Overzicht van binnengekomen advisories.
1553 resultaten gevonden
A critical authentication bypass vulnerability tracked as CVE-2026-82329 has been discovered in JFrog Artifactory and is being actively exploited in the wild. Attackers are leveraging the flaw to forge tokens that grant full administrative access to affected Artifactory instances. The vulnerability allows threat actors to bypass authentication controls entirely, posing a severe risk to organizations using JFrog Artifactory for software artifact management. Successful exploitation could allow attackers to manipulate build artifacts, inject malicious packages into the software supply chain, or exfiltrate sensitive data. Organizations are urged to apply patches immediately and audit existing admin tokens for signs of unauthorized creation.
Bekijk origineel advisory →Manifold Security has disclosed eight security flaws across seven command-line AI coding agents, including Claude, Codex, and Cursor. The vulnerabilities allow a malicious Git configuration file within a repository to name a command that the AI agent will execute on the developer's machine. The execution occurs as the user, bypassing the agent's sandbox and without triggering any approval prompt. Exploitation requires only that the malicious repository be cloned or opened by the developer. At the time of publication, four of the eight flaws remained unpatched. This class of vulnerability represents a supply chain and social engineering risk, as developers may unknowingly run attacker-controlled code simply by interacting with a repository. The attack surface is broad, affecting multiple widely-used AI-assisted development tools.
Bekijk origineel advisory →Hackers executed a Border Gateway Protocol (BGP) hijack to divert traffic intended for Softaculous, the distributor of the Virtualizor control panel software. The diverted traffic was used to deliver a malicious Virtualizor package to targeted installations. At least one hosting provider confirmed that 5 out of 34 checked Virtualizor hypervisors were compromised at the root level. The attack established persistent root access on affected systems. The incident window began approximately August 28 at 20:57. This represents a sophisticated supply chain attack combining network-level manipulation with software update poisoning. The attack targeted server virtualization infrastructure, potentially exposing all virtual machines hosted on compromised hypervisors. The use of BGP hijacking indicates a highly capable threat actor with access to routing infrastructure.
Bekijk origineel advisory →Dropbox is warning users that an unauthorized party accessed accounts by exploiting a flaw in Lenovo's email verification process. Attackers used the flaw to register fraudulent Lenovo IDs, which were then leveraged to gain unauthorized access to Dropbox accounts. The vulnerability resided in Lenovo's identity and authentication pipeline, enabling account takeover without the victim's credentials. This incident highlights risks associated with third-party identity provider integrations and cross-platform authentication dependencies. Affected Dropbox users are being notified of the breach. The attack vector involves abusing the trust relationship between Dropbox and Lenovo's verification system. No specific CVE has been mentioned in the article content provided.
Bekijk origineel advisory →SonicWall has released security updates addressing two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series VPN appliances. The flaws were discovered internally by SonicWall researchers William Perry and Adam Babis. One of the vulnerabilities, CVE-2026-83548, carries a maximum CVSS score of 10.0 and is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability. The two vulnerabilities may form an attack chain, potentially allowing attackers to escalate their access or impact. Active exploitation in the wild has been confirmed, classifying these as zero-day vulnerabilities. SonicWall has urged users to apply the released patches immediately to mitigate risk.
Bekijk origineel advisory →Unit 42 investigated a real-world cyberattack in which an attacker leveraged autonomous AI agents to breach an enterprise network within hours. The incident highlights the emerging threat of agentic AI being weaponized for offensive cyber operations. The attacker used AI to accelerate and automate various stages of the attack lifecycle. This case represents a significant evolution in attack sophistication and speed. The article aims to help defenders understand agentic attack techniques and how to mitigate them. Organizations are urged to adapt their defenses to account for AI-driven threat actors.
Bekijk origineel advisory →SonicWall has patched two zero-day vulnerabilities in its SMA1000 Appliance that were actively exploited in the wild. The first vulnerability is a pre-authentication Server-Side Request Forgery (SSRF) in the Work Place interface, allowing unauthenticated remote attackers to perform unauthorized actions. The second vulnerability enables post-authentication remote code execution, allowing attackers with valid credentials to execute arbitrary code remotely. Both vulnerabilities have been confirmed as actively exploited zero-days. The Dutch NCSC (National Cyber Security Centre) urges organizations to follow SonicWall's advisory and apply the available patches immediately. The combination of an unauthenticated SSRF and an authenticated RCE poses a significant risk to organizations using this appliance.
Bekijk origineel advisory →Two vulnerabilities in GeoNetwork, the open-source geospatial metadata catalog, can be chained to achieve unauthenticated remote code execution (RCE). The flaws affect many government and agency geoportal backends that rely on GeoNetwork. Fixes were shipped in versions 4.4.12 and 4.2.17 on July 8, 2026, with full vulnerability details published on August 31, 2026. GeoNetwork originated at the United Nations Food and Agriculture Organization and is widely used in public sector infrastructure. The chained attack requires no authentication, making it particularly dangerous for exposed government systems. Organizations running GeoNetwork are urged to upgrade immediately to the patched versions.
Bekijk origineel advisory →Forescout Research - Vedere Labs demonstrated the use of Anthropic's Claude AI to port a pre-authentication remote code execution exploit from one WAGO programmable logic controller (PLC) model to another. The exploit targets CVE-2021-31886, a stack-based buffer overflow vulnerability in the Nucleus FTP server's handling of the USER command. Researchers successfully executed attacker-supplied ARM shellcode on live hardware, showcasing the potential of AI tools to accelerate exploit development and porting. This research highlights significant risks to industrial control systems and operational technology environments. The ability to leverage AI to adapt existing exploits lowers the barrier for attackers targeting critical infrastructure. WAGO PLCs are commonly used in industrial automation and critical infrastructure settings, amplifying the severity of this finding.
Bekijk origineel advisory →Threat actors are actively exploiting a critical security vulnerability in Sangoma Switchvox, an enterprise VoIP platform. The vulnerability, tracked as CVE-2026-9586, carries a CVSS score of 9.3 and affects Sangoma Switchvox SMB Edition 8.3 (build 104997). The flaw is an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary code without any credentials. Attackers are leveraging this vulnerability to deploy reverse shells on compromised systems. The unauthenticated nature of the exploit makes it particularly dangerous as no prior access or credentials are required. The critical severity and active exploitation make this a high-priority patching concern for organizations using the affected VoIP platform.
Bekijk origineel advisory →SonicWall has issued a warning to customers regarding two newly discovered zero-day vulnerabilities affecting its SMA1000 series appliances. Threat actors are actively chaining these two flaws together to achieve remote code execution. The vulnerabilities are being exploited in the wild, making them a critical and immediate threat. SonicWall has urged customers to apply patches or mitigations as soon as possible. The SMA1000 product line is used for secure remote access in enterprise environments, making it a high-value target. The chaining of two zero-days suggests a sophisticated threat actor. No CVE identifiers were specified in the available content. Organizations using SMA1000 devices should treat this as a high-priority incident response situation.
Bekijk origineel advisory →Kludex Starlette contains an HTTP request/response smuggling vulnerability tracked as CVE-2026-48710. The flaw allows attackers to inject paths into the host part of a request, prepending the actual path and potentially causing authentication bypass when authentication logic depends on the reconstructed URL path. This vulnerability can be chained with CVE-2026-42271 to amplify impact. It affects an open-source component that may be used by a wide range of products and implementations. CISA has catalogued this vulnerability under BOD 26-04, which prioritizes security updates based on risk. A security advisory has been published on GitHub by Kludex. Organizations using Starlette-based applications should apply patches promptly. The vulnerability is rated High criticality.
Bekijk origineel advisory →GitLab's Threat Research Group discovered a critical sandbox escape vulnerability (CVSS 3.1: 10.0) in vm2, a widely used Node.js sandboxing library with ~1.25 million weekly npm downloads. The flaw allows remote code execution when using the default configuration from vm2's own README, specifically when require.external is enabled with root set to './'. The attack works by requiring vm2's own package from within the sandbox, which loads through Node's real unsandboxed require() due to the default context: 'host' setting, then spinning up a second unrestricted NodeVM with access to child_process. The vulnerability was fixed in vm2 version 3.11.7, but the fix is narrow and broader configuration risks remain. Users relying on require.external with overly broad require.root settings remain vulnerable even after patching. GitLab recommends restricting require.root strictly, setting context: 'sandbox', and for truly untrusted code isolation, using containers or separate processes instead of vm2.
