1553 resultaten gevonden

  • critical · nvd.nist.gov

    Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.

    Craft CMS versions before 5.10.11 contain a critical authentication bypass vulnerability where the admin flag is not properly validated during user registration. This flaw allows the admin flag to persist from deactivated admin accounts. An attacker can exploit this by registering a new account using a deactivated administrator's email address, thereby inheriting full administrator privileges. The attack is feasible when the target instance has public registration enabled and email verification disabled. This represents a significant privilege escalation risk for affected deployments. The vulnerability has been assigned CVE-2026-84795 and has been patched in version 5.10.11. Organizations using Craft CMS with public registration should prioritize upgrading immediately.

    Bekijk origineel advisory →
  • critical · nvd.nist.gov

    Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

    CVE-2026-84353 is a critical use-after-free vulnerability in the Shared Tab Groups feature of Google Chrome on Android. Versions prior to 152.0.7977.75 are affected. A remote attacker can exploit this vulnerability through social engineering, tricking a user into visiting a crafted HTML page. Successful exploitation allows arbitrary code execution outside the browser sandbox, representing a full sandbox escape. The vulnerability has been assigned a Critical severity rating by the Chromium security team. Users are urged to update to Chrome 152.0.7977.75 or later on Android immediately.

    Bekijk origineel advisory →
  • critical · nvd.nist.gov

    A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.

    A critical vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches allows an unauthenticated remote attacker to execute arbitrary code with root privileges. The flaw exists due to TCP ports 43210 and 43211 being accessible by default in the Layer 3 virtual routing and forwarding (VRF) context. An attacker can connect to these open ports and send specially crafted input to trigger code execution at the root level. Additionally, successful exploitation can crash the S1HAL process, potentially causing the affected device to reload and resulting in a denial of service condition. No authentication is required to exploit this vulnerability, significantly lowering the barrier for attackers. The vulnerability is tracked as CVE-2026-20212 and is currently awaiting full analysis by NVD. Cisco has published a security advisory with further details and remediation guidance.

    Bekijk origineel advisory →
  • high · nvd.nist.gov

    ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters.

    ION-DTN versions prior to 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function. Unauthenticated remote attackers can exploit this by sending truncated SDNV values via UDP datagrams to the LTP link service input port. The vulnerability can trigger memory reads up to nine bytes past buffer boundaries and cause byte counter underflows. No authentication is required to exploit this flaw, making it accessible to any network-adjacent or remote attacker. The vulnerability has been patched in ION-DTN version 4.2.0. ION-DTN is NASA JPL's open-source implementation of the Delay-Tolerant Networking (DTN) protocol, commonly used in space communications infrastructure. A fix commit is available on GitHub along with a security advisory via GHSA-85pw-28vw-2jf7.

    Bekijk origineel advisory →
  • high · nvd.nist.gov

    BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.

    BookStack versions before 26.05.4 contain a stored cross-site scripting (XSS) vulnerability in the drawing upload endpoint. The endpoint accepts unvalidated base64 content and stores it without content inspection, allowing SVG files with embedded scripts to be uploaded. Attackers with editor-level permissions can exploit this by uploading malicious SVG files that execute scripts in administrator browsers when accessed via the image gallery API. The vulnerability is compounded by the absence of content-type validation and CSP headers. The issue has been patched in BookStack version 26.05.4. A fix was committed to the repository and a release was tagged accordingly. Organizations using affected versions should upgrade immediately to mitigate risk of privilege escalation or session hijacking via stored XSS.

    Bekijk origineel advisory →
  • high · nvd.nist.gov

    The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.

    CVE-2026-78408 is a privilege escalation vulnerability in the util-linux nsenter utility affecting its --join-cgroup option. When nsenter opens the target cgroup.procs file as root, it leaves the file descriptor open across namespace and credential changes and across execve() calls. The Linux kernel uses the credentials from the original open to authorize later cgroup migrations, meaning a program in an attacker-controlled container can inherit root-level cgroup manipulation capabilities. After a privileged operator invokes --join-cgroup against a malicious target, an unprivileged user inside that environment can migrate arbitrary host processes between cgroups and terminate unrelated root processes. This represents a container escape/host process interference scenario requiring no additional privileges from the attacker beyond control of the target container. The vulnerability is tracked by Red Hat and has an associated GitHub security advisory in the util-linux repository.

    Bekijk origineel advisory →
  • high · nvd.nist.gov

    APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.

    APITable versions through 1.13.0-beta.1 expose an internal organization loadOrSearch endpoint without any authentication requirement. Unauthenticated attackers can exploit this vulnerability to retrieve sensitive information including member names, email addresses, and team hierarchy structures. The attack vector requires only a space identifier, which can be obtained from publicly shared links or public templates. This allows attackers to enumerate the complete member directory of any workspace. The vulnerability resides in the InternalOrganizationController and is related to missing authentication checks in the ResourceInterceptor. The flaw represents a significant information disclosure risk for organizations using APITable. No authentication or special privileges are required to exploit this issue.

