LIVE FEED
4273 events · 13 sources · newest first
Events in view
4273
all sources
Critical
1863
severity
Active sources
13
collectors
Last sync
2026-08-30 18:00
UTC
All sources
NVD CVE · 1813CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-08-30
NVD CVE
CVE-2026-82539: A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This imp
CRITICAL
A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument...
a720rcstecgicgicve-2026-82539exploit-disclosuremac-filteringmemory-corruptionnvd-cveremote-attacks
2026-08-30
NVD CVE
CVE-2026-82542: A weakness has been identified in Tenda HG10 300001138. Affected by this issue i
CRITICAL
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the...
boa-web-serverbuffer-overflowcve-2026-82542destnetexploitforms-ipv6-routinghardware-vulnerabilitiesipv6-routing
2026-08-30
NVD CVE
CVE-2026-15980: The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in a
CRITICAL
The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token...
authentication-bypassauthorizationcookie-theftcve-2026-15980myhome-coremyhome-themenvd-cveplugin
2026-08-29
NVD CVE
CVE-2026-14494: The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution
CRITICAL
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the...
code-executioncve-2026-14494files-uploadmime-type-validationnvd-cveplugins-vulnerabilitiesremote-code-executionsecurity-vulnerability
2026-08-29
NVD CVE
CVE-2026-82460: Cloud Commander before 19.20.2 contains a directory traversal vulnerability in R
CRITICAL
Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences...
cloud-softwareclouds-commanderscode-executioncve-2026-82460datum-exfiltrationdirectories-traversalfile-operationmarkdown-endpoint
2026-08-29
NVD CVE
CVE-2026-15369: The Custom User Registration Fields for WooCommerce plugin for WordPress is vuln
CRITICAL
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled...
administrator-privilegescheckout-apicustom-user-registrationcve-2026-15369nvd-cveorder-metaplugins-vulnerabilitiesprivileges-escalation
2026-08-29
NVD CVE
CVE-2026-82456: argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts
CRITICAL
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke...
api-tokenargocd-mcpargos-cdauthenticationcredentials-exposurecve-2026-82456https-transportmcp-protocols
2026-08-29
NVD CVE
CVE-2026-82454: The Omnivore API (packages/api) before the fix in commit abf53d6 contains an aut
CRITICAL
The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the...
apple-signauthentication-bypasscommit-abf53d6cve-2026-82454forged-tokenhmacimpersonationjwt
2026-08-29
NVD CVE
CVE-2026-82452: rust-iot-platform through commit 5df942ab contains an authentication bypass vuln
CRITICAL
rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create,...
api-securityauthentication-bypasscommit-5df942abcredential-validationcve-2026-82452endpoint-protectioniots-platformnvd-cve
2026-08-29
NVD CVE
CVE-2026-82448: Shinobi before commit 5a76c74f contains a hardcoded connection key in the child
CRITICAL
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can...
arbitrary-code-executioncameras-configurationschild-nodecommit-5a76c74fcve-2026-82448database-queryhardcoded-credentialnvd-cve
2026-08-28
News
<p>The service will deliver nine Spectrum Situational Awareness Systems to “prioritized Army units” in three weeks, officials told reporters.</p>
<p>The post <a...
armycommand-postdefense-scoopdetection-toolnewss2assignal-emissionspectrum-situational-awareness-systems
2026-08-28
News
CISA’s top quantum security expert says agencies will need to work closely with industry on the cryptographic transition.
agencies-cybersecuritycisacisa-expertcrypto-transitionscryptographic-transitionfederal-agenciesfederal-cybersecurityfederal-procurement
2026-08-28
News
<p>A federal district judge found the government's actions, including the Pentagon’s designation that Anthropic posed a supply chain risk, were “illegal and baseless.” </p>
<p>The post <a...
administrative-actionsanthropiccisacourt-rulingdefense-industrydodfederal-judgegovernment-ban
2026-08-28
News
<p>The prolific ransomware group Qilin claimed responsibility for the attack. ATF insists the incident was limited to a standalone system and hasn’t impacted critical operations. </p>
<p>The post <a...
atfcyberattackcyberscoopdojnewsqilinransomware
2026-08-28
News
<p>The department is also looking into data protection measures that are designed to advance its migration to post-quantum cryptography.</p>
<p>The post <a...
cryptographydata-protectiondata-securitydoddod-probesdods-encryptionsencryptionencryption-migration
2026-08-28
News
<p><a href="https://breakingdefense.com/2026/08/the-big-defense-spending-priorities-awaiting-congress-in-september/"><img width="1024" height="576"...
appropriationbudgetbudgets-authorizationscongresscongressional-prioritiescongressional-sessiondefense-budgetdefense-funding
2026-08-28
News
<p>The congressional watchdog’s shift from a five-year modernization plan to ongoing IT work wasn’t documented clearly, OIG found.</p>
<p>The post <a...
news
2026-08-28
News
<p>The Department of Homeland Security unit will spend more than $16.7 million on 6,650 of the “conductive distraction and de-escalation” devices made by Compliant Technologies. </p>
<p>The post <a...
cmmccompliant-technologiesconductive-distractioncontracts-compliant-technologiesde-escalationdhdh-contractdod
2026-08-28
News
<p>Over two days this week, Joint Task Force-Southern Border used the Army Multipurpose High Energy Laser system to engage three "hostile" UAS, according to a press release.</p>
<p>The post <a...
news
2026-08-28
News
<p>The Department of Veterans Affairs is integrating more artificial intelligence to connect veterans with benefits.</p>
<p>The post <a href="https://fedscoop.com/va-launches-ai-helpdesk-chatbot/">VA launches AI...
