Overzicht van binnengekomen advisories.
1553 resultaten gevonden
Microsoft heeft een groot aantal kwetsbaarheden verholpen in diverse Office-producten, waaronder SharePoint, Teams, Word, Excel, Outlook, Access, PowerPoint en cloudservices. De kwetsbaarheid CVE-2026-65667 in Microsoft Teams heeft een maximale CVSS-score van 10.0. CVE-2026-70306 in SharePoint (CVSS 9.3) vereist actie en stelt aanvallers in staat willekeurige code uit te voeren via cross-site scripting. CVE-2026-63520 in SharePoint wordt actief misbruikt in het wild, met name bij publiek toegankelijke installaties. CVE-2026-50515 (Azure Service Bus, CVSS 9.9), CVE-2026-62896 (Teams, CVSS 9.6) en CVE-2026-70332 (SharePoint, CVSS 9.6) zijn reeds centraal verholpen en vereisen geen verdere actie. Succesvolle aanvallen vereisen doorgaans dat een slachtoffer een kwaadaardig bestand opent of een link volgt. De kwetsbaarheden leiden tot uitvoering van willekeurige code, privilege escalatie, identiteitsvervalsing en toegang tot gevoelige gegevens.
Bekijk origineel advisory →Arctic Wolf, with medium confidence, linked threat actors to Dark Caracal in a June 2026 intrusion targeting an unnamed communications organization in Venezuela. The attackers deployed GoCaracal, a previously undocumented Go-based malware framework. GoCaracal leverages Ethereum smart contracts to fetch replacement C2 addresses, providing resilience against takedowns. The malware grants operators remote shell access and payload execution capabilities. An extended profile adds browser data theft, keylogging, and remote desktop control. This represents a novel use of blockchain technology to maintain C2 infrastructure. The target being a communications organization raises concerns about potential intelligence collection. The use of Go and blockchain-based C2 reflects increasing sophistication in malware development.
Bekijk origineel advisory →CISA has issued an emergency directive ordering U.S. federal agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution (RCE) vulnerability. The vulnerability is being leveraged in real-world attacks, prompting CISA to set an urgent deadline of Saturday for remediation. The flaw affects Citrix NetScaler ADC and NetScaler Gateway appliances. Active exploitation in the wild makes this a critical priority for government and enterprise environments. Federal agencies are required to comply with CISA's Known Exploited Vulnerabilities (KEV) catalog directives. Failure to patch could expose sensitive government systems to unauthorized remote access. The urgency of the patch deadline reflects the severity and exploitation activity observed by CISA.
Bekijk origineel advisory →The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a 'major incident' following breach claims made by the Qilin ransomware gang. ATF is a U.S. federal regulatory agency responsible for enforcing laws governing firearms and explosives. The Qilin ransomware group claimed responsibility for compromising one of ATF's systems. This incident represents a significant attack on a U.S. law enforcement and regulatory agency. The breach raises serious concerns about the exposure of sensitive federal data related to firearms and explosives enforcement. Qilin is a known ransomware-as-a-service operation that has targeted various high-profile organizations. The confirmation of a 'major incident' suggests the compromise may have had significant operational or data impact. Further details on the extent of the breach and any data exfiltration are pending investigation.
Bekijk origineel advisory →Academic researchers from the University of Toronto have disclosed a new Rowhammer attack called GPUThor targeting NVIDIA workstation GPUs equipped with GDDR6 memory. The attack defeats error correction codes (ECC), which is the primary mitigation NVIDIA recommends against GPU Rowhammer attacks. GPUThor enables both denial-of-service (DoS) and privilege escalation attacks, ultimately allowing an attacker to gain a root shell on the host system. The attack demonstrates that ECC alone is insufficient as a defense against Rowhammer-class attacks on modern GPU hardware. This research highlights significant security risks for workstation and high-performance computing environments using NVIDIA RTX A6000 GPUs, and potentially other GDDR6-based GPU products.
Bekijk origineel advisory →JFrog Artifactory contains an improper limitation of a pathname to a restricted directory (path traversal) vulnerability tracked as CVE-2026-66384. The flaw allows an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog and is subject to BOD 26-04, which prioritizes security updates based on risk. JFrog has published security advisories and release notes for self-managed Artifactory instances addressing this issue. Organizations using JFrog Artifactory in self-managed deployments are advised to apply the relevant patches immediately. CISA has also provided forensics triage requirements as part of the BOD 26-04 implementation guidance. The NVD entry for this CVE provides additional technical details and scoring.
Bekijk origineel advisory →CVE-2026-53362 is a vulnerability in the Linux Kernel affecting the IPv6 networking subsystem that allows for privilege escalation. The vulnerability is unspecified in nature but has been assigned a high criticality rating. It impacts multiple products and distributions that rely on the Linux Kernel, including SUSE, Red Hat, and others. CISA has listed this vulnerability in its Known Exploited Vulnerabilities catalog. Multiple kernel commits have been identified as patches for this issue across several stable branches. The vulnerability affects open-source components and third-party libraries or implementations used by various products. BOD 26-04 directives from CISA require prioritization of security updates based on risk for this vulnerability.
Bekijk origineel advisory →CVE-2023-49105 is a critical improper authentication vulnerability in ownCloud that allows unauthenticated attackers to access, modify, or delete any file if the victim's username is known and no signing-key is configured. The vulnerability affects the WebDAV API via pre-signed URLs, enabling a complete bypass of authentication controls. This flaw poses significant risks to organizations using ownCloud for file storage and sharing. It has been flagged by CISA and is listed in their Known Exploited Vulnerabilities catalog. Remediation guidance is available through ownCloud's security advisories and CISA's BOD 26-04 directive on prioritizing security updates based on risk.
Bekijk origineel advisory →CVE-2026-81097 affects rails-mcp-server versions 1.4.0 through 1.6.0, where the execute_ruby tool's sandbox can be escaped via the pseudo-terminal (PTY) library's spawn entry points. The tool was documented as a read-only Ruby sandbox enforced by a pattern denylist and replacements for Kernel process-spawning methods. However, PTY spawn entry points were never included in the denylist, allowing an attacker to start a shell and execute arbitrary OS commands as the server's running account. The vulnerability was introduced when the denylist was added in version 1.4.0 and persisted through 1.6.0. Version 1.6.1 mitigates the issue by restricting allowed requires to a data-only list and blocking dynamic dispatch to execution entry points. Version 2.0.0 removes the vulnerable tool entirely.
Bekijk origineel advisory →A denial-of-service vulnerability exists in openssl_encrypt versions before 1.4.9. The library fails to validate the 'total' field from QR JSON payloads prior to materializing ranges, allowing attackers to craft malicious QR images containing extremely large total values. This triggers unbounded memory allocation, leading to out-of-memory conditions and denial of service. No authentication or special privileges appear to be required to exploit this vulnerability, as attackers only need to supply a crafted QR image. A fix is available in version 1.4.9 of the openssl_encrypt library. The vulnerability has been assigned CVE-2026-81693 and is documented on NVD as well as GitHub Security Advisories and VulnCheck.
Bekijk origineel advisory →A vulnerability in openssl_encrypt before version 1.4.9 allows attackers to inject ANSI escape sequences via unsanitized email fields in imported identity documents. This enables manipulation of terminal output to display fraudulent cryptographic fingerprints, effectively bypassing the out-of-band verification mechanism designed to protect against key substitution attacks. Attackers can deliver crafted identity bundles through standard contact-exchange flows or keyserver responses, making the attack vector accessible and realistic. The core risk is that users performing fingerprint verification β a critical trust step in encrypted communications β can be deceived into accepting a forged key. This undermines the fundamental security model of tools relying on openssl_encrypt for identity verification and key authentication.
Bekijk origineel advisory →Multiple Zbtlink and MoreQuick router firmware versions ship with a pre-installed backdoor C2 implant called 'yunmgrd' that communicates over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack this channel and execute arbitrary commands as root on affected devices. The vulnerability affects a wide range of devices including Zbtlink L3_V2_8, WE826-T2, ZBT-7628, ZBT-ZBT7621, MoreQuick MQAC/MQAP series, AP522, AP7628, HC5661A, APG721B, HK300, and MAP-N10. Beyond remote code execution, the attacker can modify DNS entries, exfiltrate PPPoE credentials, and establish reverse SSH tunnels for persistent access. This is effectively a supply-chain-level backdoor shipped in production firmware, posing severe risks to network infrastructure and connected environments. The issue was reported by VulnCheck under the campaign name 'DarkLantern/SpeakingStone'.
Bekijk origineel advisory →openssl_encrypt versions prior to 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler. The implementation uses unstretched SHA-256 instead of the recommended Argon2id algorithm for key derivation. This flaw allows attackers to perform offline password guessing attacks against encrypted files at speeds six to seven orders of magnitude faster than the documented protection level. The vulnerability stems from missing key stretching and hash rounds in the encryption pipeline. Exploitation requires access to encrypted files but no authentication or special privileges. Users are advised to upgrade to version 1.4.9 or later to mitigate the risk. The issue is tracked as CVE-2026-81704 and has been assigned a high criticality rating.
