CVE-2026-50522 (CVSS 9.8) SharePoint deserialization is actively exploited: attackers steal machine keys in one request, making patching alone insufficient. #DFIR_Radar https://t.co/8vU1MkAvfr
avatar
the SE@theSEalpha
8 days ago
CISA added SharePoint CVE-2026-50522 to KEV after reports of machine-key theft. Zero Trust takeaway: patching closes the bug, not the trust you already leaked. Rotate machine keys, hunt forged-token persistence, and reduce internet exposure before calling it contained. https://t.co/7ByjFzLa5n
avatar
JNR Management@jnrmanagement
8 days ago
🚨 Fourth SharePoint Exploit in One Month — CVE-2026-50522 (CVSS 9.8) Actively Exploited, Attackers Stealing Machine Keys for Post-Patch Persistence, CISA KEV Listed. 👉 𝗥𝗲𝗮𝗱 𝗠𝗼𝗿𝗲: https://t.co/KzQZyhazVJ #CyberSecurity #JNRManagement #CISO #SharePoint https://t.co/OU4ypecTsV
avatar
0xbobaa@0xbobaaa
8 days ago
@Gustafssonkotte I don't understand what these numbers mean: CVE-2026-50522
avatar
Lucas@lucasverdan
9 days ago
🛑 SharePoint CVE-2026-50522 makes patching only the first step CISA added CVE-2026-50522 to KEV after reports of active SharePoint exploitation, making ke… 🔗 Details → https://t.co/uyZLNiaDDh
avatar
ByteDrop@ByteDrop453
10 days ago
Patched your SharePoint server already? That's not enough anymore. Attackers exploiting CVE-2026-50522 are stealing machine keys before you patch, then using them to stay in even after the fix is applied. The patch closes the door. It doesn't kick out who's already inside.
avatar
DCI CyberSec News@DCICyberSecNews
10 days ago
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC https://t.co/kSU6StwRjE via @TheHackersNews
CVE-2026-63077
9.8/ 10
CVSS Score
89/ 100
SVRS Score
2.53M
Audience
29
Social Media
13
News
0
Repos
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
avatar
Mitch (Casspari)@mitchcasspari
2 days ago
TeamCity: Kritische Lücke (CVE-2026-63077) ermöglicht Remote-Command-Execution ohne Authentifizierung: https://t.co/LndZWuBzV2 - #hacker #news #technology #technologie #it #informationstechnologie #hacking #computer #nerds #itsicherheit #itsecurity #itnews #cybercrime #cybersec…
avatar
Aviatrix Threat Research Center@aviatrixtrc
2 days ago
TRC analysis shows attackers exploited CVE-2026-63077 to execute arbitrary commands on JetBrains TeamCity servers without authentication. The compromise enabled lateral movement through CI/CD infrastructure and exfiltration of build artifacts. Runtime segmentation helps contain
avatar
Nicolas Krassas@Dinosn
3 days ago
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity https://t.co/TG9GdwU5TN
avatar
Rapid7@rapid7
3 days ago
🚨 On 7/27/26, #JetBrains published a security advisory for CVE-2026-63077, a critical vuln. affecting all versions of TeamCity On-Premises. Attackers who exploit the vulnerability can read stored credentials and compromise CI/CD pipeline integrity. More: https://t.co/sNPxEsR7df https://t.co/Zz9MJ2iCXs
avatar
JT Koffenberger@DMVG_JTK
3 days ago
CVSS 9.8, unauthenticated, sitting inside your CI/CD server. Read that one more time slowly. The new TeamCity On-Premises flaw (CVE-2026-63077) lets anyone with HTTP access to your build server skip the login and run OS commands. And your build server isn't some dusty box in the
avatar
CyberTLDR@CyberTLDR
3 days ago
2/3 CVE-2026-63077 is a pre-auth command injection in TeamCity On-Premises. Anyone who can reach the web interface can execute operating system commands as the service account, no credentials needed. #CVE #InfoSec #DevSecOps
avatar
Frontiera Tech@FrontieraTechIT
3 days ago
🛡️ BOLLETTINO CYBER | 29/07/2026 1. Vulnerabilità critica in JetBrains TeamCity (CVE-2026-63077) Rilevata una vulnerabilità critica di autenticazione bypass e remote code execution non autenticata. Un attaccante con accesso HTTP(S) al server può eseguire comandi arbitrari con i https://t.co/PR4NMLUSxV
avatar
NeoTeo.com@NeoteoCom
4 days ago
CVE-2026-63077 en TeamCity permite ejecutar comandos como root sin autenticarse. JetBrains ya publicó parches para todas las versiones on-premise. https://t.co/50w8aKW0XW
avatar
SecAlerts@SecAlertsCo
4 days ago
CVSS 9.8 vuln affects all JetBrains TeamCity On-Premises versions, could allow unauthenticated RCE. Info, incl. fix info, now at #SecAlerts: CVE-2026-63077, CVSS 9.8: https://t.co/H8mjYdp61L #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #CVE202663077 #JetBrains https://t.co/p9vVi4Efod
avatar
ExploitGrid@exploitgrid
5 days ago
[CVE] CVE-2026-63077 [HIGH PRIORITY] 🔗 https://t.co/gX70tj7Xcy
