Overview of incoming advisories.
1553 results found
CVE-2026-82855 affects @hulumi/policies versions before 1.3.2, exposing an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators. Attackers can exploit this flaw by submitting compliant evidence from unrelated zones, hostnames, origins, or repositories to suppress policy violations. This allows bypassing security guardrails for unrelated resources within the same stack. The vulnerability undermines the integrity of policy enforcement mechanisms designed to govern deployments and Cloudflare configurations. The issue is resolved in version 1.3.2 of the package. The vulnerability has been assigned a high criticality rating, indicating significant risk to affected deployments. Organizations using @hulumi/policies for infrastructure governance should upgrade immediately to mitigate potential exploitation.
View original advisory →CVE-2026-51720 describes an incorrect access control vulnerability in the TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. The flaw exists in the delIpPortFilterRules function, which fails to enforce authentication before processing requests. Unauthenticated remote attackers can exploit this by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. Successful exploitation allows attackers to delete firewall IP/port filter rules, potentially exposing the network to further attacks. The vulnerability is significant because it undermines network perimeter defenses without requiring any credentials. It affects TOTOLINK T6 routers, which are consumer and small business networking devices. References include GitHub repositories detailing vendor coordination efforts and the TOTOLINK official website for firmware downloads.
View original advisory →A critical OS command injection vulnerability (CVE-2026-82668) has been identified in klaussilveira GitList version 2.0.0. The vulnerability exists in the getDefaultBranch function within src/SCM/System/Git/CommandLine.php of the Git Command Line component. An attacker can exploit this flaw remotely to execute arbitrary OS commands. The exploit has been publicly disclosed and is available for use, increasing the risk of active exploitation. A patch has been released and is identified by commit 88cf2866083d5f7c20d9d565c45f828a7ad1516b. Users are strongly advised to upgrade to GitList version 3.0.0-beta to remediate the vulnerability. No workaround is mentioned other than upgrading the affected component.
View original advisory →CVE-2026-82856 affects @hulumi/policies versions before 1.3.2, which fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can exploit this vulnerability by using ForAnyValue:StringLike operators to obscure wildcard GitHub Actions OIDC subject conditions, effectively bypassing security guardrails. This allows malicious actors to craft trust policies that appear compliant but grant overly permissive access. The vulnerability poses a significant risk in CI/CD pipelines that rely on GitHub Actions with AWS IAM role assumption via OIDC federation. The fix is available in version 1.3.2 of the package. Organizations using this library should upgrade immediately to prevent unauthorized AWS resource access. The issue has been documented in both the GitHub security advisory and VulnCheck advisories.
View original advisory →A critical unauthenticated SQL injection vulnerability has been identified in the WordPress plugin 'Throws SPAM Away' affecting versions 3.8.2 and earlier. The vulnerability allows unauthenticated attackers to perform SQL injection attacks, potentially exposing sensitive database information or enabling further compromise of the WordPress site. The flaw is documented under CVE-2026-81763 and has been reported via both the NVD and Patchstack vulnerability databases. No authentication is required to exploit this vulnerability, making it particularly dangerous for unpatched installations. WordPress site administrators using this plugin are advised to update to a patched version immediately. The vulnerability was assigned a high severity rating. Details are available through the NVD and Patchstack advisory pages.
View original advisory →A critical unrestricted file upload vulnerability has been identified in the Cozmoslabs Profile Builder Plugin for WordPress, affecting versions up to 3.16.1. The vulnerability resides in the wppb_ajax_simple_avatar function within the Avatar Simple Upload AJAX Handler component at /wp-admin/admin-ajax.php. An unauthenticated remote attacker can exploit this flaw to upload arbitrary files to the server, potentially leading to remote code execution. The exploit has been publicly disclosed, increasing the risk of active exploitation in the wild. The vulnerability has been assigned CVE-2026-82607 and is rated as high severity. WordPress site administrators running affected versions are strongly advised to upgrade to version 3.16.2, which resolves the issue. No workaround is documented other than upgrading the plugin.
View original advisory →A critical OS command injection vulnerability (CVE-2026-82692) has been discovered in D-Link DNS-340L and DNS-345 NAS devices up to firmware version 20260717. The vulnerability exists in the /cgi-bin/iscsi_mgr.cgi file, where manipulation of the alias, username, password, or volume_location arguments can lead to OS command injection. The attack can be initiated remotely without requiring physical access. A public exploit has been released, increasing the risk of active exploitation. The vulnerability affects iSCSI management functionality of the affected D-Link NAS devices. D-Link DNS-340L and DNS-345 are network-attached storage devices commonly used in home and small business environments. The public availability of the exploit significantly elevates the risk level for unpatched devices. Users of affected D-Link NAS devices should apply patches or mitigations immediately to prevent potential compromise.
View original advisory →A vulnerability has been identified in cu silicon up to version 0.1.5. The vulnerability affects the create_app function in views.py within the edit Endpoint component. Exploitation of this flaw leads to missing authentication, allowing unauthenticated access. The attack can be performed remotely without requiring local access. A public exploit is already available, increasing the risk of active exploitation. The vendor was notified prior to disclosure but did not respond. This raises concerns about the availability of a patch or mitigation. The lack of vendor response leaves users of affected versions at continued risk.
View original advisory →A critical missing authentication vulnerability has been identified in Tenda AC1206 firmware version 15.03.06.23. The vulnerability affects the R7WebsSecurityHandler function within the /goform/ate endpoint of the device's Web UI component. An attacker can exploit this flaw remotely without requiring any authentication credentials. The exploit code is publicly available, significantly increasing the risk of active exploitation in the wild. The issue allows unauthorized access to sensitive router functions through the web interface. Tenda AC1206 is a consumer-grade wireless router, making this vulnerability potentially impactful across many home and small business networks. The vulnerability has been catalogued in VulDB and assigned CVE-2026-82694.
View original advisory →ToolJet versions before v3.16.208 contain a critical cross-tenant authorization bypass vulnerability in its tooljet-db endpoints. The flaw allows any authenticated Builder user to access, modify, and delete database tables belonging to other organizations without authorization. The vulnerability stems from a failure to validate that the authenticated user belongs to the organization specified in the organizationId path parameter. Attackers can harvest victim organization IDs from public app endpoints and then exploit schema operation endpoints to read table schemas, insert malicious tables, corrupt existing schemas, or permanently delete victim data. This represents a significant multi-tenant isolation failure that could lead to data breaches and data destruction across organizational boundaries. A fix has been released in ToolJet v3.16.208.
View original advisory →A missing authentication vulnerability has been identified in Tenda AC1206 firmware version 15.03.06.23. The flaw exists in the TendaTelnet function located at /goform/telnet within the Web UI component. An unauthenticated remote attacker can exploit this vulnerability by manipulating the affected endpoint without requiring any credentials. The vulnerability is remotely exploitable and the exploit has been publicly disclosed, increasing the risk of active exploitation. Affected users should apply patches or mitigations as soon as they become available. The issue has been documented in VulDB and assigned CVE-2026-82693. The public disclosure of a working exploit raises the severity and urgency for remediation.
View original advisory →CVE-2026-51680 is an incorrect access control vulnerability discovered in the setLedCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to modify the device's LED behavior by sending a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication or credentials are required to exploit this vulnerability, making it trivially accessible to any attacker with network access to the device. The vulnerability stems from insufficient access controls on a CGI-based web interface function. TOTOLINK T6 is a consumer/SOHO network router, meaning exploitation could affect home and small business environments. Proof-of-concept and vendor coordination details have been published on GitHub by security researchers. The vendor's official website and firmware download pages have been referenced as part of the disclosure.
View original advisory →CVE-2026-49003 is a critical command injection vulnerability affecting ZTE power monitoring systems. Attackers can exploit this flaw to delete core system runtime files, causing the monitoring module to crash and become non-functional. The vulnerability also allows attackers to escalate privileges to root level, enabling theft of sensitive configuration credentials including SNMP passwords. With root access and stolen credentials, attackers can tamper with critical system parameters, potentially triggering abnormal operation of entire power systems. This represents a significant threat to critical infrastructure, combining availability impact (crash) with confidentiality (credential theft) and integrity (parameter tampering) impacts. ZTE has published a security bulletin addressing this issue.
View original advisory →CVE-2026-82217 affects Eclipse Theia versions 1.73.0 up to but not including 1.75.0. The AI Agent Mode file-change tools (writeFileContent, suggestFileContent, and related helpers) fail to validate that model-supplied file paths remain within the workspace boundary. Attackers can supply crafted relative paths (e.g., ../.bashrc), absolute paths, or tilde-expanded paths to read, write, or delete files outside the workspace with the privileges of the Theia backend OS user. Because the path argument is derived from model output, the vulnerability is exploitable via indirect prompt injection. In Agent Mode, file writes are applied automatically without a user confirmation dialog, removing a key safety gate. Writing to sensitive host-executed files such as shell startup scripts or ~/.ssh/authorized_keys can lead to remote code execution on the backend host. Patches are available in version 1.75.0 and later, with a fix referenced in the linked GitHub commit.
View original advisory →A path traversal vulnerability has been identified in Dokploy up to version 0.29.7. The flaw exists in the writeTraefikConfigInPath function within packages/server/src/utils/traefik/application.ts in the Settings component. An attacker can manipulate the path argument to traverse directories outside the intended scope. The vulnerability is remotely exploitable without requiring physical access. A public exploit is already available, increasing the risk of active exploitation. The vendor was contacted prior to disclosure but did not respond, leaving users without an official patch or mitigation. This represents a significant risk to deployments running affected versions of Dokploy. Users are advised to restrict access and monitor for suspicious file access patterns until a fix is available.
View original advisory →A SQL injection vulnerability has been identified in SeaCMS versions up to 13.6. The flaw exists in the /zyapi.php?ac=videolist endpoint, where manipulation of the 'ids' argument allows SQL injection attacks. The vulnerability can be exploited remotely without requiring local access. A public exploit has already been released, increasing the risk of active exploitation. The issue affects an unknown functionality within the specified file. The vulnerability has been catalogued under CVE-2026-82600 and documented across NVD and VulDB. No authentication details are specified, suggesting it may be exploitable without credentials. Organizations using SeaCMS 13.6 or earlier should apply mitigations promptly given the public exploit availability.
View original advisory →CVE-2026-59111 describes an OS command injection vulnerability in the eObčanka-Identifikace application developed by Digitální a informační agentura (DIA) for macOS. The application registers a custom URL scheme (czeeopauth://) that allows parameterized application execution. Prior to version 3.6.0, URL parameters passed to a compiled AppleScript wrapper were concatenated without adequate sanitization, enabling OS command injection. An attacker could exploit this by crafting a malicious URL using the custom scheme to inject arbitrary OS commands. The vulnerability is classified under CWE as improper neutralization of special elements used in OS commands. The fix was introduced in version 3.6.0 of the application. Users are advised to update to version 3.6.0 or later to mitigate the risk.
View original advisory →A critical OS command injection vulnerability (CVE-2026-82689) has been identified in multiple D-Link NAS devices including DNS-320L, DNS-327L, DNS-340L, and DNS-345 up to firmware version 20260717. The vulnerability exists in the /cgi-bin/isomount_mgr.cgi file within the ISO Image Handler component. Attackers can exploit the vulnerability by manipulating the upIsoRootPath argument to inject arbitrary OS commands. The attack can be carried out remotely without requiring physical access to the device. A public exploit is already available, significantly raising the risk of active exploitation. D-Link NAS devices are commonly used in home and small business environments, making this a widespread risk. The exposure of this vulnerability with a public proof-of-concept increases the urgency for patching or mitigation measures.
View original advisory →CVE-2026-73819 affects an Ebyte product's vendor configuration utility, which allows access to administrative functions without proper identity verification under certain credential conditions. An unauthenticated attacker located on the adjacent network can exploit this flaw to modify critical device settings or change access credentials. This could result in legitimate administrators being locked out of device management. The vulnerability is classified as an authentication bypass or missing authentication for critical function issue. It is relevant to OT/ICS environments given the CISA ICS advisory association. The advisory is referenced by CISA under ICSA-26-237-06, indicating it has been reviewed as an industrial control system security concern. The attack vector requires adjacent network access, limiting but not eliminating the risk. The potential impact includes unauthorized configuration changes and disruption of legitimate administrative control.
View original advisory →A SQL injection vulnerability has been identified in code-projects Online Shopping System version 1.0. The vulnerability exists in the /action.php file within the Search Functionality component, where the 'keyword' argument is not properly sanitized. An attacker can manipulate this parameter to perform time-based blind SQL injection attacks. The attack can be initiated remotely without requiring physical access to the target system. A public exploit has already been disclosed and is available for use, increasing the risk of active exploitation. The affected software is a web-based online shopping platform. This vulnerability poses a significant risk to data confidentiality and integrity as unauthorized database access may be achieved. Organizations using this software should apply patches or mitigations immediately.
View original advisory →