THREAT OPS › Threat News
Threat Intelligence News
12195 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-4984 (HIGH 8.2) — The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it fetches user-controlled URLs ('MediaUrlN' parameters) using HTTP requests that include the integration's Twilio credentials in thenvd · 2026-03-27
- [NVD] CVE-2026-4948 (MEDIUM 5.5) — A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper anvd · 2026-03-27
- [Breach] ZenBusiness — 5,118,184 accounts exposedhibp_breaches · 2026-03-27
- [NVD] CVE-2026-2100 (MEDIUM 5.3) — A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitializenvd · 2026-03-26
- [NVD] CVE-2026-0968 (LOW 3.1) — A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory nvd · 2026-03-26
- [NVD] CVE-2026-0967 (MEDIUM 5.5) — A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts andnvd · 2026-03-26
- [NVD] CVE-2026-0966 (HIGH 8.2) — A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server'nvd · 2026-03-26
- [NVD] CVE-2026-0965 (LOW 3.3) — A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by cnvd · 2026-03-26
- [NVD] CVE-2026-0964 (MEDIUM 6.3) — A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. Thisnvd · 2026-03-26
- [NVD] CVE-2026-4926 (HIGH 7.5) — Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service. Patches: Fixed in version 8.4.0. Worknvd · 2026-03-26
- [NVD] CVE-2026-33487 (HIGH 7.5) — goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID. In Go versions before 1.22, or when `go.monvd · 2026-03-26
- [NVD] CVE-2026-4897 (MEDIUM 5.5) — A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of nvd · 2026-03-26
- [NVD] CVE-2026-4809 (CRITICAL 9.8) — plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executablnvd · 2026-03-26
- Introducing Intelligence Center 3.7: Faster decisions with clearer context across defense and enterpriseeclecticiq · 2026-03-26
- Free TIP Bundles to test, validate, and operationalize threat intelligence fastereclecticiq · 2026-03-26
- [Breach] BreachForums Version 5 — 339,778 accounts exposedhibp_breaches · 2026-03-26
- [NVD] CVE-2026-33247 (HIGH 7.4) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any usnvd · 2026-03-25
- [NVD] CVE-2026-33219 (MEDIUM 5.3) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requiresnvd · 2026-03-25
- [NVD] CVE-2026-33218 (HIGH 7.5) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 annvd · 2026-03-25
- [NVD] CVE-2026-33217 (HIGH 7.1) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT snvd · 2026-03-25
- [NVD] CVE-2026-33216 (HIGH 8.6) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and expnvd · 2026-03-25
- [NVD] CVE-2026-29785 (HIGH 7.5) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a pnvd · 2026-03-25
- [NVD] CVE-2026-27889 (HIGH 7.5) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic in the nats-server. This happens before anvd · 2026-03-25
- [NVD] CVE-2026-20012 (HIGH 8.6) — A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote atnvd · 2026-03-25
- [NVD] CVE-2026-3104 (HIGH 7.5) — A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11nvd · 2026-03-25
- [NVD] CVE-2026-28529 (HIGH 7.8) — cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allows local users to trigger use-after-free conditions. Attackers with access to the /dev/crypto interface can repeatedly decrement refnvd · 2026-03-25
- [NVD] CVE-2026-1519 (HIGH 7.5) — If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see:nvd · 2026-03-25
- Security for the Quantum Era: Implementing Post-Quantum Cryptography in Androidgoogle_security · 2026-03-25
- [NVD] CVE-2026-23385 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: clone set on flush only Syzbot with fault injection triggered a failing memory allocation with GFP_KERNEL which results in a WARN splat: iter.err WARNING: net/netfilter/nf_tables_api.c:84nvd · 2026-03-25
- Try our new dimensional analysis Claude plugintrailofbits · 2026-03-25
- 2026-004: Critical Vulnerability in SharePoint Exploitedcert_eu · 2026-03-25
- CSIRTs Around the World – Azerbaijanjpcert_blog · 2026-03-25
- [NVD] CVE-2026-2072 (HIGH 8.2) — Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00.nvd · 2026-03-25
- [Breach] Addi — 34,532,941 accounts exposedhibp_breaches · 2026-03-25
- [Breach] Sound Radix — 292,993 accounts exposedhibp_breaches · 2026-03-25
- [NVD] CVE-2026-4433 (MEDIUM 4.3) — An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information tnvd · 2026-03-24
- [NVD] CVE-2026-23924 (MEDIUM 4.9) — Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.nvd · 2026-03-24
- [NVD] CVE-2026-23921 (HIGH 8.8) — A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary nvd · 2026-03-24
- [NVD] CVE-2026-23920 (HIGH 8.8) — Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.nvd · 2026-03-24
- [NVD] CVE-2026-23919 (MEDIUM 6.0) — For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A finvd · 2026-03-24
- How a Poisoned Security Scanner Became the Key to Backdooring LiteLLMsnyk · 2026-03-24
- [NVD] CVE-2026-22739 (HIGH 8.6) — Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Snvd · 2026-03-24
- [NVD] CVE-2026-33211 (CRITICAL 9.6) — Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tnvd · 2026-03-24
- Supercharge Your SOCelastic_security · 2026-03-24
- Streamlining the Security Analyst Experienceelastic_security · 2026-03-24
- Security Automation with Elastic Workflows: From Alert to Responseelastic_security · 2026-03-24
- Investigating from the Endpoint Across Your Environment with Elastic Security XDRelastic_security · 2026-03-24
- [NVD] CVE-2026-33167 (MEDIUM 6.1) — Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript invd · 2026-03-23
- 2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADCcert_eu · 2026-03-23
- GitHub expands application security coverage with AI‑powered detectionsgithub_security_lab · 2026-03-23
- [NVD] CVE-2026-4647 (MEDIUM 6.1) — A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being usnvd · 2026-03-23
- [NVD] CVE-2026-31848 (CRITICAL 9.8) — Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible and lacks integrity protection, an attacker can reconstructnvd · 2026-03-23
- [NVD] CVE-2026-31847 (HIGH 8.8) — Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. By sending a crafted POST request with parameters such as telnetManageEn=true and telnetPwd, an authenticatednvd · 2026-03-23
- [NVD] CVE-2026-31846 (MEDIUM 6.5) — Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthenticated attacker to retrieve sensitive device information, including the administrator password. An attacker can decode this value to nvd · 2026-03-23
- [NVD] CVE-2026-4602 (HIGH 7.5) — Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow nvd · 2026-03-23
- [NVD] CVE-2026-4601 (HIGH 8.7) — Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalinvd · 2026-03-23
- [NVD] CVE-2026-4600 (HIGH 7.4) — Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatnvd · 2026-03-23
- [NVD] CVE-2026-4599 (CRITICAL 9.1) — Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting tnvd · 2026-03-23
- [NVD] CVE-2026-4598 (HIGH 7.5) — Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such cranvd · 2026-03-23
- [NVD] CVE-2026-2756 (MEDIUM 5.0) — A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characternvd · 2026-03-21
- [NVD] CVE-2026-32896 (MEDIUM 4.8) — The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can bypass webhook authentication by exploitnvd · 2026-03-21
- [NVD] CVE-2026-33243 (HIGH 8.2) — barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were venvd · 2026-03-20
- [NVD] CVE-2026-33231 (HIGH 7.5) — NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet Bnvd · 2026-03-20
- [NVD] CVE-2026-33228 (CRITICAL 9.8) — flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, anvd · 2026-03-20
- [NVD] CVE-2026-33210 (CRITICAL 9.1) — Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used nvd · 2026-03-20
- [NVD] CVE-2026-33186 (CRITICAL 9.1) — gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` ominvd · 2026-03-20
- [NVD] CVE-2025-15608 (CRITICAL 9.8) — This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions,nvd · 2026-03-20
- [NVD] CVE-2026-4519 (LOW 3.3) — The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().nvd · 2026-03-20
- [NVD] CVE-2026-32829 (HIGH 7.5) — lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from previous decompression operations. The library fails to properly valnvd · 2026-03-20
- Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenarioelastic_security · 2026-03-20
- A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)watchtowr · 2026-03-19
- [NVD] CVE-2026-4426 (MEDIUM 6.5) — A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO fnvd · 2026-03-19
- [NVD] CVE-2026-4424 (HIGH 7.5) — A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specianvd · 2026-03-19
- [NVD] CVE-2025-71260 (HIGH 8.8) — BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the Vnvd · 2026-03-19
- [NVD] CVE-2025-71259 (MEDIUM 4.3) — BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from the server. Attackers can exploit insufficiennvd · 2026-03-19
- [NVD] CVE-2025-71258 (MEDIUM 4.3) — BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL nvd · 2026-03-19
- [NVD] CVE-2025-71257 (HIGH 7.3) — BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can bypass access controls to invoke restrictenvd · 2026-03-19
- [Breach] Berkadia — 305,216 accounts exposedhibp_breaches · 2026-03-19
- Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)elastic_security · 2026-03-19
- [NVD] CVE-2026-23255 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: net: add proper RCU protection to /proc/net/ptype Yin Fengwei reported an RCU stall in ptype_seq_show() and provided a patch. Real issue is that ptype_seq_next() and ptype_seq_show() violate RCU rules. ptype_nvd · 2026-03-18
- [NVD] CVE-2026-33001 (HIGH 8.8) — Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of thenvd · 2026-03-18
- The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)watchtowr · 2026-03-18
- [NVD] CVE-2026-31938 (CRITICAL 9.6) — jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the created PDF is opened in. The vulnerability can be envd · 2026-03-18
- [NVD] CVE-2026-31898 (HIGH 8.1) — jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to the following methnvd · 2026-03-18
- [NVD] CVE-2026-30922 (HIGH 7.5) — pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousanvd · 2026-03-18
- [NVD] CVE-2026-2603 (HIGH 8.1) — A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when thenvd · 2026-03-18
- [NVD] CVE-2026-2092 (HIGH 7.7) — A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a maliciousnvd · 2026-03-18
- [NVD] CVE-2026-27459 (CRITICAL 9.8) — pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Stanvd · 2026-03-18
- [Breach] Infinite Campus — 137,123 accounts exposedhibp_breaches · 2026-03-18
- [NVD] CVE-2026-32981 (HIGH 7.5) — A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to accenvd · 2026-03-17
- Agent Commander: Promptware-Powered Command and Controlembracethered · 2026-03-17
- Update: oledump.py Version 0.0.85didier_stevens · 2026-03-17
- Get started with Elastic Security from your AI agentelastic_security · 2026-03-17
- [NVD] CVE-2026-3644 (HIGH 7.5) — The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the ounvd · 2026-03-16
- [NVD] CVE-2026-28498 (HIGH 7.5) — Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verificationnvd · 2026-03-16
- [NVD] CVE-2026-27962 (CRITICAL 9.1) — Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=Nonenvd · 2026-03-16
- [NVD] CVE-2026-3442 (MEDIUM 6.1) — A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful envd · 2026-03-16
- [NVD] CVE-2026-3441 (MEDIUM 6.1) — A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker canvd · 2026-03-16
- Update: oledump.py Version 0.0.84didier_stevens · 2026-03-14
- [NVD] CVE-2026-4111 (HIGH 7.5) — A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forwnvd · 2026-03-13