CVE-2026-20896
9.8/ 10
CVSS Score
87/ 100
SVRS Score
2.52M
Audience
57
Social Media
19
News
4
Repos
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
avatar
Roger Mitan@molari999
26 days ago
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure https://t.co/RRLxz2AnYb
avatar
Wes DeVault, CISSP@wvipersg
26 days ago
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure https://t.co/Me0mnOk1IQ
avatar
Todd Pigram@pigram86
26 days ago
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure https://t.co/oMUjHpU02D
avatar
Shah Sheikh@shah_sheikh
26 days ago
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure: Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is… https://t.co/uUlQd6a8cV https://t.co/Rlka4pKVLr
avatar
Eric Vanderburg@evanderburg
26 days ago
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure https://t.co/mujQdukl5H https://t.co/Y6I9Naiyq6
avatar
Jim Rigney@RigneySec
26 days ago
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure https://t.co/YuNcJCayJ4 https://t.co/WBnDAufBUN
avatar
The Cyber Security Hub™@TheCyberSecHub
26 days ago
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure https://t.co/9h5Slyn7wa
avatar
The Daily Tech Feed@dailytechonx
26 days ago
Threat actors are actively probing Gitea Docker vulnerability CVE-2026-20896, a critical flaw allowing unauthorized access via the 'X-WEBAUTH-USER' header. With over 6,200 internet-facing instances, immediate updates to version 1.26.3 are crucial to mitigate potential risks. https://t.co/dPAEaxZdJ6
avatar
The Hacker News@TheHackersNews
26 days ago
🚨 CVE-2026-20896 saw its first in-the-wild attempt 13 days after disclosure. The Gitea Docker flaw lets reachable containers trust spoofed X-WEBAUTH-USER headers when reverse proxy auth is enabled. See which setups are exposed and where the probe stopped: https://t.co/OItSUtmhVn
avatar
CCB Alert@CCBalert
26 days ago
Warning: Critical improper access control in #Gitea. CVE-2026-20896 CVSS: 9.8. This flaw allows an attacker to impersonate any user via crafted reverse-proxy headers! #Patch #Patch #Patch More info: https://t.co/TgXm3hP4gE
CVE-2026-0257
9.1/ 10
CVSS Score
84/ 100
SVRS Score
2.5M
Audience
46
Social Media
33
News
0
Repos
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
avatar
Picus Security@PicusSecurity
3 days ago
CVE-2026-0257: no credentials, no login, just a forged cookie and a VPN tunnel into your network. Reuse the PAN-OS cookie cert for HTTPS, and the attacker harvests the key over TLS. Full root-cause breakdown: https://t.co/PIraN12cgG https://t.co/HGCC01MDkD
avatar
omvapt@omvapt
9 days ago
#Qilin #Ransomware Affiliates Abuse CVE-2026-0257 to Gain #Unauthorized_VPN Access https://t.co/UA9BWeRneV https://t.co/Bm3VPjIPRF
avatar
Vistem Solutions@VistemSolutions
10 days ago
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access Attackers exploit PAN-OS CVE-2026-0257 to deploy Qilin ransomware, with intrusions ranging from rapid encryption to data theft and double extortion. Now is the time to patch, verify exposure,
avatar
Daily CyberSecurity@Daily_CyberSec
10 days ago
Qilin ransomware affiliates exploit CVE-2026-0257 in PAN-OS GlobalProtect for unauthenticated VPN access, then encrypt entire Windows domains. #Qilin #Ransomware #CVE20260257 #PANOS #GlobalProtect #PaloAltoNetworks https://t.co/AcBxvZo7pH
avatar
Vistem Solutions@VistemSolutions
10 days ago
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access. Attackers exploit PAN-OS CVE-2026-0257 to deploy Qilin ransomware, with intrusions ranging from rapid encryption to data theft and double extortion. Patch fast, review logs, and strengthen access
avatar
Autumn Good@autumn_good_35
11 days ago
『Arctic Wolf Labs assesses with moderate confidence that intrusions leveraging CVE-2026-0257 and leading to Qilin ransomware deployment are likely ongoing.』 Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware https://t.co/mzBhKxl0YC
avatar
Cyber Security News@The_Cyber_News
11 days ago
❗️❗️Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware. Full Story: https://t.co/eIxoPIzIrV The flaw, tracked as CVE-2026-0257 (CVSS 7.8), affects the GlobalProtect https://t.co/QLcOsh3jHP
avatar
Nicolas Krassas@Dinosn
12 days ago
Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware https://t.co/UHDgBZau2V
avatar
DFIR Radar@DFIR_Radar
12 days ago
CVE-2026-0257 is being actively exploited as an initial access vector, with attackers moving rapidly from perimeter breach to domain-wide Qilin ransomware deployment. Prioritize patching and hunt for lateral movement artifacts tied to this CVE. #DFIR_Radar https://t.co/4tK3KDkzR9
avatar
YACTINA@yactina1336
12 days ago
Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware - Arctic Wolf https://t.co/jEViqtc6jN
CVE-2026-42533
8.1/ 10
CVSS Score
77/ 100
SVRS Score
2.45M
Audience
68
Social Media
19
News
5
Repos
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
avatar
National CERT/CC@CERT_UG
3 days ago
⚠️ NGINX Admins: PoC released for CVE-2026-42533. This high-severity heap buffer overflow in NGINX Plus and Open Source allows unauthenticated attackers to force worker restarts or execute arbitrary code via crafted HTTP/TLS requests. Patch immediately. 👇
avatar
The CyberSec Guru@thecybersecguru
3 days ago
Nginx CVE-2026-42533 PoC Released! Check here: https://t.co/WWshMeE1RK
avatar
FOFA@fofabot
3 days ago
⚠️⚠️ CVE-2026-42533 (CVSS 9.2): Critical heap overflow in NGINX via map regex capture clobbering — pre-auth RCE, ASLR bypass, 13 call sites. 🔗FOFA Link: https://t.co/ORPfVg0o0c 🎯578.8M+ Results are found on https://t.co/NBEEGu7ePJ in the past year. FOFA Query: app="NGINX" https://t.co/S6pRSOLEpE
avatar
NeoTeo.com@NeoteoCom
4 days ago
CVE-2026-42533 encadena un memory leak y heap overflow en nginx para evadir ASLR y ejecutar comandos sin autenticación. PoC público. https://t.co/FP0ATD36KU
avatar
Aviatrix Threat Research Center@aviatrixtrc
13 days ago
TRC analysis shows attackers exploiting CVE-2026-42533 to compromise NGINX servers through crafted HTTP requests, then escalating privileges and moving laterally across networks. Runtime segmentation helps contain post-compromise lateral movement in these breach chains.
avatar
Xavier Rivera@XavierRiveraX
13 days ago
F5 patched a critical nginx flaw, CVE-2026-42533 (CVSS 9.2), affecting every build from 0.9.6 through 1.31.2. A regex map configuration lets an unauthenticated attacker send crafted HTTP requests that overflow a heap buffer, crashing worker processes and enabling remote code
avatar
The Daily Tech Feed@dailytechonx
13 days ago
A critical vulnerability in NGINX (CVE-2026-42533) could allow remote code execution via crafted HTTP requests. F5 has released patches; users should upgrade to NGINX 1.30.4, 1.31.3, or NGINX Plus 37.0.3.1 immediately to mitigate this risk. #NGINX #CVE202642533 #CyberSecurity https://t.co/kR1IBH87U1
avatar
Cyber Kendra@cyberkendra
13 days ago
This is the THIRD "measure-then-write" mismatch in nginx's script engine this year: 🔹 NGINX Rift (CVE-2026-42945) — 18yo, exploited in the wild 🔹 nginx-poolslip (CVE-2026-9256) 🔹 This one (CVE-2026-42533) Read Details- https://t.co/OPYsPQnYoy
avatar
Cyber Kendra@cyberkendra
13 days ago
Third time in months. 🧵 nginx just took another critical pre-auth RCE — and this one's been in the code since 2011. CVE-2026-42533 · CVSS 9.2 · patched July 15. If you run nginx, patch to 1.30.4 / 1.31.3 now. Here's why it matters 👇 https://t.co/WjwROID0U2
avatar
7h3h4ckv157@7h3h4ckv157
13 days ago
Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533 Credit/Author: Cyberstan His blog: https://t.co/ZPgNTTE1l9 https://t.co/2ahfucUJ57
CVE-2026-53359
8.8/ 10
CVSS Score
80/ 100
SVRS Score
2.4M
Audience
79
Social Media
20
News
4
Repos
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. The rmap_remove() call would miss entries created after the PDE change because the GFN of the leaf SPTE does not match the GFN of the struct kvm_mmu_page. A similar hole however remains if the modified PDE points to a non-leaf page. In this case the gfn can be made to match, but the role does not match: the original large 2MB page creates a kvm_mmu_page with direct=1, while the new 4KB needs a kvm_mmu_page with direct=0. However, kvm_mmu_get_child_sp() does not compare the role, and therefore reuses the page. The next step is installing a leaf (4KB) SPTE on the new path which records an rmap entry under the gfn resolved by the walk. But when that child is zapped its parent kvm_mmu_page has direct=1 and kvm_mmu_page_get_gfn() computes the gfn for the 4KB page as sp->gfn + index instead of using sp->shadowed_translation[] (or sp->gfns[] in older kernels). It therefore fails to remove the recorded entry. When the memslot is dropped the shadow page is freed but the rmap entry survives, as in the scenario that was already fixed. Code that later walks that gfn (dirty logging, MMU notifier invalidation, and so on) dereferences an sptep that lies in the freed page, causing the use-after-free.
avatar
Hacker News 50@betterhn50
26 days ago
Januscape: Guest-to-Host Escape in KVM/x86 [CVE-2026-53359] https://t.co/PU6LV8RU0w (https://t.co/9aPDRx941e)
avatar
AlmaLinux@AlmaLinux
26 days ago
We have two patched kernels ready for testing: Januscape (CVE-2026-53359) and Bad Epoll (CVE-2026-46242). Januscape affects every supported AlmaLinux release (8, 9, and 10). Bad Epoll affects AlmaLinux 9 and 10. Learn more ⤵️ https://t.co/uskzjvj9HJ
avatar
Hacker News 20@betterhn20
26 days ago
Januscape: Guest-to-Host Escape in KVM/x86 [CVE-2026-53359] https://t.co/HBMAJDuA5O (https://t.co/C3hUsTPL2D)
avatar
SecureChap@SecureChap
26 days ago
CVE-2026-53359 sat in KVM for sixteen years because the shadow-page reuse check only looked at the gfn. kvm_mmu_get_child_sp returned an existing page when the guest frame number matched, regardless of whether https://t.co/QIhBAVNxvv indicated a direct large-page split or an
avatar
The Daily Tech Feed@dailytechonx
26 days ago
A 16-year-old flaw in Linux KVM, dubbed 'Januscape' (CVE-2026-53359), allows guest VMs to execute code on the host system. This vulnerability affects both Intel and AMD x86 architectures and has been present since 2010. Administrators should patch systems immediately to prevent https://t.co/u1QYaxp4Ww
avatar
TECHEPAGES@techepages
26 days ago
🚨 New Linux KVM flaw: "Januscape" (CVE-2026-53359) 🐛 A 16-yr-old use-after-free in KVM's shadow MMU lets a guest VM escape to the host; the same trigger works on both Intel & AMD. 🔑 Needs root in the guest + nested virt enabled. Public PoC panics the host; full RCE exploit
avatar
Xavier Rivera@XavierRiveraX
26 days ago
CVE-2026-53359, dubbed Januscape, is a 16-year-old Linux KVM flaw on Intel and AMD x86 that lets a guest VM crash or escape to its host. KVM's shadow MMU matched tracking pages by address alone, ignoring type, so it could reuse the wrong page and corrupt host kernel memory. A
avatar
The Hacker News@TheHackersNews
26 days ago
🔥 A new 16-year-old #Linux KVM flaw lets a rooted nested VM crash the x86 host and take down other tenants on the same machine. Dubbed "Januscape" (CVE-2026-53359), the bug sits in KVM’s shadow MMU. Researcher says a full guest-to-host escape exploit also exists in a https://t.co/Axt5lB8uBG
avatar
V4bel@v4bel
26 days ago
💥 Introducing "Januscape" (CVE-2026-53359) A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU. Triggerable on both Intel and AMD hosts. Threatens x86 public clouds (GCP, AWS) that expose nested virtualization. "16 years" latent. Successfully used as a https://t.co/UHVC6Tg3Nm
avatar
VulDB 🛡@vuldb
28 days ago
A severe vulnerability was disclosed for Linux Kernel (CVE-2026-53359) https://t.co/ibQudkLzbw
CVE-2026-66066
9.5/ 10
CVSS Score
90/ 100
SVRS Score
2.34M
Audience
34
Social Media
6
News
3
Repos
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
avatar
DailyCVE@dailycve
1 day ago
🔴 (#Rails) Active Storage libvips Unfuzzed Operations Arbitrary File Read & RCE – #CVE-2026-66066 (Critical) -DC-Jul2026-1116 https://t.co/6w4e28Csf0
avatar
James Hibbard@jchibbard
2 days ago
🚨 A breakdown of the new Rails Active Storage vulnerability (CVE-2026-66066), covering the affected Rails versions, the conditions required for exploitation, and the available mitigations. #Rails https://t.co/GIKTHirJEx
avatar
Watson@watson1978
2 days ago
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing · CVE-2026-66066 · GitHub Advisory Database https://t.co/tlNS8OLI2Y
avatar
blueblue@piedpiper1616
3 days ago
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) | Ethiack — Autonomous Ethical Hacking for continuous security - https://t.co/2054zqtSrk
avatar
Kirill Firsov@k_firsov
3 days ago
This is huge. We already reproduced it. I like the CVE number CVE-2026-66066, a helluva bug!
avatar
ThreatWire@ThreatWire_
3 days ago
🚨 CVE-2026-66066: A critical Ruby on Rails flaw lets unauthenticated attackers read server files via crafted image uploads. Apps using Active Storage with Vips are affected. Stolen Rails keys, DB credentials, cloud keys, and API tokens could lead to RCE. #RubyOnRails #RCE #CVE https://t.co/ijTY158jH5
avatar
The Hacker News@TheHackersNews
3 days ago
‼️ WARNING -- Critical Rails flaw CVE-2026-66066 could let unauthenticated attackers read server files through crafted image uploads. The bug affects apps using Active Storage with Vips. Stolen Rails keys, database credentials, cloud keys, and API tokens could enable RCE. Patch https://t.co/7trtEWjLr9
avatar
funai@paveg_
3 days ago
Wrote a Claude Code skill that audits Rails repositories for CVE-2026-66066 (Active Storage + libvips). It reports one verdict per repository with the evidence behind it, and says plainly what a repository cannot tell you. https://t.co/sPIaFdzDxn
avatar
Upwind Security MDR@UpwindMDR
3 days ago
🚨 Critical - Rails Active Storage Arbitrary File Read → RCE (CVE-2026-66066) A default-config Rails app that accepts image uploads lets an unauthenticated attacker upload a crafted file that invokes libvips "unfuzzed" loaders, reading arbitrary files including the process
avatar
André Baptista@0xacb
3 days ago
@ryotkak @flatt_security CVE-2026-66066
CVE-2026-14266
7.0/ 10
CVSS Score
67/ 100
SVRS Score
2.33M
Audience
34
Social Media
15
News
3
Repos
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XZ chunked data. Crafted XZ-compressed data can trigger an overflow of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-30169.