    Bekijk origineel advisory →
  • medium · bleepingcomputer.com

    Aesto Health says data breach affects over 9.5 million patients

    Aesto LLC, operating as Aesto Health, disclosed a significant data breach affecting more than 9.5 million individuals. The breach was discovered recently and reported publicly. The incident represents one of the larger healthcare data breaches in terms of patient count. Healthcare data breaches are particularly sensitive due to the nature of personal and medical information involved. The scale of the breach places it among the more impactful incidents in the healthcare sector. Further details about the nature of the compromised data and the attack vector were not fully elaborated in the article excerpt. Regulatory notifications and patient advisories are likely underway given the magnitude of the breach.

    Bekijk origineel advisory →
  • medium · bleepingcomputer.com

    Critical Langflow flaw exploited to steal OpenAI and AWS keys

    Threat actors are actively exploiting a critical unauthenticated remote code execution vulnerability tracked as CVE-2026-0768 in Langflow, an open-source framework used for building AI applications. The exploitation allows attackers to steal sensitive credentials, tokens, and API keys including those for OpenAI and AWS. The vulnerability requires no authentication, making it particularly dangerous for exposed instances. Langflow is widely used in the AI development community, increasing the potential attack surface. Organizations using Langflow are urged to patch immediately and rotate any exposed credentials. The active exploitation status elevates the severity of this vulnerability significantly.

    Bekijk origineel advisory →
  • medium · thehackernews.com

    Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

    A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329 with a CVSS score of 9.8, is being actively exploited by threat actors just days after public disclosure. The flaw allows attackers to bypass authentication mechanisms present in default configurations of Artifactory, potentially granting them administrative access to the platform. Security researchers at watchTowr flagged the active exploitation in the wild. The vulnerability's severity is compounded by the widespread use of JFrog Artifactory in enterprise software development pipelines for artifact and package management. Organizations are urged to apply the available patch immediately to mitigate the risk of administrative token minting by unauthorized actors.

    Bekijk origineel advisory →
  • medium · thehackernews.com

    Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

    A financially motivated threat actor known as Breeze Comet (formerly UNC5669) has been targeting Brazilian financial services, retail, and e-commerce organizations since 2024. The group specializes in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. Google Threat Intelligence Group (GTIG) and Mandiant have been tracking this adversary and provided detailed descriptions of their tactics. The threat actor has executed hundreds of fraudulent transactions through Brazilian payment infrastructure. The campaign highlights ongoing risks to the Brazilian financial sector from sophisticated, targeted cybercriminal operations.

    Bekijk origineel advisory →
  • medium · bleepingcomputer.com

    Hackers push malicious Virtualizor update in BGP hijacking attack

    Threat actors conducted a BGP hijacking attack targeting the update infrastructure of Virtualizor, a popular VPS management software. By hijacking BGP routing, attackers redirected update requests intended for legitimate Virtualizor servers to malicious servers under their control. This allowed them to push trojanized or malicious software updates to unsuspecting Virtualizor users. The attack represents a sophisticated supply chain compromise leveraging BGP routing manipulation, a technique that can affect large numbers of users simultaneously. BGP hijacking at this level requires significant resources or access to BGP routing infrastructure. Users of Virtualizor who updated their software during the attack window may have received and installed malicious code. The incident highlights the risks of software update mechanisms that lack strong cryptographic verification and the dangers of BGP as an inherently trust-based protocol. Organizations using Virtualizor should audit their systems for signs of compromise and verify the integrity of installed software.

    Bekijk origineel advisory →
  • medium · thehackernews.com

    13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

    Cybersecurity researchers discovered 13 malicious Composer theme packages on Packagist, the PHP package repository, designed to target unpatched iOS devices. The packages inject malicious JavaScript into Vietnamese movie and comic streaming sites that install the libraries. The injected code performs two main operations against site visitors: mobile ad-fraud and gambling redirects, while also deploying spyware targeting unpatched iPhones. The ultimate goal appears to be stealing cryptocurrency wallet seeds from compromised iOS devices. This represents a supply chain attack leveraging trusted package repositories to reach end users through compromised websites.

    Bekijk origineel advisory →
  • medium · thehackernews.com

    Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

    The Iranian threat group Nimbus Manticore has been linked to two newly discovered malware families targeting Linux and macOS systems. The group is using a social engineering tactic where they pose as recruiters and deliver malicious coding tests to victims. The malware consists of cross-platform remote access trojans (RATs) built with Node.js and JavaScript, enabling them to infect multiple operating systems. This campaign represents an evolution of the group's toolset and an expansion of its targeting scope beyond Windows systems. Russian cybersecurity firm Kaspersky is actively tracking this threat actor and their new malware families.

