Overzicht van binnengekomen advisories.
1553 resultaten gevonden
Two recently patched security vulnerabilities in PaperCut NG and MF print management software are being actively exploited in data theft attacks. The vulnerabilities were initially exploited as zero-days before patches were released. Attackers are leveraging these flaws to steal data from affected organizations. PaperCut is widely used print management software deployed across enterprises and educational institutions. The exploitation occurred shortly after patches were made available, indicating rapid weaponization by threat actors. Organizations using PaperCut NG or MF are strongly advised to apply the available patches immediately. The active exploitation underscores the risk of delayed patching for critical software vulnerabilities.
Bekijk origineel advisory →Threat actors are actively exploiting two critical vulnerabilities in Langflow and Ruby on Rails, as reported by VulnCheck. CVE-2026-0768 (CVSS 9.8) affects Langflow and allows attackers to execute arbitrary Python code as root due to improper input validation. CVE-2026-66066 affects Ruby on Rails. The exploitation activity includes credential-probing and command-and-control (C2) operations. Both vulnerabilities are rated critical and are being leveraged in active attack campaigns. Organizations using these platforms are urged to apply patches immediately. The findings highlight the ongoing risk of unpatched web application frameworks being weaponized by threat actors.
Bekijk origineel advisory →This article analyzes a Guildma (also known as Astaroth) malware infection originating from a Brazilian Portuguese phishing email. Guildma is a sophisticated banking trojan primarily targeting Brazilian users and organizations. The malware is typically distributed via spam email campaigns written in Brazilian Portuguese to target local victims. Astaroth/Guildma is known for its use of living-off-the-land binaries (LOLBins) to evade detection and execute its payload. The infection chain often involves malicious attachments or links leading to multi-stage loaders. This malware is capable of credential theft, keylogging, and intercepting banking transactions. The article was published on September 1st and appears on the SANS Internet Storm Center diary.
Bekijk origineel advisory →CVE-2026-61774 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which can be exploited by an attacker to achieve remote code execution, data tampering, and information disclosure. The vulnerability is tracked under NVIDIA's product security advisory and listed in the National Vulnerability Database. No specific exploitation in the wild has been mentioned, but the potential impact is significant given the range of consequences. NVIDIA has published a security advisory on GitHub. Users of NVIDIA Megatron Bridge are advised to review the advisory and apply any available mitigations or patches promptly.
Bekijk origineel advisory →CVE-2026-84121 is a high-severity vulnerability in Firefox involving a use-after-free condition in the DOM Security component that enables sandbox escape. The flaw allows an attacker to potentially break out of the browser sandbox, which could lead to arbitrary code execution or privilege escalation. Mozilla has addressed the vulnerability in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Multiple Mozilla Security Advisories (MFSA2026-82 through MFSA2026-85) have been published in relation to this issue. The vulnerability is tracked in Mozilla's Bugzilla under bug ID 2059018. Users of affected Firefox versions are strongly urged to update immediately. The sandbox escape nature of the bug makes it particularly critical as it bypasses a key security boundary in the browser.
Bekijk origineel advisory →LibreNMS versions prior to 26.5.0 contain a remote code execution vulnerability in the AboutController component. The snmpget configuration parameter is passed directly to shell_exec() without proper sanitization or validation. An authenticated administrator can exploit this by modifying the snmpget configuration to reference a malicious executable. Code execution is then triggered by simply accessing the /about endpoint. The vulnerability requires administrator-level authentication, limiting the attack surface but not eliminating the risk. Fixes are available in LibreNMS version 26.5.0 and later. The issue is documented across NVD, GitHub Security Advisories, and VulnCheck.
Bekijk origineel advisory →CVE-2026-61774 affects NVIDIA Megatron Bridge, a component likely related to NVIDIA's AI/ML infrastructure tooling. The vulnerability involves deserialization of untrusted data, a well-known and dangerous vulnerability class. A successful exploit could allow an attacker to achieve remote code execution, tamper with data, or disclose sensitive information. The vulnerability is currently undergoing analysis on the NVD. NVIDIA has published a security advisory referencing this CVE in their product-security GitHub repository. No patch or workaround details are included in the available content. The severity is rated High based on the potential impact of code execution and data compromise. Organizations using NVIDIA Megatron Bridge should monitor for updates from NVIDIA and apply patches as soon as they become available.