avatar
Mas73r@Mas73r
3 days ago
CVE-2026-14266 https://t.co/SYv812Bidj
avatar
Pirat_Nation 🔴@Pirat_Nation
11 days ago
If you use 7-Zip, update it as soon as possible, A newly disclosed security flaw could let attackers run malicious code on your PC if you open a specially crafted XZ archive. The vulnerability, tracked as CVE-2026-14266, has been fixed in 7-Zip version 26.02. 7-Zip does not https://t.co/nQTVy9M7Zt
avatar
Vistem Solutions@VistemSolutions
11 days ago
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction CVE-2026-14266 is a high-severity heap overflow in 7-Zip’s XZ decoder that could run code when a user opens a crafted archive. Version 26.02 fixes it. ✅ Update 7-Zip now ✅ Avoid opening
avatar
CyberTLDR@CyberTLDR
11 days ago
1/3 Opening one crafted XZ archive in 7-Zip can run attacker code on your machine. CVE-2026-14266 is a heap overflow in the XZ decoder, rated CVSS 7.0, and it fires during extraction. Are you on 7-Zip 26.02 yet? #CyberSecurity #InfoSec #CVE #TechNews #Marvel https://t.co/ycjGG3wyWw
avatar
Carlos Fynn@fynn_JourX
11 days ago
7-Zip CVE-2026-14266 turns archive handling int… is the kind of management-plane bug defenders should move on fast. It combines active exploitation with remote code execution and auth bypass risk in FortiClient EMS. When endpoint management infrastructure is exposed, t…
avatar
Carlos Fynn@fynn_JourX
11 days ago
Legacy exposure keeps paying off for attackers. 7-Zip CVE-2026-14266 turns archive handling into an endpo… ZDI disclosed CVE-2026-14266, a 7-Zip XZ decoder heap overflow fixed in 26.02 that can enab… 🔗 Read → https://t.co/eVhV2Qda46
avatar
Lucas@lucasverdan
11 days ago
7-Zip CVE-2026-14266 turns archive handling int… is already being exploited, and Fortinet says the FortiClient EMS flaw carries remote code execution and auth bypass risk. If you run 7.4.5 or 7.4.6, treat it as exposed management-plane risk and hotfix now.
avatar
Lucas@lucasverdan
11 days ago
🛑 7-Zip CVE-2026-14266 turns archive handling into an endpoint patch prio… ZDI disclosed CVE-2026-14266, a 7-Zip XZ decoder heap overflow fixed in 26.02 that can enab… 🔗 Details → https://t.co/oMQRrMGHtN
avatar
Guardian360@Guardian360nl
11 days ago
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. https://t.co/PtTyxGnL4l
avatar
Open Source Security mailing list@oss_security
14 days ago
CVE-2026-14266: 7-Zip: XZ Decompression Heap-based Buffer Overflow, Code Execution https://t.co/xcXmQw0ANi Fixed in 26.02
CVE-2026-33017
9.8/ 10
CVSS Score
94/ 100
SVRS Score
2.19M
Audience
24
Social Media
10
News
4
Repos
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.
avatar
مجلاد بن مشاري السبيعي@Al7lhh223
9 days ago
Milestone: prompt-injection-auditor is now indexed on CVEFeed alongside CVE-2026-33017 (9.8 Critical - actively exploited) https://t.co/tH9iLAl2yA Even better: the project is now linked to 4 different CVEs in their database - researchers tracking any of them find a defensive https://t.co/8PdHWbugN1
avatar
Americo Simoes@CCT_OS
20 days ago
My exploit (Sovereign-Echo-33017) made it into the official DSCI threat report — listed as a public PoC for CVE-2026-33017. Weaponized in under 24 hours. Added to CISA KEV. Cited by Indian government-backed threat intelligence. https://t.co/wzgS5TIN6q
avatar
SecurityWeek@SecurityWeek
24 days ago
CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws - https://t.co/rnuxt9VXQm (CVE-2026-48282, CVE-2026-55255, CVE-2026-33017)
avatar
TrendAI™ Research@trendai_RSRCH
26 days ago
Attackers exploiting CVE-2026-33017 in Langflow used a command-and-control IP already on the Spamhaus DROP list. DROP enforcement at egress can block beacons from this campaign with no custom indicators required. Read the full report: https://t.co/Ed9gIanQiY
avatar
TI Mindmap HUB@ti_mindmap_hub
26 days ago
🔴 Langflow: two CVEs, two independent actors, one week. CVE-2025-3248 → JADEPUFFER (autonomous ransomware) CVE-2026-33017 → Monero cryptominer When a bleeding-edge ransomware and a commodity miner hit the same AI framework in 7 days, it's core attack surface.
avatar
Orca Security@orcasec
30 days ago
🚨 Critical Langflow RCE (CVE-2026-33017, CVSS 9.8) is being actively exploited to deploy cryptominers on AI infrastructure. Patch to v1.9.0+ now. We've got the full breakdown 👇 https://t.co/jLGWmbXcyt https://t.co/82cATmCKTq
avatar
CloudSecurityAlliance@cloudsa
30 days ago
CISO Daily Briefing: Unit 42: 2.1M AI-hallucinated brand URLs mapped — ~250K unregistered and open for adversarial squatting now; CVE-2026-33017 (Langflow, CVSS 9.3) actively exploited with cron persistence and C2; Fable 5's 19-day export control blackout exposed zero contractual
avatar
Clone Systems@CloneSystemsInc
2026-07-01
Critical Langflow RCE Exploited in Cryptomining Campaign Threat actors are exploiting CVE-2026-33017, a critical unauthenticated RCE vulnerability in Langflow, to target exposed AI application endpoints and deploy a Monero miner. The malware can disable security controls, https://t.co/rKlnJeIQj1
avatar
TrendAI™ Research@trendai_RSRCH
2026-07-01
The miner behind CVE-2026-33017 Langflow exploitation dropped from 31 out of 66 to 4 out of 66 on VirusTotal between 2024 and 2026. Smaller binary, shuffled strings, actively maintained. Not a recycled payload. See our full research: https://t.co/Ed9gIanQiY
avatar
QuanChain@Quan_Chain
2026-07-01
The most dangerous attack surface in your AI stack isn't the model, it's the endpoint. CVE-2026-33017 (CVSS 9.3): unauthenticated RCE turned exposed Langflow deployments into Monero miners. No credentials. No phishing. Just a scan. QuanChain's oracle-triggered migration detects https://t.co/JOeZe4C6Tq
CVE-2026-46331
7.8/ 10
CVSS Score
82/ 100
SVRS Score
2.17M
Audience
26
Social Media
7
News
0
Repos
In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined.
avatar
SOCRadar®@socradar
8 days ago
Running Claude locally on your Mac? Watch out for #SharedRoot. 🤖💥 CVE-2026-46331 is a sandbox-escape chain that lets attackers jump from the isolated Linux VM straight to your host Mac's files. 🔹 Patch guest kernels 🔹 Prefer remote execution 🔹 Monitor host-file access
avatar
David Mytton@davidmytton
8 days ago
First OpenAI, now Anthropic. Are sandboxes safe? 1 - use 2 kernel features to get access 2 - exploit CVE-2026-46331 (a public Ubuntu kernel priv-esc bug) 3 - piggy back on coworkd (runs as root) Maybe the frontier labs could just run their cyber models against the top projects
avatar
Sandro Bruscino@SandroBruscino
8 days ago
Claude Cowork's macOS app mounted your filesystem into the agent's VM read-write. Chain a user namespace with CVE-2026-46331 and the agent reads your SSH keys and cloud creds. ~500k local users. Anthropic closed it "informative," no fix shipped. Local sessions still exposed.
avatar
Nicolas Krassas@Dinosn
8 days ago
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 https://t.co/0yG31EdC9C
avatar
The CyberSec Guru@thecybersecguru
9 days ago
AI agents are becoming more capable, but are their sandboxes keeping up? Researchers have disclosed SharedRoot, a sandbox escape affecting Anthropic's Claude Cowork that lets an AI agent chain a Linux kernel privilege escalation (CVE-2026-46331) with a writable VirtioFS mount to
avatar
Claude AI | Anthropic News@claude_news
9 days ago
Researchers mounted one folder into Claude Cowork, sent a short message, and reached the whole Mac disk: SSH keys, cloud credentials, no permission prompt. The full host mounts into the Linux VM with write access, and a CVE-2026-46331 chain gets root inside it. https://t.co/UEMpuLO7f2
avatar
The Hacker News@TheHackersNews
9 days ago
🚨 Researchers say one short message let Claude Cowork escape its Linux VM and access files across the host Mac. The SharedRoot chain used CVE-2026-46331 to gain guest root, then crossed through Cowork’s read-write host mount. Read how it worked: https://t.co/0xbTQsJRyj https://t.co/kp2LNwBU9A
avatar
UNDERCODE TESTING@UndercodeUpdate
28 days ago
🚨 Critical #Linux Kernel Flaw #CVE-2026-46331 (Pedit COW) Allows Any Unprivileged User to Gain Root Access via Cache Poisoning + Video https://t.co/0rkf50Bzgx Educational Purposes!
avatar
Stanislav Klevtsov@stansecure
30 days ago
Top #CVE to #patch this week 👀 - @Ubiquiti UniFi OS (CVE-2026-34908, 34909, 34910) critical flaws - @Cisco UCM (CVE-2026-20230) SSRF to root - Another two @Linux Privesc pedit COW(CVE-2026-46331), DirtyClone - @Linux kernel — new DirtyFrag family privesc, JFrog published
avatar
AlexAImaginator@TraffAlex
30 days ago
🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — July 02, 2026 1️⃣ LINUX KERNEL EXPLOIT GETS ROOT WITHOUT TOUCHING A SINGLE FILE ON DISK A new Linux kernel exploit (CVE-2026-46331) achieves root access without modifying any files on disk. Instead, it poisons the cached copy of
CVE-2026-53412
9.8/ 10
CVSS Score
84/ 100
SVRS Score
2.14M
Audience
28
Social Media
13
News
0
Repos
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.
avatar
TECHEPAGES@techepages
16 days ago
⚠️ Zoom just disclosed a critical account takeover vulnerability (CVE-2026-53412) with a 9.8/10 severity score. It affects the Windows desktop client, VDI client, and Meeting SDK — and an unauthenticated attacker could hijack accounts over the network. Update now: 🔹 Zoom
avatar
Cyber Security News@The_Cyber_News
16 days ago
Zoom has released updates for a critical Windows desktop client vulnerability, tracked as CVE-2026-53412, that could allow unauthenticated attackers to remotely take over user accounts. This flaw arises from improper input validation and may enable unauthenticated attackers to https://t.co/ayXinh4kET
avatar
Vivek | Cybersecurity@VivekIntel
16 days ago
Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug https://t.co/yacIlecF4j
avatar
Shah Sheikh@shah_sheikh
16 days ago
Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug: Zoom warns of a critical Windows flaw, tracked as CVE-2026-53412, that could let attackers take over accounts without authentication. Zoom has fixed a critical Windows vulnerability, tracked as… https://t.co/YnkGY6jmwZ https://t.co/qSh87ALasT
avatar
The Hacker News@TheHackersNews
16 days ago
🚨 Zoom has patched a 9.8-rated Windows flaw that could let an unauthenticated attacker take over accounts via network access. CVE-2026-53412 affects the Desktop Client, VDI Client, and Meeting SDK. Affected versions and update details: https://t.co/plNJdD5wrE https://t.co/xJ49YwUI8e
avatar
CCB Alert@CCBalert
16 days ago
Warning: #Zoom Workplace accounts are at risk of takeover due to a critical input validation vulnerability tracked as #CVE-2026-53412. For more info about this and other vulnerabilities in Zoom visit: https://t.co/WGhUonItXv #Patch #Patch #Patch
avatar
Es Geeks@EsGeeks
17 days ago
🚨 ZOOM CRITICAL: Account Takeover sin autenticación en Windows (CVE-2026-53412 CVSS 9.8). Atacante de red puede hijackear cuentas de Zoom Workplace y VDI. Actualiza YA a 7.0.0+. #Zoom #CVE #Ciberseguridad https://t.co/0lRxdyFeAT
avatar
Aviatrix Threat Research Center@aviatrixtrc
17 days ago
TRC analysis shows attackers exploiting CVE-2026-53412 can hijack Zoom accounts without authentication, then escalate privileges and move laterally through connected enterprise systems. Runtime segmentation helps contain post-compromise activity across linked services. #ZeroTrust
avatar
Rich Tehrani@rtehrani
17 days ago
The latest security advisory from Zoom landed with an urgency that many IT teams have unfortunately come to recognize. CVE-2026-53412, a critical improper input validation bug in the Windows desktop client, Windows VDI Client, and Meeting SDK, received a severity rating of 9.8
avatar
Daily CyberSecurity@Daily_CyberSec
17 days ago
Zoom vulnerability CVE-2026-53412 (CVSS 9.8) allows unauthenticated account takeover over the network. Update Zoom Workplace for Windows to 7.0.0 now. #Zoom #CVE202653412 #AccountTakeover #Windows #CyberSecurity https://t.co/n4AsVHRTUo
CVE-2026-50656
7.0/ 10
CVSS Score
67/ 100
SVRS Score
2.14M
Audience
47
Social Media
19
News
0
Repos
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
avatar
NEWSTECNICAS | Tecnología@newstecnicas
13 days ago
🛡️ Mitigación y Gestión de la Vulnerabilidad "RoguePlanet" (CVE-2026-50656) en Microsoft Defender https://t.co/ToE4He0Rgz
avatar
Mat Clark | ReadRoost@MathewClarkAU
18 days ago
Everyone's sharing "Windows Defender bug fills your hard drive, patch now." That's backwards. The real bug (CVE-2026-50656, RoguePlanet) hands someone already on your PC full SYSTEM control. Works even with Defender's real-time protection switched off. https://t.co/gUYLujobIe
avatar
Perturb AI@perturbaix
18 days ago
Microsoft just patched RoguePlanet. CVE-2026-50656. CVSS 7.8. a privilege escalation flaw in the Microsoft Malware Protection Engine — the core scanning engine that powers Windows Defender antivirus. the researcher who disclosed it had a public feud with Microsoft over bug
avatar
Zero Hunt@zerohuntai
18 days ago
CVE-2026-50656 "RoguePlanet": a race condition in Microsoft Defender's scan engine spawns a SYSTEM shell on fully-patched Windows 10/11. Microsoft shipped an out-of-band fix on July 9. The detector became the attack surface. Fix runbook 🧵 https://t.co/fXJz854Mcn
avatar
SecEngCyGy@snypet86
20 days ago
Microsoft shipped a fix for RoguePlanet — a local privilege escalation in the Defender Malware Protection Engine (CVE-2026-50656). Authenticated attackers could reach SYSTEM on affected Windows 10/11 boxes. Public PoC sat out for about a month before the engine update landed.
