LIVE FEED
3592 events · 13 sources · newest first
Events in view
3592
all sources
Critical
1506
severity
Active sources
13
collectors
Last sync
2026-08-12 00:00
UTC
All sources
CISA KEV · 1665NVD CVE · 1412News · 229eCFR · 98CISA advisory · 86DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16Fed. Register · 12NIST · 12DCSA · 11Cyber AB docs · 10OIRA · 1
2026-08-11
CISA KEV
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance....
administrators-accessapplications-securitycisa-kevcredentials-theftcve-2026-72898data-theftdatabase-securitydatum-exfiltration
2026-08-11
NVD CVE
CVE-2026-5917: libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_
CRITICAL
libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server...
arbitrary-command-executioncommand-injectioncve-2026-5917gitgit-submodulelibgit2libssh2nvd-cve
2026-08-11
NVD CVE
CVE-2026-48362: ColdFusion is affected by an Improper Neutralization of Special Elements used in
CRITICAL
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user....
arbitrary-code-executioncode-executioncoldfusioncoldfusion-vulnerabilitiescommand-injectioncve-2026-48362exploitnvd-cve
2026-08-11
NVD CVE
CVE-2026-59124: Deserialization of untrusted data in Microsoft High Performance Computing (HPC)
CRITICAL
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-59124deserializationhigh-performance-computinghpcmicrosoftnetworks-attacksnvd-cve
2026-08-11
NVD CVE
CVE-2026-27302: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to...
adobeadobe-campaign-classicarbitrary-code-executioncve-2026-27302incorrect-authorizationnvd-cvesecurityvulnerability
2026-08-11
NVD CVE
CVE-2026-58231: SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authent
CRITICAL
SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authentication client and submit specially crafted
input to certain functions lacking sufficient validation. Successful
exploitation could...
arbitrary-code-executionauthentication-bypassavailabilityconfidentialitycve-2026-58231default-authentication-clienthigh-impactinput-validation
2026-08-11
NVD CVE
CVE-2026-34265: SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl
CRITICAL
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive...
abapavailabilityconfidentialitycve-2026-34265diagnostic-protocolsintegritymemory-corruptionnvd-cve
2026-08-11
NVD CVE
CVE-2026-73034: DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allo
CRITICAL
DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id...
agent-scriptattackers-controlledcron-directoriescve-2026-73034db-gptdirectories-traversalfiles-uploadhttps-headers
2026-08-11
NVD CVE
CVE-2026-71398: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CRITICAL
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to...
adobeadobe-campaign-classicarbitrary-code-executioncve-2026-71398incorrect-authorizationnvd-cvesecurityvulnerability
2026-08-11
NVD CVE
CVE-2026-58115: A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1
CRITICAL
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the...
arbitrary-code-executionauthenticationcve-2026-58115https-interfaceindustrial-osindustrials-iotmalicious-flowsnodes-red
2026-08-11
CISA KEV
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
ancillary-functions-driversauthorize-attackerscisa-kevcve-2026-68820freeincident-responselocal-attackmicrosoft
2026-08-11
CISA KEV
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to...
cisa-kevciscocisco-asacisco-ftdcve-2026-20349denialdevice-reloaddo-s
2026-08-11
NVD CVE
CVE-2026-50516: Missing authentication for critical function in Microsoft Azure Kubernetes Servi
CRITICAL
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
azurecloud-securitycve-2026-50516incident-responsekubernetemicrosoftmissing-authenticationnetwork-security
2026-08-11
NVD CVE
CVE-2026-69102: MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT sig
CRITICAL
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any...
admin-sessionapplication-secretcve-2026-69102forged-tokenhard-coded-secretjwtmaxkeynvd-cve
2026-08-11
NVD CVE
CVE-2026-70306: Improper neutralization of input during web page generation ('cross-site scripti
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
cross-site-scriptingcve-2026-70306inputs-neutralizationmicrosoftnetwork-securitynvd-cvesharepointspoofing
2026-08-11
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-223-02.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability...
blebluetooth-low-energycisacisa-advisorycontrol-systemcve-2026-18844cwe-912firmware
2026-08-11
NVD CVE
CVE-2026-71362: Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
CRITICAL
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources....
access-controladobeadobe-commercecommercecve-2026-71362exploitincorrect-authorizationnvd-cve
2026-08-11
NVD CVE
CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that a
CRITICAL
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to...
