Overzicht van binnengekomen advisories.
1553 resultaten gevonden
Grav CMS versions before 3.9.2 are vulnerable to Host header injection in the sendInvitationEmail() function. Attackers can manipulate the HTTP Host header to poison invitation links sent to users, redirecting them to attacker-controlled domains. The vulnerability exists because the require_trusted_host protection only covers password reset flows and not invitation email flows. Token-bearing invitation links can be crafted to exfiltrate tokens or perform phishing attacks. This represents a bypass of existing security controls within the Grav CMS framework. The fix is available in Grav version 3.9.2 and above.
Bekijk origineel advisory →CVE-2026-54874 affects OpenSSL's DTLS implementation, where receiving records for a future epoch during a handshake causes excessive memory buffering. The vulnerability stems from OpenSSL retaining the entire 16KB read buffer per record rather than just the record bytes, with up to 100 records buffered per connection, resulting in ~1.7MB retained per connection. This yields a memory amplification factor of approximately 1200x, enabling remote memory exhaustion DoS attacks against DTLS servers. Affected versions include OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2. The issue was reported by Amazon Web Services on 18 May 2026 and fixed by Matt Caswell. Patches are available across all affected branches. Severity is assessed as Low due to bounded per-connection memory and applicability of existing connection limits.
Bekijk origineel advisory →An unpatched vulnerability has been discovered in Calix GS7 XGS (GS5239XG) residential routers widely deployed by U.S. broadband providers. The flaw allows remote, unauthenticated attackers to create arbitrary port-forwarding rules, effectively bypassing Network Address Translation (NAT) protections. This exposure can make internal network devices publicly accessible from the internet without any user interaction or authentication required. The vulnerability poses significant risk to home and small business users relying on these routers for network segmentation and security. As of the article's publication, no patch has been released by Calix to address the issue. Multiple broadband providers distributing these devices could have a large number of affected customers. The ability to expose internal devices could facilitate further attacks including lateral movement, data exfiltration, or device compromise.
Bekijk origineel advisory →Hackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities allow attackers to forge SAML responses and gain administrative access to affected WordPress sites. The flaws are classified as critical severity, indicating significant risk to site integrity and data. Exploitation attempts are ongoing, making patching urgent for all affected site owners. WordPress administrators using the miniOrange SAML plugin are strongly advised to update immediately to mitigate the risk of full site compromise.
Bekijk origineel advisory →This weekly cybersecurity recap covers multiple emerging threats and attack vectors observed during the week. Key topics include AI-powered attacks targeting Programmable Logic Controllers (PLCs), attacks against GitLab infrastructure, and Stripe API key leaks. The article highlights a trend where trusted tools are being weaponized, old vulnerabilities are receiving renewed exploitation attention, and AI is lowering the barrier for exploit development. Researchers are uncovering attacks that are simpler to execute than previously assumed. The recap serves as a broad overview of the threat landscape for the week, touching on supply chain risks, credential exposures, and critical infrastructure concerns.
Bekijk origineel advisory →Cybersecurity researchers have identified two new malware families, WordlistLoader and SynkLoader, being used to deliver next-stage payloads and likely sell access to ransomware groups. WordlistLoader is used to distribute Amatera Stealer (also known as ACR Stealer or AcridRain Stealer) through ClearFake campaigns that leverage the ClickFix (FakeCaptcha) technique. SynkLoader is focused on phishing Windows credentials. Both loaders represent an evolving threat landscape where initial access brokers use stealthy delivery mechanisms to compromise victims before handing off access to ransomware operators. The campaigns highlight continued abuse of social engineering techniques like fake CAPTCHA pages to trick users into executing malicious code. Gen Digital researchers flagged these threats as part of ongoing monitoring of loader-based malware ecosystems.
Bekijk origineel advisory →A critical security vulnerability (CVE-2026-18963) has been discovered in Keycloak, the open-source identity and access management server maintained by Red Hat. The flaw carries a CVSS score of 9.1 and allows unauthenticated remote attackers to take over any user account by forcing a password reset. Red Hat and the Keycloak project have released patches to address the issue. The vulnerability poses a significant risk to organizations relying on Keycloak for authentication and authorization. Users are strongly advised to apply the available patches immediately to prevent potential account compromise.
Bekijk origineel advisory →CISA has issued an emergency directive ordering U.S. federal agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. The flaw is being actively exploited in the wild, prompting the urgent response from CISA. Zimbra Collaboration Suite is widely used by government and enterprise organizations for email and collaboration. The directive reflects CISA's Known Exploited Vulnerabilities (KEV) catalog process, which mandates timely remediation for confirmed exploited flaws. The short three-day patching window indicates the severity and active exploitation of the vulnerability. Organizations using ZCS are urged to apply available patches immediately to reduce risk of compromise.
Bekijk origineel advisory →A Chinese-speaking cybercrime group tracked as UAT-10147 has been observed targeting Windows and Linux web servers globally using AI to scale their operations. The group deploys a malware called SPECTRE along with EDR bypass techniques and a Linux rootkit. Targeted sectors include education, media, technology, and gaming. The majority of victims are located in Brazil, Bolivia, China, Canada, and Vietnam. The threat came to light following the discovery of an open directory or similar exposed infrastructure. The use of AI to scale attacks marks a notable evolution in the group's operational capabilities. The combination of EDR bypass and a Linux rootkit indicates a sophisticated and persistent threat actor capable of evading modern defenses.
Bekijk origineel advisory →CVE-2026-21962 is an improper access control vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The vulnerability allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible by the affected components. It was disclosed as part of Oracle's January 2026 Critical Patch Update. CISA has included this vulnerability under BOD 26-04, which prioritizes security updates based on risk. Federal agencies and organizations using Oracle HTTP Server or WebLogic Server Proxy Plug-in are advised to apply patches immediately. The vulnerability is rated High criticality and poses significant risk to enterprise environments relying on Oracle middleware. Forensic triage requirements have also been outlined by CISA as part of the BOD 26-04 implementation guidance.
Bekijk origineel advisory →StepSecurity threat intelligence tracked 56 open source supply chain attacks between August 2025 and August 2026, averaging roughly one attack every three days since March. The report provides a comprehensive overview of the current state of supply chain threats targeting open source ecosystems. It includes attack data, patterns, and recommended defenses for organizations relying on open source dependencies. The frequency and consistency of these attacks highlights a growing and persistent threat to software supply chains. The article serves as both a threat intelligence report and a practical guide for improving supply chain security posture.
Bekijk origineel advisory →CVE-2026-71505 describes a broken object-level authorization (BOLA) vulnerability in Dolibarr versions prior to 24.0.0. The flaw exists in the REST API's third-party site account write routes, where per-object access checks are only enforced on read routes but not on write routes. Authenticated attackers with third-party creation rights can exploit this to overwrite the WebPortal password of any company without proper authorization. After overwriting the password, attackers can authenticate as the victim company and access sensitive invoice data. Additionally, the API response exposes the victim's previous password verifier, further compounding the risk. The vulnerability enables full account takeover of any company registered in the WebPortal. A fix was introduced in Dolibarr version 24.0.0, with the patch available on GitHub. Security researchers at CodeAnt AI and VulnCheck have published advisories detailing the exploitation mechanism. Organizations running Dolibarr below version 24.0.0 should upgrade immediately.
Bekijk origineel advisory →A critical unauthenticated privilege escalation vulnerability has been identified in the TranslatePress WordPress plugin affecting versions 3.3.2 and earlier. The vulnerability allows unauthenticated attackers to escalate their privileges without requiring any authentication. This poses a significant security risk to WordPress sites using the affected plugin versions. The vulnerability has been assigned CVE-2026-78267 and is tracked by both NVD and Patchstack. Website administrators using TranslatePress are strongly advised to update to a patched version immediately to mitigate the risk of exploitation.
Bekijk origineel advisory →Multiple DrayTek VigorSwitch models are affected by unauthorized operation vulnerabilities in several syslog functions. The root cause is missing authorization checks, allowing remote attackers to perform sensitive operations without authentication. Attackers can craft malicious requests to modify device configuration, restart services, save startup configuration, or clear logs. The vulnerability poses significant risk to network infrastructure as it can be exploited remotely without credentials. DrayTek has published a security advisory addressing these issues in August 2026. The flaw is classified under missing authorization (CWE-862) and impacts network switch management integrity and availability.