avatar
Gb0l4@gb0l4
21 days ago
Your antivirus was the open door 🛡️ Microsoft just patched RoguePlanet (CVE-2026-50656) a Defender zero-day, exploit code public for 29 days. A race condition lets any local user pop a SYSTEM shell. Update Windows Security today engine 1.1.26060.3008 fixes it. #CyberSecurity
avatar
𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
21 days ago
Critical new flaws: Apache IoTDB/Camel, Gardyn IoT Hub RCE, & Kafka auth bypass just reported (Jul 11). Plus MS Defender zero-day (CVE-2026-50656) patched (Jul 9). Urgent patching needed to protect data privacy/integrity in transit. #Cybersecurity #ZeroDay #Vulnerabilities
avatar
辻 伸弘 (nobuhiro tsuji)@ntsuji
23 days ago
NVD - CVE-2026-50656 https://t.co/kYQNvAm5Y3
avatar
Aseem Shrey@AseemShrey
25 days ago
Microsoft Defender has a zero-day. No patch. Works whether real-time protection is on or off. CVE-2026-50656. Your security tool is the attack surface. Thread 🧵👇 https://t.co/0m39GNseYT
avatar
Israel@f1tym1
27 days ago
Update: Microsoft has confirmed that CVE-2026-50656 is under active exploitation in the wild, meaning attackers have already incorporated the vulnerability into real-world attack chains against live targets. https://t.co/X2ZUOeHfSM
CVE-2026-10702
4.3/ 10
CVSS Score
48/ 100
SVRS Score
2.13M
Audience
18
Social Media
3
News
0
Repos
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
avatar
Zymeralabs@Zymeralabs
2 days ago
@The_Cyber_News Una sola página maliciosa puede ser suficiente para comprometer el Tor Browser, según una nueva investigación sobre la vulnerabilidad de Firefox CVE-2026-10702. El error permite la ejecución de código arbitrario en el renderizador del navegador, y los investigadores dicen que
avatar
SecureChap@SecureChap
3 days ago
Nebula Security published a working exploit that turns one webpage visit into code execution inside Firefox's sandboxed renderer. CVE-2026-10702 is a JIT miscompilation in SpiderMonkey. Per Nebula's IonStack writeup, MObjectToIterator with skipRegistration=true was declared a
avatar
ByteSec1401 Efshagari@Leila97726926
3 days ago
A bug in Firefox JIT can compromise the TOR browser just by visiting a malicious webpage. Nebula Security reports CVE-2026-10702 as the bug that provides arbitrary code execution in the browsers renderer process. No interaction is required, as visiting the webpage alone is
avatar
The Daily Tech Feed@dailytechonx
3 days ago
A critical vulnerability, CVE-2026-10702, in the Tor Browser's JavaScript engine allows remote code execution via malicious webpages. Users should update to the latest version immediately to maintain their anonymity and security. #TorBrowser #CVE202610702 #CyberSecurity #Privacy https://t.co/lIVat5mnOK
avatar
Cyber Security News@The_Cyber_News
3 days ago
‼️A single malicious page may be enough to compromise Tor Browser, according to new research into the Firefox flaw CVE-2026-10702. The bug allows arbitrary code execution in the browser renderer, and researchers say it also worked against Tor Browser before patches landed. https://t.co/aT0qAcwkDK
avatar
The Hacker News@TheHackersNews
3 days ago
🛑 One malicious webpage visit was enough to compromise Tor Browser. No settings changes. No extra clicks. Firefox JIT flaw, CVE-2026-10702, runs code inside the browser’s renderer process and forms the first stage of an Android 17 root chain. Read how the exploit works: https://t.co/JQxsgdY0Fu
avatar
Lyrie.ai@lyrie_ai
17 days ago
@nebusecurity Full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting Firefox before v151.0.2 (CVE-2026-10702) Android 17 root Full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting Firefox before v151.0.2 (CVE-2026-10702) Click on the…
avatar
Lyrie.ai@lyrie_ai
17 days ago
CVE-2026-10702: Android 17 root Full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting Firefox before v151.0.2 (CVE-2026-10702) Click on the link -> root Android Discovered by @nebusecurity PoC not available. Info:
avatar
Rıdvan Yağlı@ridvanyagli
24 days ago
CVE-2026-10702 PoC Exploit: https://t.co/1rA1FLxYUW
avatar
YogSotho@YogSoth0
24 days ago
⚠️ IN DEVELOPMENT ⚠️ #IonStack #exploit #0days #cybernews #cybersecurity #root #android #firefox #c2 #ansi #CVE-2026-10702 — Android Firefox Root Exploit Kit CVE-2026-10702 is a memory corruption vulnerability in browser-based ANSI escapecode renderers. When a Firefox browser https://t.co/cligbBLBKT

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

F.A.Q.

Find answers to common questions about CVEs and vulnerability intelligence