    Bekijk origineel advisory →
  • medium · bleepingcomputer.com

    Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

    Nearly 22,000 Microsoft Exchange servers exposed to the internet remain unpatched against a high-severity authentication bypass vulnerability. This flaw allows attackers to hijack all user mailboxes on affected servers. The vulnerability is classified as high-severity and represents a significant risk to organizations still running unpatched versions. The large number of exposed servers indicates widespread failure to apply available security updates. Successful exploitation could lead to full compromise of email communications, data exfiltration, and further lateral movement within affected organizations.

    Bekijk origineel advisory →
  • medium · cisa.gov

    Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix

    CISA published an advisory regarding a denial-of-service vulnerability (CVE-2021-42260) affecting multiple Rockwell Automation programmable logic controllers including ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, Compact GuardLogix 5380, and CompactLogix 5480. The vulnerability is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop) and can be triggered by sending corrupt crafted data to the affected devices. Successful exploitation can cause a major nonrecoverable fault (MNRF), requiring a program download for safety controllers or a stage 2 reset for non-safety controllers. The CVSS v3.1 base score is 7.5 (HIGH) and CVSS v4.0 base score is 8.7 (HIGH), with the attack vector being network-based, requiring no authentication or user interaction. Affected firmware versions are below 34.015, 35.014, 36.013, and 37.011 across the impacted product lines. Rockwell Automation reported the vulnerability to CISA and recommends updating to the patched firmware versions. The advisory affects critical manufacturing infrastructure deployed worldwide. No known public exploitation has been reported at the time of publication.

    Bekijk origineel advisory →
  • medium · cisa.gov

    Rockwell Automation Historian ME

    CISA has published an advisory for two vulnerabilities affecting Rockwell Automation Historian ME (FactoryTalk Historian Machine Edition) in Series B 5.202 and Series C 7.101. CVE-2025-12768 is a high-severity out-of-bounds write vulnerability (CVSS 3.1: 8.0) that allows a low-privileged, network-adjacent attacker to achieve remote code execution. CVE-2026-12661 is a medium-severity stack-based buffer overflow (CVSS 3.1: 4.5) that enables an authenticated adjacent attacker to crash the device via crafted web requests, causing denial of service. Affected critical infrastructure sectors include Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, and Water and Wastewater Systems. No public exploitation has been reported. Mitigations include following Rockwell Automation security best practices, minimizing network exposure, using firewalls, and employing VPNs for remote access. Rockwell Automation self-reported these vulnerabilities to CISA.

    Bekijk origineel advisory →
  • medium · cisa.gov

    Rockwell Automation FactoryTalk Activation Manager

    A privilege escalation vulnerability (CVE-2026-16675) exists in Rockwell Automation FactoryTalk Activation Manager V5.02 and below. The flaw stems from custom installer actions that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated local attacker can hijack these console windows to obtain a SYSTEM-level command prompt, granting full access to files, processes, and system resources. The vulnerability carries a CVSS v3.1 score of 7.8 (HIGH) and CVSS v4.0 score of 8.5 (HIGH). Affected sectors include Critical Manufacturing deployed worldwide. Rockwell Automation recommends updating to V5.03 to remediate the issue. No known public exploitation has been reported to CISA at this time.

    Bekijk origineel advisory →
  • medium · cisa.gov

    Rockwell Automation Logix Platform

    A denial-of-service vulnerability (CVE-2026-9637) exists in multiple Rockwell Automation Logix Platform products due to improper validation of input length during CIP message processing. Affected products include ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 across multiple firmware versions up to V36. Exploitation can cause a major nonrecoverable fault (MNRF), requiring a power cycle to restore operation. The vulnerability is remotely exploitable with no authentication or user interaction required, scoring 7.5 (HIGH) on CVSS v3.1 and 8.7 (HIGH) on CVSS v4.0. Rockwell Automation reported the issue to CISA and has released patched firmware versions (V34.015, V35.014, V36.013, V37.011). Organizations unable to patch are advised to follow Rockwell Automation security best practices and isolate control systems from internet exposure. No known public exploitation has been reported at the time of publication.

    Bekijk origineel advisory →
  • medium · cisa.gov

    Rockwell Automation RSLinx Classic

    CISA published an ICS advisory detailing four denial-of-service vulnerabilities in Rockwell Automation RSLinx Classic versions 4.50 and earlier. The vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) can be exploited via crafted CIP packets, causing the RSLinx Classic service to crash and require a restart. Root causes include integer overflow, integer underflow, insufficient data length validation, and classic buffer overflow. CVSS v3.1 scores range from 7.5 to 8.6 (HIGH), while CVSS v4.0 scores range from 8.7 to 9.2 (HIGH to CRITICAL). The fix is available in RSLinx Classic version 4.60. These vulnerabilities affect critical manufacturing sectors worldwide. No known public exploitation has been reported at the time of publication. Rockwell Automation self-reported the vulnerabilities to CISA.

    Bekijk origineel advisory →