Posts of last few hours
A vulnerability has been found in fastify middie up to 9.3.3 and classified as critical. The affected element is an unknown function. The manipulation leads to improper access controls.
This vulnerability is listed as CVE-2026-85184. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
https://vuldb.com/vuln/398724
A vulnerability, which was classified as critical, was found in OpenStack. Impacted is an unknown function of the component Location API. Executing a manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-71198. The attack can be launched remotely. No exploit exists.
https://vuldb.com/vuln/398723
The G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transition
https://www.infosecurity-magazine.com/news/g7-urges-quantum-safe-cyber-rules/
A vulnerability, which was classified as very critical, has been found in JAL Information PALLET CONTROL, PalletControl and PalletControl Cloud. This issue affects some unknown processing. Performing a manipulation results in permission issues.
This vulnerability is identified as CVE-2026-81302. The attack is only possible with local access. There is not any exploit available.
https://vuldb.com/vuln/398722
A vulnerability classified as critical was found in MISP up to 2.5.45. This vulnerability affects the function SharingGroup::canUse of the component Sharing Group. Such manipulation of the argument sharing_group_id leads to improper privilege management.
This vulnerability is referenced as CVE-2026-85533. It is possible to launch the attack remotely. No exploit is available.
Applying a patch is advised to resolve this issue.
https://vuldb.com/vuln/398721
A vulnerability classified as critical has been found in MISP up to 2.5.45. This affects the function MispAttribute::deleteAttribute of the component Attribute Deletion. This manipulation causes improper privilege management.
The identification of this vulnerability is CVE-2026-85538. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
https://vuldb.com/vuln/398720
A vulnerability described as critical has been identified in OpenStack Glance. Affected by this issue is some unknown functionality of the component Web Download. The manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-71197. The attack may be performed from remote. There is no available exploit.
https://vuldb.com/vuln/398719
A vulnerability marked as very critical has been reported in Red Hat Enterprise Linux and OpenShift Container Platform. Affected by this vulnerability is an unknown functionality. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2026-81665. The attack is possible to be carried out remotely. No exploit exists.
https://vuldb.com/vuln/398718
A vulnerability labeled as critical has been found in OpenStack Glance. Affected is an unknown function. Executing a manipulation can lead to server-side request forgery.
This vulnerability is handled as CVE-2026-71196. The attack can be executed remotely. There is not any exploit available.
https://vuldb.com/vuln/398717
A vulnerability identified as problematic has been detected in sc Internet Vivoo Rentals Plugin up to 3.15.x on WordPress. This impacts an unknown function. Performing a manipulation results in authorization bypass.
This vulnerability is known as CVE-2026-27432. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
https://vuldb.com/vuln/398716
A vulnerability categorized as problematic has been discovered in Snowflake JDBC Driver up to 4.3.3. This affects an unknown function of the file connections.toml. Such manipulation of the argument Account leads to improper input validation.
This vulnerability is traded as CVE-2026-85528. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/398715
Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion campaign targeting government, political, education and industrial organizations across Asia. The campaign is distinct from an earlier operation reported in July that used Claude Code and DeepSeek against government and financial-sector targets. In this newer […]
The post Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/ai-powered-government-attacks/
日本研究团队发布研究结果称,在往返于北海道和东亚的候鸟粪便中发现了耐药菌。这些细菌已被报告对多种抗菌药具有耐药性,可能正在跨国境扩散。团队 2024 年 9 月在北海道厚岸町的灰背鸥繁殖地采集了粪便进行分析。这种鸟夏季在北日本地区繁殖,一天平均在栖息地周边飞 25 公里;冬季则移动至 4000 多公里以外的东亚地区。分析结果显示,检测出了“嗜麦芽窄食单胞菌”。该菌会在免疫力低下者中引发肺炎和血流感染症,也被认为是导致新冠病毒感染重症化的原因之一。检测出的部分细菌对两种用于治疗该菌感染患者的药物表现出耐药性,通过蛋白质等的膜抵抗药物攻击的守护能力以及活动能力较高。分析遗传信息后发现,其中包含日本国内尚无报告案例的类型,有可能是从海外带入的。灰背鸥是杂食性鸟类。或许是它们在各处吃食的过程中,也把细菌摄入了体内。
https://www.solidot.org/story?sid=85288
A vulnerability was found in Corosync. It has been rated as very critical. The impacted element is the function check_memb_commit_token_sanity. This manipulation causes integer overflow.
This vulnerability appears as CVE-2026-81666. The attack may be initiated remotely. There is no available exploit.
https://vuldb.com/vuln/398714
A vulnerability was found in Kings Plugins MarketKing Plugin up to 2.1.60 on WordPress. It has been declared as problematic. The affected element is an unknown function. The manipulation results in missing authorization.
This vulnerability is reported as CVE-2026-85311. The attack can be launched remotely. No exploit exists.
https://vuldb.com/vuln/398713
A vulnerability was found in WC Lovers WCFM Membership Plugin up to 2.11.11 on WordPress. It has been classified as problematic. Impacted is an unknown function. The manipulation leads to missing authorization.
This vulnerability is documented as CVE-2026-32480. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/398712
A vulnerability was found in Automattic WooCommerce Plugin up to 10.x on WordPress and classified as problematic. This issue affects some unknown processing. Executing a manipulation can lead to sql injection.
This vulnerability is registered as CVE-2026-57777. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/398711
A vulnerability has been found in Checkmk and classified as problematic. This vulnerability affects unknown code. Performing a manipulation results in improper certificate validation.
This vulnerability is cataloged as CVE-2026-15937. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/398710
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.
The vulnerabilities in question are -
CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html
A vulnerability, which was classified as problematic, was found in Snowflake Go Driver, JDBC Driver, Node.js Driver and Python Connector. This affects an unknown part. Such manipulation leads to improper certificate validation.
This vulnerability is listed as CVE-2026-85525. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
https://vuldb.com/vuln/398709
Latest Blog Posts
- 1 week 5 days ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 2 weeks ago
- 7 months 1 week ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago