Posts of last few hours
A vulnerability classified as critical has been found in Elastic Kibana up to 9.4.4. This affects an unknown function. This manipulation causes authorization bypass.
This vulnerability is registered as CVE-2026-72666. Remote exploitation of the attack is possible. No exploit is available.
https://vuldb.com/vuln/389816
本文记录 Hack The Box Monteverde 靶机的完整渗透过程。目标是一台 Windows Active Directory 域控,初始突破口来自 LDAP 匿名枚举与一次“密码即用户名”的弱口令猜测。通过 SABatchJobs 账户访问 SMB 共享,在 users$ 中发现 azure.xml 明文凭据,成功登录 mhope 用户并拿下 User Shell。随后发现目标部署了
https://xz.aliyun.com/news/92663
CVE-2026-64563 是 Linux 内核新近披露的本地权限提升漏洞,因哈希表重置未清空指针导致的释放后使用(UAF)漏洞,本文主要针对该漏洞进行分析以及利用
https://xz.aliyun.com/news/92649
Найти источник необычных помех помогло машинное обучение.
https://www.securitylab.ru/news/576951.php
A vulnerability labeled as problematic has been found in Linux Kernel up to 6.18.7. This affects the function __skb_flow_dissect of the file net/core/flow_dissector.c of the component bonding. The manipulation results in privilege escalation.
This vulnerability is reported as CVE-2026-23119. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.
https://vuldb.com/vuln/346063
A vulnerability classified as critical was found in Linux Kernel up to 6.18.7. Affected by this issue is the function l2tp_tunnel_del_work of the component l2tp. Such manipulation leads to race condition.
This vulnerability is traded as CVE-2026-23120. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/346095
A vulnerability marked as critical has been reported in Linux Kernel up to 6.18.7. This vulnerability affects the function ice_deinit_hw of the component Ice Driver. This manipulation causes null pointer dereference.
This vulnerability appears as CVE-2026-23117. The attacker needs to be present on the local network. There is no available exploit.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/346064
A vulnerability classified as critical has been found in Linux Kernel up to 6.12.68/6.18.7. Affected by this vulnerability is the function ktime_get_seconds of the component rxrpc. This manipulation causes insufficient verification of data authenticity.
This vulnerability appears as CVE-2026-23118. The attacker needs to be present on the local network. There is no available exploit.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/346094
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.161/6.6.121/6.12.67/6.18.7. Affected is the function imx8mq_vpu_power_notifier of the component pmdomain. The manipulation results in privilege escalation.
This vulnerability is reported as CVE-2026-23116. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/346093
A vulnerability classified as critical was found in Linux Kernel up to 6.18.7. This affects the function tty_port_link_device of the file drivers/tty/tty_io.c. The manipulation results in race condition.
This vulnerability is identified as CVE-2026-23115. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/345997
A vulnerability marked as critical has been reported in Linux Kernel up to 6.6.121/6.12.67/6.18.7. Impacted is an unknown function. This manipulation causes denial of service.
This vulnerability is handled as CVE-2026-23113. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/346022
A vulnerability was found in Linux Kernel up to 6.18.7. It has been rated as critical. This impacts the function fpsimd_restore_current_state of the component arm64. This manipulation causes state issue.
This vulnerability appears as CVE-2026-23114. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is advised.
https://vuldb.com/vuln/346004
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.15.199/6.1.162/6.6.123/6.12.69/6.18.9. Impacted is the function nft_map_catchall_activate of the component nf_tables. The manipulation results in improper update of reference count.
This vulnerability is known as CVE-2026-23111. Access to the local network is required for this attack. No exploit is available.
You should upgrade the affected component.
https://vuldb.com/vuln/345901
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.18.9. This issue affects the function nvmet_tcp_build_pdu_iovec of the component nvmet-tcp. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2026-23112. Access to the local network is required for this attack to succeed. There is no exploit available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/345900
A vulnerability identified as critical has been detected in Linux Kernel up to 6.18.9. This impacts the function ieee80211_ocb_rx_no_sta of the component OCB Interface. Performing a manipulation results in privilege escalation.
This vulnerability is reported as CVE-2025-71224. The attacker must have access to the local network to execute the attack. No exploit exists.
You should upgrade the affected component.
https://vuldb.com/vuln/346048
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.123/6.12.69/6.18.9. The impacted element is the function smb2_open of the component smb. The manipulation leads to improper update of reference count.
This vulnerability is uniquely identified as CVE-2025-71223. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/346068
A vulnerability was found in Linux Kernel up to 6.18.9. It has been declared as critical. Affected by this issue is the function skb_push of the component wifi. Executing a manipulation can lead to privilege escalation.
This vulnerability is tracked as CVE-2025-71222. The attack is only possible within the local network. No exploit exists.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/346073
A vulnerability classified as critical was found in Linux Kernel up to 6.18.9. The affected element is the function mmp_pdma_residue of the component dmaengine. Executing a manipulation can lead to use after free.
This vulnerability is handled as CVE-2025-71221. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/346067
LobeChat 7 月 2 日一口气公开 4 个 CVE,修 SSRF 时只覆盖了 2 个端点——但 bot 平台的 4 个 sendAttachments(discord/slack/微信/飞书)从 v2.2.9 到 8 月 12 日最新 canary 全是裸 fetch。注册账号、伪造 bot 凭证、3 个 curl 就能扫内网+打云 metadata。配套开源 lobechat-audit
https://xz.aliyun.com/news/92685
Latest Blog Posts
- 1 week 6 days ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 7 months 1 week ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago