Overview of incoming advisories.
1553 results found
A critical security vulnerability has been identified in Tenda AC18 firmware version 15.03.05.19. The flaw resides in the /goform/telnet endpoint within the Telnet Handler component. The vulnerability allows attackers to bypass authentication entirely, enabling unauthorized remote access. The attack vector is network-based and requires no authentication or special privileges. A public exploit has already been released, significantly raising the risk of active exploitation. The vulnerability is classified as missing authentication, which is a fundamental security control failure. Affected users should apply patches or mitigations as soon as possible to prevent unauthorized access to their routers.
View original advisory →A SQL injection vulnerability has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw exists in the Customer::find_phone function within the /passwordrecover.php file, part of the Password Recovery Interface component. An attacker can manipulate the 'phonenumber' argument to perform SQL injection attacks remotely. The vulnerability is exploitable over the network without requiring physical access. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability has been assigned CVE-2026-82615 and is tracked in VulDB. Affected users of the itsourcecode Online Medicine Delivery System 1.0 are advised to apply patches or mitigations promptly. The public disclosure of the exploit significantly elevates the urgency for remediation.
View original advisory →A stack-based buffer overflow vulnerability has been identified in D-Link DIR-825M firmware version 1.1.8. The flaw exists in the function sub_41802C within the file /boafrm/formLtefotaUpgradeFibocom, which is part of the LTE Module Firmware Upgrade component. The vulnerability is triggered by manipulating the 'fota_url' argument, leading to a stack-based buffer overflow condition. The attack can be executed remotely without physical access to the device. A public exploit has already been published, increasing the risk of active exploitation. This affects IoT and network infrastructure devices, specifically D-Link routers with LTE capabilities. The availability of a public exploit makes this a high-priority vulnerability for patching and mitigation.
View original advisory →CVE-2026-51720 describes an incorrect access control vulnerability in the delIpPortFilterRules function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to delete firewall filter rules by sending a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication is required to exploit this vulnerability, making it particularly dangerous as attackers can silently weaken the device's firewall posture. Successful exploitation could expose the network to further attacks by removing protective filtering rules. The vulnerability was reported via GitHub-hosted CVE vendor coordination repositories and affects TOTOLINK networking hardware. This type of unauthenticated access control bypass in network infrastructure devices poses significant risk to home and small business users.
View original advisory →CVE-2026-81892 affects EasyAdmin, an admin generator for Symfony applications, across versions 4.0.0 to 4.29.16 and up to 5.5.1. The vulnerability stems from EasyAdmin routing all backend requests through a single dashboard route and swapping controllers based on an unvalidated routeName query parameter. Because Symfony's security firewall evaluates access_control rules against the original dashboard URL before the controller swap occurs, path-based access control rules protecting target routes are never evaluated. This allows a low-privilege backend user with knowledge of a target route's name to execute that route's controller, effectively bypassing path-based authorization. Routes protected by inline authorization checks such as #[IsGranted] or denyAccessUnlessGranted() remain unaffected. The vulnerability has been patched in EasyAdmin versions 4.29.16 and 5.5.1. Fixes are available via two separate commits on the EasyCorp GitHub repository.
View original advisory →CVE-2026-82862 affects Hulumi versions before v1.3.2, where the threat-model helper script is resolved from an unsafe root directory. This flaw allows workspace files to shadow the intended helper script, enabling attackers to place malicious files in the workspace. When a local skill execution occurs, the malicious file is executed instead of the legitimate helper script, resulting in arbitrary code execution. The vulnerability is classified as high severity. Users are advised to upgrade to Hulumi v1.3.2 or later to remediate the issue. The advisory is referenced by both the GitHub Security Advisories and VulnCheck.
View original advisory →Microsoft has disclosed details of a new ClickFix variant called TerminalFix that tricks users into executing malicious commands via Windows Terminal or PowerShell. Unlike traditional ClickFix campaigns that use the Windows Run dialog, TerminalFix directs victims to Windows Terminal or PowerShell, increasing the likelihood of executing complex payloads. The campaign uses fake Cloudflare CAPTCHA pages as a social engineering lure. The ultimate payload is a reverse-tunnel backdoor, allowing attackers persistent remote access. This technique leverages legitimate-looking CAPTCHA prompts to bypass user suspicion and security controls. The shift to PowerShell/Terminal increases the capability for attackers to run sophisticated scripts. This represents an evolution of the ClickFix social engineering technique. Organizations using Windows environments are at heightened risk from this campaign.
