LIVE FEED
4291 events · 13 sources · newest first
Events in view
4291
all sources
Critical
1876
severity
Active sources
13
collectors
Last sync
2026-08-31 12:00
UTC
All sources
NVD CVE · 1826CISA KEV · 1686News · 449CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-08-11
NVD CVE
CVE-2026-65768: Improper limitation of a pathname to a restricted directory ('path traversal') i
HIGH
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
androidandroid-appscode-executioncve-2026-65768exploitmicrosoftmicrosoft-teamnetwork-security
2026-08-11
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-223-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities...
authentication-bypasscisacisa-advisorycve-2026-66098cve-2026-66340cve-2026-66875cve-2026-67558cve-2026-67568
2026-08-10
NVD CVE
CVE-2026-18948: A flaw was found in Feast. The system improperly deserializes user-defined funct
CRITICAL
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious...
arbitrary-code-executioncross-tenant-data-accesscve-2026-18948deserializationdillfeastlateral-movementnvd-cve
2026-08-10
CISA advisory
<h2><strong>Advisory at a Glance</strong></h2>
<table>
<tbody>
<tr>
<th>Title</th>
<td>#StopRansomware: Gunra Ransomware</td>
</tr>
<tr>
<th>Original Publication</th>
<td>August 10, 2026</td>
</tr>
<tr>
<th>Executive...
academia-sectorsactive-directoryaffiliate-programcisa-advisoriescisa-advisorycommands-and-controlcredentials-dumpingcritical-manufacturing-sector
2026-08-10
NVD CVE
CVE-2026-14450: A flaw was found in the MaaS API. This vulnerability allows any pod within the c
CRITICAL
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are...
api-keycve-2026-14450first-parties-authenticationforged-headershttps-headerskuadrant-authpolicykubernetemaas-apus
2026-08-10
NVD CVE
CVE-2026-63106: ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerabil
CRITICAL
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause...
administrator-passwords-hashescve-2026-63106database-contentfile-system-accessincident-responsemysqlnvd-cveproduct-controller
2026-08-10
NVD CVE
CVE-2026-13206: Improper neutralization of special elements used in an OS command ('OS command i
CRITICAL
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection.
This issue affects WAH7601: through 20072026.
command-injectioncve-2026-13206cybersecuritynetwork-adapternetwork-securitynetwork-security-vulnerabilitynetworks-devicesnetworks-devices-vulnerabilities
2026-08-10
NVD CVE
CVE-2026-59090: A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsign
HIGH
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to...
2026-08-09
NVD CVE
CVE-2026-19348: A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea
CRITICAL
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1....
add-actcommand-injectioncve-2026-19348enable-1exploitm300-wi-fi-repeaternet-smacfilter-confnvd-cve
2026-08-09
NVD CVE
CVE-2026-71993: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71988: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71989: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71990: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the...
axe6600command-injectioncve-2026-71990firmwaremsinvd-cveradixremote-attacks
2026-08-09
NVD CVE
CVE-2026-71987: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71991: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71992: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71992firmwarefirmware-vulnerabilitiesmacfiltermsi
2026-08-09
NVD CVE
CVE-2026-71984: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71984firmwaremalicious-commandsmsinvd-cve
2026-08-09
NVD CVE
CVE-2026-71985: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers...
nvd-cve
2026-08-09
NVD CVE
CVE-2026-71986: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can...
arbitrary-code-executionaxe6600command-injectioncve-2026-71986dmzfirmwaremalicious-commandsmsi
2026-08-08
NVD CVE
CVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to authori
CRITICAL
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to...
administrator-accountai-copilotauthorization-bypasscontents-generatorcve-2026-14526frontend-pagejavascriptmalicious-workflow
2026-08-08
NVD CVE
CVE-2026-71944: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71945: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71983: MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CRITICAL
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71946: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71958: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71954: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71953: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71955: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71956: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71951: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71950: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71952: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71948: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71947: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71949: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject...
nvd-cve
2026-08-08
NVD CVE
CVE-2026-71957: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CRITICAL
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the...
nvd-cve
2026-08-07
News
The federal IT beat had a busy week. Again. GSA is changing the playbook. Instead of waiting years for standards and policy reviews, GSA is testing technology first. Then it feeds the lessons learned back into the...
2026-08-07
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-219-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>ATN-B1 CPDLC relies on legacy clear text...
attackaviationcisa-advisorycommunicationcybersecurityexploitinfrastructuremitigation
2026-08-07
CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
bod-26-04cisacisa-advisorycommand-injectioncve-2026-8037cverecordcyber-attacksfederal-agencies
2026-08-07
NVD CVE
CVE-2026-62836: Improper restriction of communication channel to intended endpoints in Azure SQL
HIGH
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
azure-sqlimproper-restrictions-communicationsnetworks-vulnerabilitiesnvd-cveprivileges-elevationunauthorized-attacks