LIVE FEED
4274 events · 13 sources · newest first
Events in view
4274
all sources
Critical
1864
severity
Active sources
13
collectors
Last sync
2026-08-31 00:00
UTC
All sources
NVD CVE · 1814CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-08-24
CISA KEV
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
HIGH
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as...
cisa-kev
2026-08-24
NVD CVE
CVE-2026-77915: rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that
CRITICAL
rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes()...
administrator-privilegesapi-token-issuanceauthentication-bypasscve-2026-77915nvd-cverconfigregistration-controllerroles-default
2026-08-24
CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://edit.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
bod-26-04cisacisa-advisorycve-2026-21962cybersecurityexploitationfederal-agenciesfederal-civilian-executive-branch
2026-08-24
NVD CVE
CVE-2026-78169: A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This
CRITICAL
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a...
1250gwaspremotepapconftempsendcve-2026-78169goformhiperhttps-request-handlernvd-cvepublic-exploit
2026-08-24
NVD CVE
CVE-2026-67602: phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST
CRITICAL
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is...
api-tokenapp-codeapp-idauthentication-bypasscaches-keyingcve-2026-67602databases-rows-identifiersinsecure-cache
2026-08-24
NVD CVE
CVE-2026-71933: Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabiliti
CRITICAL
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these...
nvd-cve
2026-08-24
NVD CVE
CVE-2026-78168: A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0.
CRITICAL
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper...
cve-2026-78168efmhttpcon-check-session-urlimproper-authenticationiptimenvd-cveremote-attackssecurities-disclosures
2026-08-24
NVD CVE
CVE-2026-78167: A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted eleme
CRITICAL
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper...
attackcve-2026-78167efmhttpcon-check-session-urlimproper-authenticationiptimenvd-cvepublic-exploit
2026-08-24
NVD CVE
CVE-2026-76070: Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow v
CRITICAL
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded...
base64-decoderbin-netis-cgiboa-web-servercgicve-2026-76070firmwarelogin-handlernc63
2026-08-24
NVD CVE
CVE-2026-76071: Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow v
CRITICAL
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to...
boa-web-serverbuffer-overflowcgicve-2026-76071firmwareipfilterlistnc63netis
2026-08-24
NVD CVE
CVE-2026-71921: Multiple DrayTek VigorSwitch models contain a pre-authentication command injecti
CRITICAL
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command...
nvd-cve
2026-08-24
NVD CVE
CVE-2026-78207: exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in th
CRITICAL
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed...
cell-notecve-2026-78207deepmergeexcelj-hardenedexcelj-vulnerabilityjson-parsingmalicious-codenvd-cve
2026-08-24
NVD CVE
CVE-2026-78211: 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injec
CRITICAL
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter,...
4mosan4mosan-security-technologyadodbarbitrary-command-executioncve-2026-78211gcbs-doctormalicious-command-injectionnvd-cve
2026-08-23
NVD CVE
CVE-2026-78050: A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is th
CRITICAL
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone of the component Web Management. The manipulation...
cf-n1-scgi-bincomfastcve-2026-78050ntp-timezonenvd-cveremote-exploitsecurity-bulletin
2026-08-23
NVD CVE
CVE-2026-7808: justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that ca
CRITICAL
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The...
cross-site-scriptingcve-2026-7808dom-manipulationsforeign-contents-bypasshtml-sanitizationjusthtmlmathml-injectionsnamespaces-mislabeling
2026-08-23
NVD CVE
CVE-2026-5388: justhtml before 1.15.0 contains multiple security issues in URL sanitization hel
CRITICAL
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom...
active-htmlcustoms-sanitizationcve-2026-5388encoded-urlshtml-commenthtml-serializationjavascript-injectionjusthtml
2026-08-23
NVD CVE
CVE-2026-8445: justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-si
CRITICAL
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set...
code-executioncross-site-scriptingcve-2026-8445html-escapinginput-validationjusthtmlmarkdownnvd-cve
2026-08-22
News
<p>The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. </p>
<p>The post <a...
administrative-ruleselections-securitymail-ballotsnewspostal-serviceregulatory-actionsrulemakingscotus
2026-08-22
News
Hackers infect Android car head units with proxy botnet malware ↗
◈ 2 sources · orig. bleepingcomputer.com
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]
ad-fraudandroidbotnetcar-head-unitincident-responsemalwarenewsproxies-botnets
2026-08-22
NVD CVE
CVE-2026-4703: The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vuln
CRITICAL
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission...
code-executioncve-2026-4703deserializationfile-deletionnvd-cvephp-object-injectionsecurity-bulletinsensitive-data-exposure
2026-08-22
NVD CVE
CVE-2026-77946: A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by thi
CRITICAL
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler....
apply-timecgibuffer-overflowcgi-bincve-2026-77946exploitnetwork-trafficntpnvd-cve
2026-08-22
NVD CVE
CVE-2026-78003: The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Requ
CRITICAL
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the...
administrator-accounts-takeoverapi-keycve-2026-78003email-forwardinginput-validationmailgunnvd-cvepassword-reset
2026-08-21
News
<p>Officials leading the Joint Interagency Task Force 401 shared new details about that pilot program and other updates on recent progress.</p>
<p>The post <a...
counter-dronecounter-unmanned-aerial-systemsdefense-scoopdefense-technologydirected-energiesdirected-energy-weaponsdrones-defensegovernmentwide-initiatives
2026-08-21
News
Solutions of choice need to address runtime-relevant exposure, reduce CVE counts, and allow authorizing officials to distinguish noise from mission impact.
ai-securityai-workloadcves-countfederal-newsnetworkmission-criticalmission-impactnational-securitynews
2026-08-21
News
Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.
budget-cutscisacongressional-inquirycybersecurity-agenciescybersecurity-workforcefederal-agenciesgovernment-oversightinvestigation
2026-08-21
News
CISA said agencies will be able to achieve priority logging capabilities that support continuous event monitoring, threat hunting, incident response and more.
agencycisacontinuous-events-monitoringcybersecuritydata-loggingguidanceincident-responsenews
2026-08-21
News
<p>The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data.</p>
<p>The post <a...
apollobreach-disclosurecloud-platformcloud-securitycyber-attackscyberscoopdata-breachesdata-compromise
2026-08-21
News
<p><a href="https://breakingdefense.com/2026/08/space-war-2040-spacecom-preps-for-attacks-on-ground-segments-eyes-cislunar-ops/"><img width="1024" height="576"...
breaking-defensecislunar-operationsground-segmentsjoint-force-developmentjoint-force-trainingnewsspace-attackspace-com
2026-08-21
News
"Attackers are well aware of the demand for that and are going to use it to try to get eyeballs onto their sites," said Greg Pollock.
attackercompromised-websitescybersecuritydemandeyeballfederal-newsnetworkgovernments-websitesnews
2026-08-21
News
<p>The Department of Homeland Security component intends to spend up to $20 million on the “conductive distraction and de-escalation” devices made by Compliant Technologies. </p>
<p>The post <a...
budgetcompliant-technologiesconductive-distractionde-escalationdhdhs-componentfedscoopice
2026-08-21
News
<p><a href="https://breakingdefense.com/2026/08/taiwan-proposes-record-35-billion-defense-budget/"><img width="1024" height="577"...
breaking-defensedefense-budgetlegislaturenewsopposition-controlledtaiwan
2026-08-21
News
<p> “We need help in implementing agents securely, so that it doesn't inadvertently increase our attack surface,” an Army official said. “If we have a bunch of agents roaming around, and they're vulnerable, that just...
adversaryai-agentai-securityarmyattack-surfacecybersecuritydefense-scoopnews
2026-08-21
News
<p>The fiscal 2024 audit shows the GAO slightly off pace from its own targets and further behind OPM’s time-to-hire goals for IT management roles.</p>
<p>The post <a...
auditfiscal-2024gaoit-hiringit-managementnewsoigopm
2026-08-21
News
<p>Hung Cao warned sailors, Marines and Navy civilians about a "deliberate effort to gather intelligence, test our defenses, disrupt our operations, and intimidate our force."</p>
<p>The post <a...
coordinated-campaignscyber-physical-threatdefense-intelligencedefense-scoopforce-intimidationhung-caoinstallation-securityintelligence-gathering
2026-08-21
News
<p><a href="https://breakingdefense.com/2026/08/army-cyber-defenses-need-dedicated-funding-for-ai-top-official-says/"><img width="1024" height="577"...
aiarmyartificial-intelligencebudgetcyber-commandcyber-defensedefense-industrial-basefunding
2026-08-21
News
<p>Sen. Ron Wyden and Rep. Greg Casar want a GAO probe on the government’s use of spyware and other sophisticated hacking tools and authorities.</p>
<p>The post <a...
congressional-investigationscyberscoopcybersecurityfederal-governmentgaoprobehacking-toolsintelligence-agencylawmaker
2026-08-21
News
<p><a href="https://breakingdefense.com/2026/08/hot-competition-nsa-deputy-sounds-alarm-on-china-threat-ai-race/"><img width="1024" height="575"...
ai-racebreaking-defensechina-threatcyber-threatsdefense-industryforeign-influencegeointgeopolitical-threat
2026-08-21
News
<p><a href="https://breakingdefense.com/2026/08/how-the-army-balances-patriot-priorities-and-approaches-golden-dome/"><img width="1024" height="576"...
news
2026-08-21
News
<p>ISASecure, a wholly owned subsidiary of the International Society of Automation (ISA), is partnering with the U.S. National...</p>
<p>The post <a...
certification-schemehcsahigh-criticalityics-certificationics-cyber-securityindustrial-control-systemindustrial-cybersecurityisa
2026-08-21
News
<p>The U.S. National Institute of Standards and Technology (NIST) published a guide that outlines practical and actionable ways...</p>
<p>The post <a...
actionableaiai-promptai-use-caseanalysiscybersecurity-framework-2-0cybersecurity-frameworksguide