Overview of incoming advisories.
1553 results found
A critical OS command injection vulnerability has been identified in D-Link DNS-327L and DNS-340L NAS devices up to firmware version 20260717. The vulnerability exists in the /cgi-bin/ve_mgr.cgi file, where manipulation of the 'f_dev' argument allows an attacker to inject arbitrary OS commands. The flaw can be exploited remotely without requiring physical access to the device. A public exploit has already been published, increasing the risk of active exploitation. The vulnerability affects network-attached storage devices commonly used in home and small business environments. No official patch details are mentioned in the article. The issue has been documented in VulDB and referenced in NVD. Given the remote exploitability and public exploit availability, this is considered a high-severity issue. Users of affected D-Link NAS devices should monitor for vendor advisories and apply mitigations promptly.
View original advisory →A vulnerability has been identified in D-Link DSM-G600 version 1.01 affecting the /load_file.cgi file within the Multipart Handler component. The flaw allows an attacker to trigger an out-of-bounds write through manipulation of an unknown function. The attack can be launched remotely without requiring physical access to the device. A public exploit has already been released, increasing the risk of active exploitation. The vulnerability is tracked as CVE-2026-82680 and has been documented in VulnDB and GitHub. D-Link network storage devices are the affected product class. The public availability of the exploit significantly elevates the threat level for unpatched devices. Organizations using D-Link DSM-G600 should monitor for patches and apply mitigations immediately.
View original advisory →The npm package @hulumi/policies versions before 1.3.2 contains a vulnerability where inline and attached IAM policy evidence is not fully inspected for the administrator-policy guardrail. This flaw allows attackers to craft admin-equivalent policy paths that bypass policy evaluation controls. The vulnerability effectively enables privilege escalation by circumventing intended access restrictions. Users should upgrade to version 1.3.2 or later to remediate the issue. The vulnerability has been assigned CVE-2026-82860 and is rated high severity. It poses a significant risk in cloud environments where IAM policy enforcement is critical to access control boundaries.
View original advisory →A command injection vulnerability was identified in TOTOLINK NR1800X router firmware version 9.1.0u.6681_B20230703. The vulnerability exists in the setUssd function within the /cgi-bin/cstecgi.cgi file. An attacker can manipulate the 'ussd' argument to inject arbitrary commands. The attack can be launched remotely without requiring physical access to the device. A public exploit is already available, increasing the risk of active exploitation. This type of vulnerability in network routers poses significant risk to network security and integrity. The affected product is a 5G NR router commonly used for broadband connectivity.
View original advisory →A path traversal vulnerability exists in pnpm package manager versions prior to 10.34.5 and from 11.0.0 until 11.11.0. The flaw stems from pnpm parsing package names from attacker-controlled pnpm-lock.yaml files without proper validation. The unvalidated package name is passed to path.join(), storeController.importPackage, and related functions, enabling package contents to be written outside the intended node_modules directory. If lifecycle scripts are permitted via dangerouslyAllowAllBuilds or a matching allowBuilds configuration, an attacker can achieve arbitrary code execution with the victim user's privileges. The attack vector requires a user to run pnpm install against a malicious or compromised lockfile. This represents a supply chain risk, particularly in CI/CD environments or shared repositories. Fixes are available in pnpm versions 10.34.5 and 11.11.0.
View original advisory →CVE-2026-76133 affects an Ebyte product that uses a deprecated hashing algorithm in an authentication-related operation. The weak cryptographic construction reduces the assurance of the authentication mechanism. Under conditions where an attacker can manipulate or predict the authentication exchange, unauthorized access may be facilitated. The vulnerability is classified as an authentication weakness tied to outdated cryptographic practices. It is tracked by NVD and has an associated CISA ICS advisory (icsa-26-237-06). The issue falls under the category of improper use of deprecated algorithms in security-critical operations. It is particularly relevant to OT/ICS environments given the CISA advisory context. The current risk level is rated High.
View original advisory →A SQL injection vulnerability has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw exists in the Employee::employeeAuthentication function within the /rider/login.php file at the Login Interface component. Attackers can manipulate the emp_email argument to perform SQL injection attacks. The vulnerability is remotely exploitable without requiring physical access to the target system. A public exploit has already been released, increasing the risk of active exploitation. This type of vulnerability can allow attackers to bypass authentication and gain unauthorized access to the system. The affected product is a web-based medicine delivery management system. The issue has been documented in VulDB and the National Vulnerability Database. Organizations using this software should apply patches or mitigations immediately given the public availability of the exploit.
View original advisory →CVE-2026-82861 affects @hulumi/policies versions before 1.3.2, exposing a parent spoof bypass vulnerability in the policy evaluation engine. Attackers can submit falsified SecureBucket parent evidence during policy evaluation, tricking the validator into treating unsafe bucket configurations as compliant. This allows bypassing security policy checks entirely, potentially exposing misconfigured or insecure storage buckets. The vulnerability is resolved in version 1.3.2 of the package. It has been disclosed via GitHub Security Advisories and VulnCheck. The issue is particularly concerning for environments relying on @hulumi/policies for enforcing storage security posture. No active exploitation has been publicly confirmed, but the bypass nature warrants high-priority patching.
View original advisory →A command injection vulnerability has been identified in D-Link DIR-825M firmware version 1.1.8. The vulnerability resides in the function sub_456CF4 within the file /boafrm/formSysCmd, part of the System Command Execution component. An attacker can manipulate the 'sysCmd' argument to inject arbitrary operating system commands. The attack can be initiated remotely without physical access to the device. A public exploit has been released, increasing the risk of active exploitation. The vulnerability is tracked as CVE-2026-82595 and has been submitted to VulDB. D-Link home/SMB routers are the affected product class. Users are advised to monitor for patches or apply mitigations. The public disclosure and exploit availability make this a high-priority issue for affected device owners.
View original advisory →CVE-2026-82659 affects nodemailer versions before 9.0.1, where the disableFileAccess and disableUrlAccess security flags are not applied to the message-level raw option. This oversight allows authenticated attackers to supply path or href properties in crafted raw messages, enabling arbitrary file reads or server-side request forgery (SSRF). The vulnerability bypasses the intended sandbox restrictions, with fetched file or URL content being delivered in outgoing emails to attacker-controlled recipients. The attack requires authentication but can lead to significant data exfiltration or internal network reconnaissance via SSRF. The fix is available in nodemailer version 9.0.1 and above. Organizations using nodemailer in their applications should upgrade immediately to mitigate risk.
View original advisory →A critical OS command injection vulnerability has been identified in D-Link DNS-340L and DNS-345 network-attached storage devices across multiple firmware versions (1.01B04, 1.03B06, 1.04.B02, 1.05b04). The vulnerability exists in the /cgi-bin/virtual_vol.cgi file within the Virtual Volume Handler component. Attackers can manipulate the arguments f_sharename, f_target, or f_name to inject arbitrary OS commands. The vulnerability is remotely exploitable without requiring physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation in the wild. D-Link NAS devices are commonly used in home and small business environments, broadening the potential attack surface. The vulnerability has been assigned CVE-2026-82688 and is tracked on NVD and VulnDB.
View original advisory →A critical OS command injection vulnerability (CVE-2026-82691) has been identified in multiple D-Link NAS devices including DNS-320L, DNS-327L, DNS-340L, and DNS-345 running firmware up to version 20260717. The vulnerability exists in the CGI Handler component, specifically in the /cgi-bin/usb_device.cgi file. By manipulating the f_ups_ip argument, a remote attacker can execute arbitrary OS commands on the affected device. The attack can be performed remotely without requiring physical access. A public exploit has already been disclosed, increasing the risk of active exploitation. D-Link NAS devices are commonly deployed in small business and home office environments, making this a significant threat to a wide range of users.
View original advisory →CVE-2026-77966 affects an Ebyte product that fails to properly separate limited user and administrative management functions. A low-privileged authenticated attacker can access security-sensitive configuration functions without proper authorization. This flaw allows unauthorized modification of device settings, potentially impacting the confidentiality, integrity, and availability of the device. The vulnerability is classified as an improper access control or broken access control issue. It is relevant to OT/ICS environments, as indicated by the CISA ICS advisory reference. CISA has published an advisory (ICSA-26-237-06) detailing the issue. The vulnerability poses a significant risk as it can be exploited by any authenticated low-privileged user on the device.
View original advisory →YaCy Search Server through version 1.941 is affected by an XML External Entity (XXE) injection vulnerability. The flaw exists in three parsers: SVG, FreeMind, and OpenSearch, which fail to disable external entity resolution. Attackers can craft malicious documents with DOCTYPE declarations referencing SYSTEM entities that point to local files on the server. When the YaCy crawler processes these documents, it inadvertently exfiltrates local file contents into the searchable index, exposing sensitive data. The vulnerability allows unauthorized access to local filesystem contents through the crawler mechanism. A fix has been committed to the repository. Multiple parser source files are identified as vulnerable, including svgParser.java, mmParser.java, and opensearchdescriptionReader.java. The issue is tracked publicly via GitHub issue #818 and has been reported by VulnCheck.
View original advisory →CVE-2026-81780 describes an unauthenticated arbitrary file upload vulnerability affecting the Hash Form WordPress plugin in versions 1.4.2 and below. This vulnerability allows unauthenticated attackers to upload arbitrary files to the affected WordPress site, which could lead to remote code execution. The flaw is particularly critical because no authentication is required to exploit it, greatly expanding the potential attack surface. The vulnerability was documented by both the NVD (National Vulnerability Database) and Patchstack. Users of the Hash Form plugin are advised to update to a patched version immediately. Arbitrary file upload vulnerabilities are commonly leveraged by attackers to plant web shells or malicious scripts on compromised servers. The severity is rated High due to the unauthenticated nature and potential for full site compromise.
View original advisory →A path traversal vulnerability in pnpm package manager (prior to versions 10.34.5 and 11.11.0) allows attackers to overwrite arbitrary filesystem paths during package installation. The flaw exists because pnpm's pickPackage.ts only rejects slash characters in unscoped package names, leaving scoped names unvalidated. The unvalidated name is then used in raw path joins across multiple source files, enabling package extraction outside the intended node_modules directory. Attackers can craft malicious tarball dependencies whose package.json manifest names exploit this bypass. The attack can overwrite critical files such as shell startup scripts, Git hooks, or installed package code, ultimately leading to arbitrary code execution. Critically, the vulnerability persists even when the --ignore-scripts flag is used, bypassing a common security mitigation. The issue has been patched in pnpm versions 10.34.5 and 11.11.0.
View original advisory →CVE-2026-51680 describes an incorrect access control vulnerability in the setLedCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to modify LED behavior on the affected device by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication or credentials are required to exploit this vulnerability, making it trivially accessible to any attacker with network access to the device. The vulnerability stems from missing or improperly enforced access controls on a sensitive CGI function. While the immediate impact appears limited to LED configuration changes, the pattern of unauthenticated CGI access could indicate broader attack surface concerns on this device. TOTOLINK T6 is a consumer/SOHO networking device, and such vulnerabilities are commonly targeted in IoT-focused botnet campaigns.
View original advisory →A severe path traversal vulnerability has been identified in Goploy, an open-source automation deployment system, affecting versions prior to 1.18.0. The vulnerability exists in the backend API endpoint /deploy/fileDiff (File Compare), which improperly handles file paths provided by clients. This flaw could allow attackers to traverse the file system and access arbitrary files outside the intended directory. The vulnerability has been classified as severe, indicating significant risk to affected deployments. A patch has been released in version 1.18.0 of Goploy. Users are strongly advised to upgrade to the patched version immediately. The fix is documented in a specific commit and detailed in a GitHub Security Advisory. No active exploitation has been mentioned, but the severity of path traversal vulnerabilities makes prompt remediation critical.
View original advisory →A vulnerability has been identified in MSI Dragon Center up to version 2.0.155.0, specifically in the MmioWritePath function within the NTIOLib_X64.sys library. The flaw resides in the MMIO Write Path Handler component, where manipulation of the count/elementSize arguments leads to an integer overflow condition. The vulnerability requires local access to exploit, limiting its attack surface but not eliminating risk for multi-user or shared systems. A public exploit has been released, increasing the likelihood of active exploitation. The vendor was notified prior to public disclosure but did not respond, leaving users without an official patch or mitigation guidance. This unpatched status, combined with public exploit availability, raises the overall risk level significantly.
View original advisory →MCPHub, a unified hub for managing and orchestrating multiple MCP servers/APIs, contains an authorization bypass vulnerability prior to version 1.0.31. The flaw exists in the isBearerKeyAllowedForRequest function, which incorrectly grants access to an entire server group when a bearer key with accessType 'servers' or 'custom' is used against a group route. Access is granted if any single server in the group appears in the key's allowedServers list, rather than verifying all servers. Once group-level access is authorized, allowedServers is never re-checked. This means a key scoped to one specific server inadvertently grants full access to all other servers sharing the same group, including those the key was never authorized for. The vulnerability represents a significant privilege escalation risk in multi-server environments. The issue has been fully patched in MCPHub version 1.0.31.
View original advisory →