LIVE FEED
4277 events · 13 sources · newest first
Events in view
4277
all sources
Critical
1866
severity
Active sources
13
collectors
Last sync
2026-08-31 06:00
UTC
All sources
NVD CVE · 1816CISA KEV · 1686News · 445CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-08-19
News
<p>An inspector general report said IRS employees who took deferred resignation offers didn’t have a "legitimate business reason” to still have access to sensitive agency networks. </p>
<p>The post <a...
2026-08-19
News
<p>The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first.</p>
<p>The post <a...
2026-08-19
News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild.
The...
2026-08-19
CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
bod-26-04cisacisa-advisorycompromisecve-2026-64849cyber-attacksfederal-agenciesfederal-enterprises
2026-08-19
NVD CVE
CVE-2026-76310: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut
CRITICAL
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material,...
administrative-actionscve-2026-76310embedded-reportsnvd-cvereport-managementrest-apirole-based-accesssessions-materials
2026-08-19
NIST
<p>This new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing, and monitoring an organization’s progress toward achieving CSF 2.0 outcomes....
ai-prompt-engineeringartificial-intelligencecybersecurity-frameworkscybersecurity-policygeneratives-aimission-objectivesnismapnist
2026-08-19
NVD CVE
CVE-2026-18315: The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CRITICAL
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including,...
accounts-takeoverauthorization-bypasscve-2026-18315emails-overwritelost-password-flownvd-cveplugins-vulnerabilitiessecurity-vulnerability
2026-08-19
CISA KEV
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
attack-vectorscisa-kevcloud-metadatacloud-securitycve-2026-64849internal-servicesmetadata-servicesmlflow
2026-08-19
NVD CVE
CVE-2026-76886: C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows den
HIGH
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
2026-08-19
NVD CVE
CVE-2026-70496: A flaw was found in search-v2-operator. The operator's ClusterRole has permissio
CRITICAL
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC)...
certificates-signing-requestcluster-administratorsclusterrolecve-2026-70496excessive-privilegeimpersonationkubernetemanifestwork
2026-08-19
NVD CVE
CVE-2026-76003: A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected
CRITICAL
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based...
cve-2026-76003nvd-cveremote-attacksstack-based-buffer-overflowstrcpyuttutt-hyper-1200gwutt-hypers
2026-08-19
NVD CVE
CVE-2026-76312: In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unaut
CRITICAL
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session...
authorization-boundariescve-2026-76312dispatches-archivesembedded-reportshtml-sourcenvd-cvereport-managementsearch-job-data
2026-08-19
NVD CVE
CVE-2026-71960: Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC si
CRITICAL
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT...
authenticationcudycve-2026-71960firmwarehmacjwtmesh-networkingmosquitto
2026-08-19
NVD CVE
CVE-2026-76590: A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by
CRITICAL
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument...
cgi-bincve-2026-76590nvd-cvepppoepublicly-available-exploitremote-exploitsecurity-bulletinssi
2026-08-19
NVD CVE
CVE-2026-75976: A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the
CRITICAL
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes...
buffer-overflowcgi-bincve-2026-75976exploitnetwork-attached-storagenvd-cvenvrremote-attacks
2026-08-19
NVD CVE
CVE-2026-76589: A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the
CRITICAL
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack...
buffer-overflowcvecve-2026-76589firmware-vulnerabilitiesnetwork-adapternetwork-securitynvd-cveremote-attacks
2026-08-19
NVD CVE
CVE-2026-76311: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut
CRITICAL
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed...
authorization-flowcve-2026-76311dispatches-archivesembedded-reportsnvd-cvereport-managementscheduled-reportssecurity-configuration
2026-08-19
CISA advisory
<h2><strong>Executive summary</strong></h2>
<p><em><strong>Note:</strong> This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity...
access-controlcisa-advisoriescisa-advisorycritical-infrastructuredefensedepthincident-responseinternet-exposure
2026-08-19
NVD CVE
CVE-2026-16919: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.
aixarbitrary-code-executioncve-2026-16919ibmimproper-validationnetwork-supplied-pointernvd-cvepowervm
2026-08-19
NVD CVE
CVE-2026-66794: A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine f
CRITICAL
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and...
authentication-bypassauthorization-bypasscluster-compromisecluster-proxy-addoncve-2026-66794information-disclosureinternal-service-accesskubernete
2026-08-18
News
The federal CIO's office is reviewing governmentwide cyber supply chain security standards, as it looks to root risks related to foreign adversaries.
2026-08-18
News
Tanner will manage the Navy and Marine Corps’ information technology portfolio of more than $12 billion.
2026-08-18
News
"We are in a messy middle situation, where they don't have funding certainty, but they also don't have regulatory certainty," said Stephanie Kostro.
2026-08-18
News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
Ray is an...
2026-08-18
NVD CVE
CVE-2026-70979: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily...
2026-08-18
NVD CVE
CVE-2026-71014: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0....
2026-08-18
NVD CVE
CVE-2026-71015: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0....
2026-08-18
NVD CVE
CVE-2026-62610: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
confidentiality-impactcritical-datacve-2026-62610cvss-31data-compromisehttpintegrity-impactnetwork-access
2026-08-18
NVD CVE
CVE-2026-71036: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily...
2026-08-18
NVD CVE
CVE-2026-60995: Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion
CRITICAL
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability...
cve-2026-60995cvss-31cvss-99network-securitynvd-cveoracleoracle-fusionoracle-identity-manager-connector
2026-08-18
NVD CVE
CVE-2026-70978: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily...
2026-08-18
NVD CVE
CVE-2026-70670: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
2026-08-18
NVD CVE
CVE-2026-70977: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily...
availability-impactcve-2026-70977cvss-31data-creationdata-deletiondata-modificationdosdose-attack
2026-08-18
NVD CVE
CVE-2026-70673: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability...
confidentiality-impactcve-2026-70673cvss-31data-compromisehttpintegrity-impactnetwork-accessnvd-cve
2026-08-18
NVD CVE
CVE-2026-18963: A flaw was found in the reset-credentials flow of the keycloak-services componen
CRITICAL
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated...
accounts-takeovercredentials-compromisecve-2026-18963email-verification-bypassidentity-and-access-managementkeycloakkeycloak-servicenvd-cve
2026-08-18
NVD CVE
CVE-2026-70976: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience
CRITICAL
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily...
availability-impactcontent-acquisition-systemscve-2026-70976cvss-31data-creationdata-deletiondata-modificationdos
2026-08-18
NVD CVE
CVE-2026-61001: Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middle
CRITICAL
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...
confidentiality-impactcve-2026-61001cvss-31data-modificationhttpintegrity-impactlow-privileged-attackernetwork-access
2026-08-18
NVD CVE
CVE-2026-62609: Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middlewar
CRITICAL
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability...
2026-08-18
NVD CVE
CVE-2026-71065: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CRITICAL
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated...
2026-08-18
NVD CVE
CVE-2026-70926: Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (compone
CRITICAL
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows...
availabilitycompromiseconfidentialitycve-2026-70926cvss-31cvss-98integritynetwork-access