Bekijk origineel advisory →CVE-2026-61771 affects NVIDIA Megatron Bridge, a component related to NVIDIA's AI and deep learning infrastructure. The vulnerability involves deserialization of untrusted data, a class of vulnerability that can be particularly severe. A successful exploit could lead to remote code execution, data tampering, and information disclosure. This type of deserialization flaw typically allows attackers to craft malicious serialized objects that, when processed by the target application, execute arbitrary code. The vulnerability is currently undergoing analysis by NVD. NVIDIA has published a security advisory on their GitHub product-security repository. Given the potential for code execution and data tampering, this is rated as high severity.
Bekijk origineel advisory →CVE-2026-61779 is a deserialization of untrusted data vulnerability found in NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and cause information disclosure. The vulnerability is currently undergoing analysis on the NVD. NVIDIA has published a security advisory on their GitHub product-security repository. The flaw represents a high-severity risk given the potential for full code execution on affected systems. Organizations using NVIDIA Megatron Bridge should monitor for patches and apply mitigations as soon as they become available. The CVE record is also tracked on the official CVE.org portal.
Bekijk origineel advisory →CVE-2026-61769 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, data tampering, and information disclosure. The vulnerability is currently undergoing analysis by NVD. NVIDIA has published a security advisory via their product-security GitHub repository. The flaw is classified as high criticality given the potential impact of code execution and data compromise. No additional technical details or proof-of-concept code are currently referenced. Users of NVIDIA Megatron Bridge should monitor NVIDIA's security advisories for patches and mitigations.
Bekijk origineel advisory →A critical vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer (AFC). An unauthenticated remote attacker can exploit this flaw to gain administrative access to vulnerable AFC hosts. Successful exploitation allows arbitrary command execution as a privileged user on the underlying operating system. This leads to complete system compromise without requiring any credentials. The vulnerability is tracked as CVE-2026-76658 and is currently awaiting full analysis by NVD. HPE has published a security bulletin with remediation guidance. The severity is rated High given the unauthenticated remote exploitation vector and full system compromise potential.
Bekijk origineel advisory →A cleartext storage vulnerability exists in the @step and @remote decorator pipeline components of the Amazon SageMaker Python SDK prior to versions v3.11.0 and v2.256.0. An authenticated remote user can extract an HMAC signing key from SageMaker DescribePipeline API responses due to the key being stored in plaintext. The exposed key allows an attacker to forge valid integrity signatures for specially crafted function payloads. This forgery enables code execution within another user's pipeline execution context inside the same AWS account. The vulnerability represents a significant lateral movement and privilege escalation risk within shared AWS environments. Fixes have been released in SageMaker Python SDK v2.256.0 and v3.11.0. AWS has published a security bulletin and GitHub advisory addressing the issue.
Bekijk origineel advisory →CVE-2026-61762 is a high-severity vulnerability identified in NVIDIA Megatron Bridge involving deserialization of untrusted data. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with sensitive data, and disclose confidential information. The vulnerability was published via the National Vulnerability Database (NVD) and is referenced in NVIDIA's product security advisories. Deserialization vulnerabilities are particularly dangerous as they can allow attackers to execute arbitrary code on the affected system. NVIDIA has acknowledged the issue and linked it to their official product security repository. Organizations using NVIDIA Megatron Bridge should review the advisory and apply any available mitigations or patches promptly. The potential impact spans code execution, data integrity, and confidentiality, making this a critical concern for affected deployments.
Bekijk origineel advisory →Memos versions 0.26.0 through 0.30.0 contain a vulnerability where refresh tokens are not invalidated when a user changes their password. This allows an attacker who has obtained a refresh token to continue generating valid access tokens indefinitely via the RefreshToken RPC, effectively bypassing the security intent of a password change. The vulnerability is classified as Insufficient Session Expiration. An attacker maintaining a stolen refresh token can rotate it perpetually, preserving unauthorized account access even after the legitimate user has updated their credentials. The issue is documented in the Memos authenticator and user service source files. A fix requires implementing token revocation logic tied to password change events.
Bekijk origineel advisory →A path traversal vulnerability exists in Next.js versions 13.4.0 through 15.5.23 and 16.x before 16.3.3 affecting Windows-hosted servers. The framework fails to consistently escape backslashes in route segments when constructing incremental-cache paths. Attackers can supply encoded Windows path separators via remote requests to traverse outside the intended cache root directory. This exposure can leak private build data, including the server-reference-manifest encryption key. Disclosure of this encryption key can lead to remote code execution on the affected application. The vulnerability affects applications using Pages Router or App Router without Cache Components on Windows. Affected files include escape-path-delimiters.ts and file-system-cache.ts. Fixes are available in versions 15.5.24 and 16.3.3.
Bekijk origineel advisory →ModelScope, an AI model repository framework, uses PyYAML's unsafe yaml.Loader to parse model configuration files. This allows arbitrary code execution through Python object construction tags embedded in YAML files. Attackers can craft malicious model repositories containing poisoned configuration files that execute arbitrary code when loaded by unsuspecting users. The vulnerability affects ModelScope through version 1.40.0 and has been confirmed in multiple source files including voice.py and configuration_mplug.py. This represents a significant supply chain risk as users downloading and loading models from repositories could unknowingly execute malicious code. The issue is a classic unsafe deserialization vulnerability where yaml.Loader should be replaced with yaml.SafeLoader. Users and organizations relying on ModelScope for AI/ML workflows are advised to update immediately and audit any model configurations loaded from untrusted sources.
Bekijk origineel advisory →A path traversal vulnerability exists in Laravel Excel (Maatwebsite/Laravel-Excel) versions 3.1.8 through 3.1.69 in the Disk::copy() method within src/Files/Disk.php. The method resolves caller-controlled destination paths using realpath() against the process working directory rather than the configured Flysystem filesystem disk, bypassing path confinement. If the resolved path points to an existing writable file, the method opens it with fopen() in rb+ mode and overwrites it using stream_copy_to_stream(). This allows attackers who control export destination paths to overwrite arbitrary files on the server. The rb+ mode results in non-truncating overwrites, leaving trailing bytes when the new content is shorter. Overwriting executable PHP files can result in remote code execution. The vulnerability is exploitable via Excel::store(), $export->store(), or storeExcel() methods. The issue has been patched in version 3.1.70.
Bekijk origineel advisory →CVE-2026-61760 is a high-severity vulnerability affecting NVIDIA Megatron Bridge, a component likely related to NVIDIA's AI/ML infrastructure. The flaw involves deserialization of untrusted data, a well-known attack vector that can allow attackers to inject malicious payloads during data processing. A successful exploit could result in remote code execution, data tampering, and information disclosure. The vulnerability was published on NVD and references an NVIDIA product security advisory on GitHub. Deserialization vulnerabilities are particularly dangerous as they can be exploited without authentication in some configurations. Organizations using NVIDIA Megatron Bridge in AI training or inference pipelines should apply available patches immediately. The breadth of potential impact—code execution, data integrity, and confidentiality—classifies this as a critical risk for affected deployments.
Bekijk origineel advisory →A CRLF injection vulnerability exists in the Predis PHP Redis/Valkey client library affecting versions 3.0.0-RC1 through 3.3.0. The flaw resides in pipeline handling on aggregate cluster and replication connections, where AbstractAggregateConnection::write() incorrectly reparses serialized RESP buffers using explode('\r\n') instead of respecting RESP length prefixes. Attacker-controlled keys or values containing CRLF sequences can be interpreted as additional commands via Command::deserializeCommand(). On cluster connections, injected keyless commands can be routed using a literal fake key, enabling shard-wide cache deletion, data modification, data reads, or node disruption. On replication connections, the vulnerability can cause uncaught exceptions that repeatedly terminate requests, resulting in denial of service. Only the pipeline() method is affected; transaction() and MULTI are not vulnerable. The vulnerability has been patched in version 3.3.0 of Predis.
Bekijk origineel advisory →CVE-2026-61752 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, data tampering, and information disclosure. The vulnerability is currently undergoing analysis by NVD. NVIDIA has published an advisory via their product-security GitHub repository. The flaw is classified as high criticality given its potential for full system compromise. Deserialization vulnerabilities are commonly exploited in attacks targeting AI/ML infrastructure and enterprise software. Users of NVIDIA Megatron Bridge are advised to monitor NVIDIA's security advisories for patches and mitigations.
Bekijk origineel advisory →