View original advisory →CVE-2026-15980 describes a critical authentication bypass vulnerability in the MyHome Core plugin for WordPress, affecting all versions up to and including 4.4.5. The flaw stems from missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. Unauthenticated attackers can exploit this to generate activation tokens for unconfirmed user accounts and obtain valid authentication cookies, potentially gaining administrator-level access. Exploitation requires the MyHome theme to be in legacy/WPBakery mode with frontend registration and confirmation email enabled, and the target account must lack the myhome_agent_confirmed user meta flag. This vulnerability poses a significant risk to real estate WordPress sites using this theme. No patch version is explicitly mentioned beyond the affected range of 4.4.5 and below.
View original advisory →A vulnerability identified as CVE-2026-82539 affects TOTOLINK A720R firmware version 4.1.5cu.630_B20250509. The flaw resides in the setMacFilterRules function within the cstecgi.cgi file, specifically in the MAC Filtering component. Manipulation of the 'desc' argument can trigger memory corruption, potentially allowing an attacker to execute arbitrary code or crash the device. The attack vector is remote, requiring no physical access to the target device. A public exploit has already been disclosed and is available for use, increasing the risk of active exploitation. TOTOLINK routers are commonly deployed in home and small business environments, widening the potential attack surface. The vulnerability poses a significant risk to network infrastructure security.
View original advisory →Multiple critical security vulnerabilities have been disclosed in widely-used WordPress plugins and themes including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. The flaws, tracked by Wordfence and Patchstack, can lead to authentication bypass, account takeover, and arbitrary remote code execution. At least one CVE, CVE-2026-76581, carries a near-maximum CVSS score of 9.8. The vulnerabilities span authentication bypass and potentially other critical classes. Successful exploitation could allow attackers to fully compromise affected WordPress sites. Site administrators are urged to apply patches immediately to mitigate risk of site takeover or RCE.
View original advisory →Ten malicious versions of the npm package @7nohe/openapi-react-query-codegen were published by attackers who exploited an exposed npm publishing workflow in the package's CI/CD pipeline. The compromise allowed unauthorized publication of malicious package versions to the npm registry. The article details indicators of compromise (IOCs) associated with the malicious versions and provides recovery steps for affected users and maintainers. This incident highlights the risk of exposed secrets or misconfigured publishing workflows in open source projects. The attack falls under the category of software supply chain compromise, where downstream consumers of the package may have been impacted by installing the malicious versions.
View original advisory →McKesson, a major healthcare and pharmaceutical distribution company, has disclosed a cybersecurity incident involving unauthorized access to third-party applications. The ShinyHunters extortion group has claimed responsibility, alleging they stole 284 million patient data records. The breach involves sensitive patient information, making it one of the largest healthcare data theft incidents. McKesson confirmed unauthorized access occurred but has not yet provided full details on the scope of the breach. ShinyHunters is a well-known threat actor group associated with large-scale data theft and extortion operations targeting high-value organizations. The incident raises significant concerns about third-party application security in the healthcare sector. Regulatory and legal implications are likely given the scale of the alleged data theft and the sensitive nature of patient records.
View original advisory →CVE-2026-15369 affects the Custom User Registration Fields for WooCommerce WordPress plugin in versions up to and including 2.2.3. The vulnerability allows unauthenticated attackers to escalate privileges to Administrator level by manipulating the afreg_select_user_role parameter in the WooCommerce Store API checkout request. The flaw exists because the plugin fails to validate the attacker-controlled role value against the admin-configured allowed role list before passing it to WP_User::add_role(). An attacker can exploit this during the checkout process by submitting a modified JSON body specifying 'administrator' or any other role slug. The exploit is conditional on the 'User Role Selection' setting being enabled in the plugin configuration. The vulnerability resides in the af_reg_checkout_data_to_order_meta_data_block() and af_reg_custom_order_processing_function() functions. No authentication is required to exploit this vulnerability, making it particularly dangerous for affected WordPress/WooCommerce installations.
View original advisory →CVE-2026-82454 describes a critical authentication bypass vulnerability in the Omnivore API (packages/api) affecting Apple Sign-In token verification. The decodeAppleToken function incorrectly trusted the attacker-supplied 'alg' field from the JWT header, passing it directly to jwt.verify() as the allowed algorithm. By setting alg=HS256 and using Apple's publicly available RSA public key as an HMAC secret, an attacker could forge a valid-looking JWT token. The jsonwebtoken v8 library used did not validate key/algorithm compatibility, enabling the bypass. This flaw allowed an attacker to impersonate any Apple-linked Omnivore account without knowing the victim's credentials. The vulnerability was fixed in commit abf53d6. This is a classic JWT algorithm confusion attack, a well-known class of vulnerability in token-based authentication systems.
View original advisory →The rust-iot-platform project, through commit 5df942ab, stores user passwords in plaintext without hashing in the user model. This critical security flaw allows attackers to retrieve plaintext credentials for all accounts by reading API responses from user retrieval and listing routes. The vulnerability exposes all user accounts to credential theft, as no password hashing mechanism is implemented. The affected code is located in the user_biz.rs file within the API source. This issue poses a significant risk to any deployment of the platform, as compromised credentials can lead to full account takeover and lateral movement.
View original advisory →CVE-2026-82461 affects pac4j-oidc versions before 6.5.6, which fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. This critical flaw allows attackers to forge access tokens with administrative roles and pair them with valid ID tokens to bypass authorization checks. Applications relying on pac4j role validation for access control are vulnerable to privilege escalation. The vulnerability resides in the KeycloakRolesAuthorizationGenerator class. A fix was introduced in pac4j version 6.5.6 via a specific commit. Organizations using pac4j with Keycloak integration should upgrade immediately to mitigate the risk of unauthorized administrative access.
View original advisory →BookStack versions before 26.05.4 are affected by a remote code execution vulnerability in the portable ZIP import functionality. Authenticated users with Import Content and Create Books permissions can exploit this by uploading a PHP polyglot file disguised as a book cover image. The attack bypasses image extension validation by embedding a PHP file with a .php filename inside the ZIP archive. Once uploaded, the malicious file is stored in the public web root and can be executed by unauthenticated HTTP requests. This effectively allows privilege escalation from a limited authenticated user to full server-side code execution. The vulnerability has been patched in BookStack version 26.05.4. References include the official BookStack GitHub repository and a specific commit addressing the flaw.
View original advisory →CVE-2026-82455 describes a path traversal vulnerability in RubyGems where symlink resolution during gem extraction is not re-validated for path containment. A pre-existing symlink inside the destination directory that points outside the extraction root can cause extracted files to be written to arbitrary locations outside the intended destination. This breaks the extraction safety boundary and could allow an attacker to write files to sensitive locations on the filesystem. The fix involves resolving the real path of the parent directory before writing and raising a Gem::Package::PathError if the resolved path escapes the destination directory. The vulnerability affects RubyGems versions prior to 4.0.13. A patch has been committed to the ruby/rubygems GitHub repository and a pull request has been merged to address the issue.
View original advisory →CVE-2026-82457 affects su-exec through version 0.3, a utility used to execute programs with different user/group privileges. The vulnerability stems from a failure to validate numeric user and group identifiers parsed with strtol before assigning them to uid_t and gid_t types. This allows integer truncation of out-of-range values to zero, which corresponds to the root user identifier. An attacker can supply a large numeric user or group identifier that truncates to root's UID (0), causing su-exec to execute target programs with full root privileges instead of the intended unprivileged account. This represents a privilege escalation vulnerability that can be exploited by supplying crafted input values. The flaw is particularly concerning in containerized environments where su-exec is commonly used. No patch has been confirmed in the referenced version, and a proof-of-concept has been published on GitHub Gist.
View original advisory →iFlytek astron-agent through version 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint. The endpoint fails to validate workflow ownership, allowing authenticated attackers to enumerate workflow identifiers. Attackers can exploit this to overwrite other tenants' workflows or copy private workflows to read their definitions. This is a multi-tenant data isolation failure that enables cross-tenant data access and manipulation. The vulnerability is classified as an Insecure Direct Object Reference (IDOR) type flaw. It affects the WorkflowService.java component in the console backend toolkit. The issue has been reported via GitHub issues and documented by VulnCheck. No patch beyond version 1.1.1 is indicated in the advisory.
View original advisory →