Bekijk origineel advisory →A buffer overflow vulnerability has been identified in UTT HiPER 1200GW devices running firmware versions up to 2.5.3-170306. The flaw resides in the strcpy function within the file /goform/formConfigFastDirectionW, where manipulation of the 'ssid' argument can trigger a buffer overflow condition. The vulnerability is remotely exploitable, meaning an attacker does not need local access to the device to leverage it. A public exploit has already been published and is available for use, increasing the risk of active exploitation. The affected product is a network gateway device, making this a significant concern for network infrastructure security. No authentication bypass details are specified, but the remote nature and published exploit raise the overall severity. Users of UTT HiPER 1200GW should apply patches or mitigations immediately. The vulnerability is tracked as CVE-2026-78170 and has been reported via NVD, VulDB, and a GitHub proof-of-concept repository.
Bekijk origineel advisory →A SQL injection vulnerability was identified in itsourcecode Real Estate Management System version 1.0. The flaw exists in the file search.php, where manipulation of arguments including search, delivery_type, search_price, and property_type can trigger SQL injection. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit is already available, increasing the risk of active exploitation. The issue affects an unknown portion of the application's functionality. Attackers could potentially extract, modify, or delete database contents through this vector. The vulnerability has been catalogued in NVD, VulDB, and referenced in a GitHub issue. Organizations using this system should apply patches or mitigations immediately given the public exploit availability.
Bekijk origineel advisory →Combodo iTop, a web-based IT service management tool, is vulnerable to PHP object injection in its user preference functionality prior to version 3.2.3. This vulnerability can be exploited to achieve remote code execution (RCE). The flaw resides in how user preferences are handled, allowing attackers to inject malicious PHP objects. The issue has been assigned CVE-2026-40877 and is rated high criticality. A fix has been released in iTop version 3.2.3. Organizations using iTop should upgrade immediately to mitigate the risk of remote compromise. No specific threat actors or active exploitation have been mentioned in the article.
Bekijk origineel advisory →Ghostwriter versions before 7.1.2 contain a vulnerability in the report template swap endpoint that fails to validate template ownership. This allows authenticated attackers to attach client-scoped templates belonging to other clients to their own reports. By exploiting sequential template primary keys, attackers can enumerate and attach foreign templates. Once attached, attackers can generate reports to extract sensitive template contents including letterhead, boilerplate text, and methodology documentation. This constitutes a cross-client information disclosure vulnerability affecting multi-tenant deployments of Ghostwriter. The issue has been patched in version 7.1.2 with a fix available in the referenced commit.
Bekijk origineel advisory →CVE-2026-76844 describes a path traversal vulnerability in webpack-dev-middleware affecting the getFilenameFromUrl function. The flaw arises when publicPath is configured without a trailing slash: a crafted request like GET /assets../.env bypasses the UP_PATH_REGEXP traversal guard because the dot-dot sequence is embedded within a path segment rather than standing alone. The offset slice then passes ../.env to path.join, resolving one directory above outputPath. Exploitation requires the middleware to use the physical filesystem, which occurs when writeToDisk is true or a custom outputFileSystem is supplied. The default memfs-backed configuration is not exploitable. Traversal depth is limited to a single directory level due to URL parsing collapsing additional dot-dot segments. The default publicPath of 'auto' (resolving to '/') is also not affected. This is identified as an incomplete fix for CVE-2024-29180, with the vulnerable code present in all releases from 5.3.4, 6.1.2, and 7.1.0 onward.
Bekijk origineel advisory →CVE-2026-28165 describes an unauthenticated privilege escalation vulnerability affecting the Digits WordPress plugin in versions 9.2 and below. The flaw allows unauthenticated users to escalate their privileges, potentially gaining administrative or elevated access without any prior authentication. This type of vulnerability poses a critical risk to WordPress sites using the affected plugin. The vulnerability is documented on the NVD and has been reported via Patchstack. Users are advised to update the Digits plugin beyond version 9.2 to remediate the issue. No exploitation details or active in-the-wild exploitation have been explicitly mentioned, but the unauthenticated nature makes it high severity.
Bekijk origineel advisory →