Bekijk origineel advisory →A relative path traversal vulnerability exists in the zip extraction functionality of AWS diagram-as-code (awsdac) affecting versions 0.10 through 0.23. The flaw allows a third party to write arbitrary files to the local filesystem by crafting malicious zip entry names containing path traversal sequences. Exploitation could enable unauthorized file writes and inappropriate actions within the diagram bundle. The vulnerability is tracked as CVE-2026-81838 and was disclosed via NVD and an AWS security bulletin. Users are advised to upgrade to version 0.24 or later to remediate the issue. The fix is available on the official GitHub releases page for the awsdac project.
Bekijk origineel advisory →A critical use-after-free vulnerability (CVE-2026-81934) has been identified in Redis within the 'tlsProcessPendingData()' function, which manages the TLS pending-data list. The vulnerability is present when Redis is configured with TLS support. A remote, unauthenticated attacker can potentially exploit this flaw to execute arbitrary commands with the privileges of the Redis server process. The vulnerability affects multiple Redis versions and has been patched in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1. A proof-of-concept exploit has been publicly released on GitHub. Organizations running Redis with TLS enabled should prioritize upgrading to the patched versions immediately to mitigate the risk of unauthorized remote code execution.
Bekijk origineel advisory →CVE-2026-81701 affects openssl_encrypt versions prior to 1.4.9, which use a denylist approach to identify trusted built-in plugins rather than a more secure allowlist. This design flaw allows unsigned plugins placed in top-level plugins/ directories or unknown subdirectories to bypass signature verification entirely. Attackers who can place malicious unsigned plugins along documented installation paths can achieve arbitrary code execution within the CLI process. The impact is severe as the compromised process has direct access to passwords and cryptographic keys. The vulnerability is fixed in version 1.4.9 of openssl_encrypt. Security advisories have been published on GitHub and VulnCheck detailing the issue and remediation steps.
Bekijk origineel advisory →The Python pip package openssl-encrypt (versions 1.4.8 and earlier) contains a vulnerability in its FLAC file parsing logic. It fails to validate the 36-bit STREAMINFO total_samples field before using it to size a NumPy memory allocation. A crafted ~50-byte FLAC file declaring approximately 100 million samples can trigger a multi-gigabyte memory allocation, resulting in an out-of-memory denial of service condition. The vulnerability is triggered during the 'decrypt --stego-extract' operation. Both the 1.4.x and 1.5.x release lines are affected. The issue has been patched in version 1.4.9. Users are advised to upgrade immediately to mitigate the risk of denial of service attacks via malicious FLAC files.
Bekijk origineel advisory →A denial-of-service vulnerability exists in openssl_encrypt versions prior to 1.4.9. The software fails to validate Key Derivation Function (KDF) cost parameters found in encrypted file metadata and keystore headers. Attackers can craft malicious encrypted files with arbitrarily large Argon2, scrypt, or balloon KDF parameters to trigger unbounded memory allocation. This leads to memory exhaustion and process crashes. No authentication is required to exploit this vulnerability. The flaw affects any system processing attacker-controlled encrypted files using the vulnerable library. A fix is available in version 1.4.9 and later. The issue is tracked as CVE-2026-81721 and has been assigned a high severity rating.
Bekijk origineel advisory →CVE-2026-81098 describes a critical missing authentication vulnerability in the Telnyx MCP (Model Context Protocol) server. The HTTP transport was bound to all network interfaces instead of loopback only, and the authentication header parsing logic did not fail when credentials were absent. This allowed unauthenticated remote callers who could reach the port to complete initialization and dispatch tools without any credential. Upon dispatch, the server forwarded its own stored credentials β including the Telnyx API key, client secret, and code-execution key β to upstream endpoints, effectively granting attackers full use of those privileged credentials. The vulnerability affected packages/mcp-server/src/http.ts in the telnyx-node package through version 6.83.0. The fix defaults the host binding to loopback, requires a server API key, and enforces authentication in middleware.
Bekijk origineel advisory →CVE-2026-30062 is a vulnerability affecting free5gc v4.0.1, an open-source 5G core network implementation. The flaw resides in the NGAP (Next Generation Application Protocol) handler, which is responsible for processing communication between the 5G core and base stations. Attackers can exploit this vulnerability by sending a specially crafted NAS (Non-Access Stratum) PDU (Protocol Data Unit) to trigger a Denial of Service condition. Successful exploitation could cause the free5gc service to crash or become unresponsive, disrupting 5G core network operations. The issue was reported via the free5gc GitHub issue tracker. This vulnerability is particularly significant as free5gc is widely used in research, testing, and potentially production 5G deployments. No authentication appears to be required to send malformed NGAP/NAS messages, broadening the attack surface.
Bekijk origineel advisory →