Bekijk origineel advisory →SonicWall SMA1000 Appliances contain a server-side request forgery (SSRF) vulnerability tracked as CVE-2026-83548. The flaw allows remote unauthenticated attackers to gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA has flagged this vulnerability under BOD 26-04, which prioritizes security updates based on risk. SonicWall has published an advisory via its PSIRT portal. The vulnerability is rated high severity given its unauthenticated remote exploitation potential. Federal agencies and organizations using SMA1000 appliances are urged to apply patches promptly. CISA also references forensic triage requirements as part of the BOD 26-04 implementation guidance. The NVD entry provides additional technical details on the vulnerability.
Bekijk origineel advisory →Sangoma Switchvox contains a critical SQL injection vulnerability (CVE-2026-9586) that allows unauthenticated remote attackers to execute arbitrary SQL statements against the backend PostgreSQL database. Exploitation requires only a single crafted request, enabling database manipulation and remote code execution. The vulnerability is unauthenticated, significantly raising its severity and risk profile. CISA has listed this vulnerability under BOD 26-04, mandating prioritized patching for federal agencies. A patch is available in Switchvox version 8.4.0.2, released July 14, 2026. Organizations using Sangoma Switchvox should apply the update immediately. CISA also requires forensic triage for affected systems per BOD 26-04 implementation guidance.
Bekijk origineel advisory →JFrog Artifactory contains a critical improper authentication vulnerability (CVE-2026-82329) that allows unauthenticated attackers with network access to gain administrative privileges under default configuration. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog and is subject to BOD 26-04 remediation requirements. JFrog has published security advisories and release notes for self-managed Artifactory instances. Organizations are urged to apply patches immediately as the flaw requires no authentication to exploit. The vulnerability poses significant risk to software development pipelines and artifact repositories. CISA has also issued forensic triage guidance as part of its implementation guidance for BOD 26-04. The severity is rated High given the default-configuration exploitability and potential for full administrative compromise.
Bekijk origineel advisory →BerriAI LiteLLM contains an improper authentication vulnerability affecting the MCP Streamable HTTP endpoint. An unauthenticated attacker can exploit this flaw to establish an authenticated MCP session using an arbitrary Bearer token, effectively bypassing authentication controls. The vulnerability has been assigned CVE-2026-59822 and is tracked by CISA under BOD 26-04, which prioritizes security updates based on risk. The issue is documented in a GitHub security advisory (GHSA-7488-6r32-c95q) and in the NVD. CISA has classified this as high severity, requiring forensic triage per BOD 26-04 implementation guidance. Organizations using LiteLLM should apply available patches immediately to prevent unauthorized access to MCP sessions.
Bekijk origineel advisory →SonicWall SMA1000 appliances contain an OS command injection vulnerability tracked as CVE-2026-83549. The flaw allows a remote authenticated attacker with administrator privileges to execute arbitrary OS commands, leading to remote code execution. The vulnerability has been flagged by CISA and is subject to BOD 26-04, which prioritizes security updates based on risk. CISA has also issued forensic triage requirements as part of its implementation guidance. SonicWall's PSIRT has published an advisory under SNWLID-2026-0016. The vulnerability is also documented in the NVD. Organizations using SonicWall SMA1000 appliances are urged to apply patches immediately. The criticality level is rated High.
Bekijk origineel advisory →Kestra OSS contains a critical OS command injection vulnerability tracked as CVE-2026-49869. The flaw allows unauthenticated remote attackers to create and execute arbitrary workflows without any credentials. This represents a significant security risk as it requires no authentication to exploit. The vulnerability affects an open-source component that may be used by multiple products. CISA has flagged this under BOD 26-04, which prioritizes security updates based on risk. The advisory references the GitHub Security Advisory GHSA-5vc5-wxxq-3fjx for additional technical details. Organizations using Kestra OSS are urged to apply security updates promptly. Forensic triage requirements are also outlined under BOD 26-04 implementation guidance.
Bekijk origineel advisory →Cisco's IOS XR Software engineering team conducted an internal security review that uncovered multiple vulnerabilities, including those tracked under CVE-2026-20279. The vulnerabilities involve improper access control issues classified under CWE-284. Cisco has released software hardening updates to address these internally discovered flaws. The advisory was published on the National Vulnerability Database (NVD) and Cisco's own security advisory portal. No external discovery or active exploitation is mentioned, suggesting this is a proactive disclosure. The affected product is Cisco IOS XR Software, widely used in carrier-grade and enterprise network infrastructure. Organizations running IOS XR are advised to review and apply the relevant hardening releases.
Bekijk origineel advisory →