Aggregator
CVE-2026-3202 | Wireshark up to 4.6.3 NTS-KE Protocol Dissector null pointer dereference (EUVD-2026-8661)
4 months ago
A vulnerability classified as problematic was found in Wireshark up to 4.6.3. This impacts an unknown function of the component NTS-KE Protocol Dissector. Such manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2026-3202. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-3203 | Wireshark up to 4.4.13/4.6.3 RF4CE Profile Protocol Dissector buffer over-read (EUVD-2026-8662)
4 months ago
A vulnerability, which was classified as problematic, has been found in Wireshark up to 4.4.13/4.6.3. Affected is an unknown function of the component RF4CE Profile Protocol Dissector. Performing a manipulation results in buffer over-read.
This vulnerability is known as CVE-2026-3203. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-65995 | Apache Airflow up to 3.1.3 kwargs information disclosure (EUVD-2025-207649)
4 months ago
A vulnerability was found in Apache Airflow up to 3.1.3 and classified as problematic. This issue affects some unknown processing of the component kwargs. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2025-65995. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-26047 | Moodle TeX Formula Editor resource consumption (EUVD-2026-7527 / Nessus ID 299831)
4 months ago
A vulnerability was found in Moodle. It has been rated as problematic. This affects an unknown function of the component TeX Formula Editor. The manipulation leads to resource consumption.
This vulnerability is documented as CVE-2026-26047. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
Bringing Shadow AI Into the Light
4 months ago
In offices across the world, the most productive employees are already working with artificial intelligence (AI), and their organizations are just beginning to notice. According to Gallup, “the percentage of U.S. employees who reported using AI at work at least a few times a year increased from 40% to 45% between the...
Heather Broughton
Chinese cyberspies breached dozens of telecom firms, govt agencies
4 months ago
Google's Threat Intelligence Group (GTIG), Mandiant, and partners disrupted a global espionage campaign attributed to a suspected Chinese threat actor that used SaaS API calls to hide malicious traffic in attacks targeting telecom and government networks. [...]
Bill Toulas
Accelerate Digital Service Delivery in Government Agencies
4 months ago
Joe Henry
Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration
4 months ago
Cybersecurity researchers have disclosed multiple security vulnerabilities in Anthropic's Claude Code, an artificial intelligence (AI)-powered coding assistant, that could result in remote code execution and theft of API credentials.
"The vulnerabilities exploit various configuration mechanisms, including Hooks, Model Context Protocol (MCP) servers, and environment variables – executing
The Hacker News
安全预警 - CPU漏洞“Meltdown”和“Spectre”
4 months ago
安全预警 - CPU漏洞“Meltdown”和“Spectre”
4 months ago
Threat actor leveraged Cisco SD-WAN zero-day since 2023 (CVE-2026-20127)
4 months ago
A “highly sophisticated” cyber threat actor has been exploiting a zero-day authentication bypass vulnerability (CVE-2026-20127) in Cisco Catalyst SD-WAN Controller (formerly vSmart), Cisco has announced today. The vulnerability was reported by Australian Signals Directorate’s Australian Cyber Security Centre, who said that once the vulnerability was exploited, “the malicious actors add[ed] a rogue peer, and eventually gain[ed] root access to establish long-term persistence in SD-WANs.” “This vulnerability exists because the peering authentication mechanism in an affected … More →
The post Threat actor leveraged Cisco SD-WAN zero-day since 2023 (CVE-2026-20127) appeared first on Help Net Security.
Zeljka Zorz
CVE-2026-27541 | Wholesale Suite Plugin up to 2.2.1 on WordPress privilege escalation
4 months ago
A vulnerability classified as critical has been found in Wholesale Suite Plugin up to 2.2.1 on WordPress. The affected element is an unknown function. This manipulation causes privilege escalation.
This vulnerability is registered as CVE-2026-27541. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-27542 | Wholesale Lead Capture Plugin up to 1.17.8 on WordPress Remote Code Execution
4 months ago
A vulnerability described as critical has been identified in Wholesale Lead Capture Plugin up to 1.17.8 on WordPress. Impacted is an unknown function. The manipulation results in Remote Code Execution.
This vulnerability is cataloged as CVE-2026-27542. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-27540 | Wholesale Lead Capture Plugin up to 1.17.8 on WordPress unrestricted upload
4 months ago
A vulnerability marked as critical has been reported in Wholesale Lead Capture Plugin up to 1.17.8 on WordPress. This issue affects some unknown processing. The manipulation leads to unrestricted upload.
This vulnerability is listed as CVE-2026-27540. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-3184 | util-linux Hostname Canonicalization access control
4 months ago
A vulnerability labeled as critical has been found in util-linux. This vulnerability affects unknown code of the component Hostname Canonicalization. Executing a manipulation can lead to improper access controls.
This vulnerability is tracked as CVE-2026-3184. The attack is only possible within the local network. No exploit exists.
vuldb.com
CVE-2026-3190 | Red Hat KeyCloak UMA 2.0 Protection API information disclosure
4 months ago
A vulnerability identified as problematic has been detected in Red Hat KeyCloak. This affects an unknown part of the component UMA 2.0 Protection API. Performing a manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-3190. The attack can only be performed from the local network. There is not any exploit available.
vuldb.com
CVE-2026-25984 | Overflow in PSB PSDImageMagick out-of-bounds
4 months ago
A vulnerability categorized as problematic has been discovered in Overflow in PSB PSDImageMagick. Affected by this issue is some unknown functionality of the component PSB Handler. Such manipulation leads to out-of-bounds read.
This vulnerability is referenced as CVE-2026-25984. It is possible to launch the attack remotely. No exploit is available.
A patch should be applied to remediate this issue.
vuldb.com
PowerSchool, Chicago Public Schools to settle student data privacy lawsuit for $17 million
4 months ago
In addition to the $17.25 million payout, which will be split between more than 10 million potential class members, the settlement requires PowerSchool to establish a “web governance” committee to monitor certain actions.
CVE-2026-20010 | Cisco NX-OS Software Link Layer Discovery Protocol buffer access with incorrect length value (cisco-sa-n3kn9k_aci_lldp_dos-NdgRrrA3)
4 months ago
A vulnerability was found in Cisco NX-OS Software, NX-OS System Software in ACI Mode and Unified Computing System. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component Link Layer Discovery Protocol. This manipulation causes buffer access with incorrect length value.
The identification of this vulnerability is CVE-2026-20010. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com