Aggregator
56 моделей AMD, 7,1 балла по CVSS. Чем опасна CVE-2025-54502 и нужно ли срочно обновлять BIOS
CVE-2026-9568 | ThingsBoard up to 4.3.1.1 YAML /api/v1/provision getGatewayDockerComposeFile code injection (ID 15550)
【安全圈】“神奇小子”乔治 · 霍茨警告称 AI 编程智能体将成软件最大隐患
【安全圈】用户反馈摩托罗拉手机预装 App 劫持电商应用,植入电商联盟代码
【安全圈】微软 Copilot Cowork 智能体 AI 曝安全风险,机密文件恐外泄
Submit #817064: ThingsBoard ThingsBoard Community Edition 3.6.2 through 4.3.1.1 Code Injection [Accepted]
CVE-2026-9567 | GPAC up to 2.4.0 MP4Box isom_intern.c MergeFragment null pointer dereference (Issue 3549)
CVE-2026-9566 | teableio teable up to 1.9.x Sign-up LoginPage.tsx redirect cross site scripting
Submit #816075: GPAC MP4Box <= 2.4.0 (master commit 7508ccc and earlier) Null pointer dereference (Denial of Service) [Accepted]
Submit #815798: Teable < release.2026-04-21T08-57-20Z.1513 DOM-Based XSS, Open Redirect [Accepted]
Critical Memcached SASL Vulnerability Let Attackers Infer Valid Usernames
A newly disclosed security issue in Memcached has raised concerns after developers confirmed a timing side-channel vulnerability in its SASL authentication mechanism that could allow attackers to infer valid usernames, now tracked as CVE‑2026‑47783. The flaw was addressed in the recently released Memcached version 1.6.42, a security-focused update that fixes multiple critical bugs affecting stability […]
The post Critical Memcached SASL Vulnerability Let Attackers Infer Valid Usernames appeared first on Cyber Security News.
共研智能体岗位标准 360牵头推进AI人才规范化发展!
High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)
Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks. It affects the SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. About CVE-2026-45659 CVE-2026-45659 stems from Shareoint deserializing untrusted data, and may be exploited by an authenticated attacker to execute code remotely on a vulnerable SharePoint Server instance – no user interaction required. “The attack complexity is Low (AC:L) because … More →
The post High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659) appeared first on Help Net Security.
CVE-2026-9565 | haojing8312 WorkClaw up to 0.6.4 Blacklist bash.rs is_dangerous os command injection
Apache CXF LDAP Injection Vulnerability Let Attacker Retrieve Arbitrary Certificates
A newly disclosed vulnerability in Apache CXF, tracked as CVE-2026-44930, is raising concerns among enterprise users relying on its XKMS (XML Key Management Specification) services. The flaw, classified as an important severity issue, affects the LDAP-based certificate repository component and could allow attackers to retrieve arbitrary digital certificates from vulnerable systems. Apache CXF is widely […]
The post Apache CXF LDAP Injection Vulnerability Let Attacker Retrieve Arbitrary Certificates appeared first on Cyber Security News.
CVE-2026-9564 | SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0 view_patient Remarks cross site scripting
CVE-2026-9562 | sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5 Dashboard access control
Submit #815713: haojing8312 WorkClaw v0.1.0 - v0.6.3 Incomplete Blacklist [Accepted]
ConnectWise Automate Vulnerability Let Attackers Bypass Security Checks
ConnectWise has disclosed a high-impact security vulnerability in its Automate platform that could allow attackers to bypass critical security checks and execute malicious code under specific conditions. The flaw, tracked as CVE-2026-9089, affects versions of ConnectWise Automate before 2026.5 and has been assigned a CVSS score of 8.8, highlighting its potential severity in managed service […]
The post ConnectWise Automate Vulnerability Let Attackers Bypass Security Checks appeared first on Cyber Security News.