aiartificial-intelligencebenefitchatbotfedscoophelpdesknewsva
2026-08-28
News
<p>The human capital agency said AI uses that support applicant evaluation and pre-offer quality control likely don’t fall into a category that requires more risk management scrutiny. </p>
<p>The post <a...
ai-usageapplicant-evaluationartificial-intelligencefederal-agenciesfederal-hiringhr-technologyhuman-capitalnews
2026-08-28
News
PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.
actives-exploitationsattackcybersecurityemergencies-advisoriesexploitinformation-securitymalwarenetwork-security
2026-08-28
News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a...
cisacritical-flawscve-2023-49105cybersecuritydata-theftexploitkevs-catalognews
2026-08-28
News
<p><a href="https://breakingdefense.com/2026/08/military-uses-av-directed-energy-system-to-defeat-drones-at-the-border/"><img width="697" height="393"...
av-systemborder-securitybreaking-defensecounter-dronedefensedirected-energy-systemsdronedrug-cartels
2026-08-28
News
<p>The Defense Information Systems Agency issued another sources-sought notice Thursday as it prepares to initiate a massive transition of combatant commands from legacy common-use IT services and assets they have...
ciocombatant-commanddefense-information-systems-agenciesdefense-scoopdisadoddodnetit-migration
2026-08-28
News
<p><a href="https://breakingdefense.com/2026/08/finland-and-sweden-team-up-to-boost-counter-drone-defenses/"><img width="1024" height="577"...
bilateral-cooperationbreaking-defensecounter-dronedefense-cooperationfinlandpresidents-stubbssweden
2026-08-28
News
<p><a href="https://breakingdefense.com/2026/08/with-ai-hackers-in-mind-air-forces-cyber-develops-defensive-campaign-plan/"><img width="1024" height="576"...
16th-air-forceai-hackerai-threatair-force-cyberbreaking-defensecyber-defensedefensive-campaign-planinflection-point
2026-08-28
News
<p><a href="https://breakingdefense.com/2026/08/f-35-lifetime-price-tag-dips-beneath-2-trillion-even-as-buying-costs-rise/"><img width="1024" height="577"...
budget-estimatesdefense-acquisitionsdefense-departmentdodf-35newspentagonprograms-costs
2026-08-28
News
<p><a href="https://breakingdefense.com/2026/08/the-president-doesnt-need-a-one-trick-army/"><img width="1024" height="577"...
air-defenseartillerydefense-industrydefense-policyfamfiregermanygrafenwoehr-training-areamaneuver-shorad
2026-08-28
News
<p>CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.</p>
<p>The post <a...
cisacve-2026-53362cybersecurityexploitincident-responsejfrogkevs-cataloglinux-kernel
2026-08-28
News
Boston Scientific faces ongoing operational disruption after cybersecurity incident impacts IT systems, order processing ↗
◈ 2 sources · orig. therecord.media
<p>Medical equipment manufacturer Boston Scientific identified a cybersecurity incident affecting certain information technology systems that resulted in a...</p>
<p>The post <a...
bostons-scientificscybersecurity-incidentsincident-responseinformation-technologyit-systemmanufacturingmedical-equipmentnews
2026-08-28
News
<p>The U.K. National Cyber Security Centre (NCSC) said it has seen increased targeting of OT (operational technology) systems...</p>
<p>The post <a...
cyber-threatscybersecurity-advisorycybersecurity-warningedge-deviceindustrial-control-systeminternet-exposed-systemsnational-cyber-security-centrenews
2026-08-28
NVD CVE
CVE-2026-82266: Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_requi
CRITICAL
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to...
admins-apibrokers-accountscluster-configurationcve-2026-82266default-configurationdefensedepthincident-response
2026-08-28
NVD CVE
CVE-2026-19295: IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execut
CRITICAL
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a...
arbitrary-code-executionauthenticate-attackercommand-executioncraftingcve-2026-19295ibmlangflownvd-cve
2026-08-28
NVD CVE
CVE-2026-82244: Budibase versions before 3.41.3 contain a remote code execution vulnerability in
CRITICAL
Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball. The server...
arbitrary-code-executionbudibasecredential-exfiltrationcve-2026-82244environment-variableseval-functionmalicious-pluginsnodej
2026-08-28
NVD CVE
CVE-2026-76581: The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypa
CRITICAL
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the...
administratorajaxauthentication-bypasscve-2026-76581dashboard-pluginhmachub-ss0nvd-cve
2026-08-28
NVD CVE
CVE-2026-3627: IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacke
CRITICAL
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the...
concertcve-2026-3627data-deletiondata-modificationdatabaseibminformation-disclosurenvd-cve
2026-08-28
NVD CVE
CVE-2026-18527: IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (AR
CRITICAL
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker...
cve-2026-18527elevate-privilegegui-component-vulnerabilityibmibm-administration-runtime-expertsibm-application-runtime-expertsibm-i-systemnvd-cve
2026-08-28
NVD CVE
CVE-2026-40541: An improper neutralization of input during web page generation ('Cross-site Scri
CRITICAL
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI...
cross-site-scriptingcve-2026-40541denialdsrmfile-readingfiles-writinginputs-neutralizationnvd-cve
2026-08-28
NVD CVE
CVE-2026-82082: NUMail developed by Green-Computing has an OS Command Injection vulnerability. U
CRITICAL
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
arbitrary-command-executioncve-2026-82082green-computingnumailnvd-cveos-command-injectionremote-attackssecurity-vulnerability