chrome-privilegescve-2026-73032file-readsfile-writejavascriptllmmitmnvd-cve
2026-08-11
NVD CVE
CVE-2026-62893: Use after free in Windows Deployment Services allows an unauthorized attacker to
CRITICAL
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-62893freeincident-responsenetworks-attacksnvd-cvepatch-managementremote-code-execution
2026-08-11
NVD CVE
CVE-2026-62815: Use after free in Microsoft QUIC allows an unauthorized attacker to execute code
CRITICAL
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
attackercode-executioncve-2026-62815exploitfreemicrosoftnetwork-securitynvd-cve
2026-08-11
NVD CVE
CVE-2026-62878: Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to ex
CRITICAL
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-62878dns-securityexploitnetworks-attacksnetworks-vulnerabilitiesnvd-cve
2026-08-11
NVD CVE
CVE-2026-44758: SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig
CRITICAL
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation....
arbitrary-code-executionavailabilityconfidentialitycve-2026-44758high-privilegeinput-validationintegritymanufacturing-integration-and-intelligence
2026-08-11
NVD CVE
CVE-2026-10579: A flaw was found in Picketlink Federation SAML; the unsolcited response handler
CRITICAL
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in...
access-controlauthentication-bypassauthorizationcve-2026-10579federationforged-assertionsidentity-managementinformation-disclosure
2026-08-11
NVD CVE
CVE-2026-65791: Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorize
CRITICAL
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
buffer-overflowcode-executioncve-2026-65791exploitheap-based-buffer-overflowiscsinetworks-attacksnvd-cve
2026-08-11
NVD CVE
CVE-2026-71384: is affected by an Incorrect Authorization vulnerability that could result in a S
CRITICAL
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write...
access-controladministrative-network-zoneapplications-vulnerabilitiescve-2026-71384cybersecuritydenialexploitincorrect-authorization
2026-08-11
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-223-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities...
authentication-bypasscisacisa-advisorycve-2026-66098cve-2026-66340cve-2026-66875cve-2026-67558cve-2026-67568
2026-08-11
NVD CVE
CVE-2026-19425: Travel Agency Management System developed by Win Men Intermational has a SQL Inj
CRITICAL
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
code-injectioncve-2026-19425data-deletiondata-modificationdatabases-compromisesdatum-exfiltrationnvd-cvepatch-management
2026-08-11
CISA advisory
<p>CISA has added three new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
bod-26-04cisacisa-advisoryciscocve-2026-20349cve-2026-68820cve-2026-72898cyber-attacks
2026-08-10
CISA advisory
<h2><strong>Advisory at a Glance</strong></h2>
<table>
<tbody>
<tr>
<th>Title</th>
<td>#StopRansomware: Gunra Ransomware</td>
</tr>
<tr>
<th>Original Publication</th>
<td>August 10, 2026</td>
</tr>
<tr>
<th>Executive...
academia-sectorsactive-directoryaffiliate-programcisa-advisoriescisa-advisorycommands-and-controlcredentials-dumpingcritical-manufacturing-sector
2026-08-10
NVD CVE
CVE-2026-14450: A flaw was found in the MaaS API. This vulnerability allows any pod within the c
CRITICAL
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are...
api-keycve-2026-14450first-parties-authenticationforged-headershttps-headerskuadrant-authpolicykubernetemaas-apus
2026-08-10
NVD CVE
CVE-2026-18948: A flaw was found in Feast. The system improperly deserializes user-defined funct
CRITICAL
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious...
arbitrary-code-executioncross-tenant-data-accesscve-2026-18948deserializationdillfeastlateral-movementnvd-cve
2026-08-10
NVD CVE
CVE-2026-63106: ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerabil
CRITICAL
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause...
administrator-passwords-hashescve-2026-63106database-contentfile-system-accessincident-responsemysqlnvd-cveproduct-controller
2026-08-10
NVD CVE
CVE-2026-13206: Improper neutralization of special elements used in an OS command ('OS command i
CRITICAL
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection.
This issue affects WAH7601: through 20072026.
command-injectioncve-2026-13206cybersecuritynetwork-adapternetwork-securitynetwork-security-vulnerabilitynetworks-devicesnetworks-devices-vulnerabilities
2026-08-09
NVD CVE
CVE-2026-71991: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71990: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the...
axe6600command-injectioncve-2026-71990firmwaremsinvd-cveradixremote-attacks
2026-08-09
NVD CVE
CVE-2026-71989: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71987: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-19348: A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea
CRITICAL
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1....
add-actcommand-injectioncve-2026-19348enable-1exploitm300-wi-fi-repeaternet-smacfilter-confnvd-cve
2026-08-09
NVD CVE
CVE-2026-71993: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71988: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve