MikeTrendsTrends right now

search

CVSS

Trends

  1. 1
    Oracle PeopleSoft flaw mass-exploited by ShinyHuntersโ—๐Ÿค– Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8, unauthenticated RCE) is being mass-exploited again by ShinyHunters. AttackMmastodonTechnologyCybersecurity24 d ago

    Attackers are mass-exploiting a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, rated CVSS 9.8 as an unauthenticated remote code execution flaw. The ShinyHunters group is reportedly using URL-encoding tricks to bypass WAF rules before deploying web shells. Google has warned of global targeting across multiple sectors, and renewed exploitation waves are drawing fresh attention from security teams.

  2. 2
    Citrix patches two actively exploited NetScaler zero-daysโ—๐Ÿšจ CVE-2026-88771 & CVE-2026-88772: Citrix has patched two exploited NetScaler zero-days (CVSS 9.5). Update to 14.1-73.37MmastodonTechnologyCybersecurity23 d ago

    Citrix has released fixes for two NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated critical at CVSS 9.5 and both reportedly already exploited in the wild. Administrators are urged to update to NetScaler 14.1-73.37 or 13.1-64.23 and to check their systems for signs of compromise. Security teams worldwide are discussing the patch as urgent.

  3. 3
    D-Link DIR-895L routers hit by unpatched critical flawโ–ผD-Link DIR-895L routers hit by CVE-2026-100740, a CVSS 9.9 vulnerability. No patch coming: the series reached end-of-lifMmastodonTechnologyCybersecurity13 d ago

    A critical vulnerability, CVE-2026-100740 with a CVSS score of 9.9, has been reported in D-Link DIR-895L routers. The company will not release a fix because the product line reached end-of-life in 2019. Security watchers are warning that affected devices remain exposed, with no vendor support available, and are urging users of the model to consider replacement or mitigation.

  4. 4
    Cross-site scripting flaw found in Greek Open eClass platformโ–ผ๐Ÿšจ EUVD-2024-55777 ๐Ÿ“Š Score: 5.4/10 (CVSS v3.1) ๐Ÿ“… Published: 2026-09-29 | Updated: 2026-09-30 ๐Ÿ“ Cross Site Scripting vulneMmastodonTechnologyCybersecurity07 h ago

    A cross-site scripting vulnerability, tracked as EUVD-2024-55777, has been disclosed in the Greek Universities Network (GUnet) Open eClass Platform version 3.15. The flaw, rated 5.4 out of 10 on the CVSS v3.1 scale, could let a remote attacker execute arbitrary code through user name fields. The advisory was published on 29 September and updated the following day.

  5. 5
    Three unpatched critical flaws disclosed in LightLLMโ–ผ๐Ÿšจ LightLLM Mass Disclosure โ€” 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) โ€” unauthenticated RCE, router profiler RPyC CVEMmastodonTechnologyAI41 d ago

    Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.

  6. 6
    Critical LightLLM flaw exposes AI servers to remote code executionโ—๐Ÿšจ CVE-2026-103041 โ€” CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cacheMmastodonTechnologyCybersecurity01 d ago

    A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.

  7. 7
    Kilo Code vulnerability lets local attackers run codeโ–ผ๐Ÿšจ EUVD-2026-89423 ๐Ÿ“Š Score: 8.4/10 (CVSS v3.1) ๐Ÿ“… Published: 2026-09-29 | Updated: 2026-09-30 ๐Ÿ“ An issue in Kilo Code befoMmastodonTechnologyCybersecurity07 h ago

    A high-severity flaw tracked as EUVD-2026-89423 affects Kilo Code versions before v7.4.1, scoring 8.4 out of 10 under CVSS v3.1. The issue, published on 29 September 2026 and updated a day later, allows a local attacker to execute arbitrary code through the permission or allow-everything endpoint. Users are urged to update to v7.4.1 or later.

  8. 8
    Two memory flaws found in CTranslate2 inference engineโ–ผ๐Ÿšจ CTranslate2 CVE-2026-102566 & CVE-2026-102567 The inference engine behind Whisper & OpenNMT has two memory flaws in itMmastodonTechnologyCybersecurity11 d ago

    Security researchers have disclosed two vulnerabilities in CTranslate2, the machine learning inference engine used by Whisper and OpenNMT. CVE-2026-102566, rated CVSS 7.8, is a heap buffer overflow in the model loader that could allow arbitrary code execution, while CVE-2026-102567, rated 6.1, is an out-of-bounds read enabling memory disclosure or crashes. Developers running speech recognition or translation services are being urged to patch.

  9. 9
    RaspAP hit with three unpatched CVE disclosuresโ–ผ๐Ÿšจ RaspAP Mass Disclosure โ€” 3 CVEs, no patch CVE-2026-101860 (CVSS 8.8) โ€” privilege escalation via sudoers manipulation โ†’MmastodonTechnologyCybersecurity21 d ago

    Security researchers have disclosed three vulnerabilities in RaspAP, the popular router software for Raspberry Pi, with no patches available. The most severe, CVE-2026-101860 with a CVSS score of 8.8, allows privilege escalation to root via sudoers manipulation. Two further flaws, CVE-2026-101859 (5.4) and CVE-2026-101858 (4.7), involve OS command injection, including through the OpenVPN handler and WiFiManager SSID handling.

  10. 10
    CPython vulnerability EUVD-2026-89183 disclosed with moderate severityโ–ผ๐Ÿšจ EUVD-2026-89183 ๐Ÿ“Š Score: 5.9/10 (CVSS v3.1) ๐Ÿ“ฆ Product: CPython ๐Ÿข Vendor: Python Software Foundation ๐Ÿ“… Updated: 2026-09MmastodonTechnologyCybersecurity01 d ago

    A vulnerability tracked as EUVD-2026-89183 has been disclosed in CPython, the reference implementation of the Python language maintained by the Python Software Foundation. The flaw concerns cleanup of tempfile.TemporaryDirectory, where a race condition could let an attacker who can modify the directory tree during cleanup swap in a directory in place of the intended one. It is rated 5.9 out of 10 on the CVSS v3.1 scale, a moderate severity score.

  11. 11
    ArgusMonitor Driver Vulnerability Flagged With Medium Severityโ–ผ๐Ÿšจ EUVD-2026-89424 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“… Published: 2026-09-29 | Updated: 2026-09-30 ๐Ÿ“ Improper Access Control inMmastodonTechnologyCybersecurity07 h ago

    A newly tracked vulnerability, EUVD-2026-89424, describes improper access control in the ArgusMonitor.sys driver used by Argotronic eGbR's hardware monitoring tool ArgusMonitor, affecting version 7.4.02 and earlier. With a CVSS v3.1 score of 5.3, the flaw reportedly allows local, low-privileged users to bypass device handle access restrictions. Published on 29 September and updated the next day, it is drawing attention from security watchers tracking Windows driver weaknesses.

  12. 12
    Fastify vulnerability EUVD-2026-70998 rated 7.5 publishedโ–ผ๐Ÿšจ EUVD-2026-70998 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: fastify ๐Ÿข Vendor: fastify ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ fastify vulneMmastodonTechnologyCybersecurity03 h ago

    A new vulnerability, EUVD-2026-70998, has been recorded for Fastify, the popular Node.js web framework. The flaw, rated 7.5 out of 10 on CVSS v3.1, allows a header validation bypass caused by incomplete schema case normalization. The entry in the European vulnerability database was updated on 30 September 2026. Security teams using Fastify are expected to review the advisory and check whether their deployments are affected.

  13. 13
    Critical RCE vulnerability disclosed in LightLLMโ—๐Ÿšจ CVE-2026-103040 โ€” CVSS 9.3 CRITICAL LightLLM through 1.2.0 contains a remote code execution vulnerability in the routeMmastodonTechnologyCybersecurity01 d ago

    A critical remote code execution flaw, tracked as CVE-2026-103040 with a CVSS score of 9.3, has been disclosed in LightLLM through version 1.2.0. The vulnerability sits in the router profiler service when launched with the --enable_profiling flag, which exposes an unauthenticated RPyC server with pickle deserialization enabled, letting attackers run arbitrary code. Security teams are being urged to check whether their deployments are affected.

  14. 14
    High-severity vulnerability disclosed in Capgo update serviceโ–ผ๐Ÿšจ EUVD-2026-87707 ๐Ÿ“Š Score: 8.6/10 (CVSS v3.1) ๐Ÿ“ฆ Product: capgo.app ๐Ÿข Vendor: Cap-go ๐Ÿ“… Published: 2026-09-26 | Updated: 2MmastodonTechnologyCybersecurity07 h ago

    A security advisory published as EUVD-2026-87707 describes a vulnerability in Capgo, the over-the-air update service for Capacitor apps, rated 8.6 out of 10 on the CVSS scale. Versions up to 12.261.0 reportedly contain an incomplete access-control fix for the public.sso_providers table, meaning earlier mitigation efforts did not fully close the flaw. The advisory was published on 26 September 2026 and updated on 30 September, prompting developers who rely on Capgo to check whether they need to update.

  15. 15
    Critical missing-authentication flaw reported in PTZOptics camerasโ–ผ๐Ÿšจ CVE-2026-75969 โ€” CVSS 9.1 CRITICAL Missing authentication for critical function vulnerability for all PTZOptics cameraMmastodonTechnologyCybersecurity010 h ago

    A new critical vulnerability, tracked as CVE-2026-75969 with a CVSS score of 9.1, has been disclosed affecting all PTZOptics cameras and the Firmware Upgrade Tool's Firmware Update modules. The flaw is a missing authentication issue in the firmware update mechanism, meaning critical functions could be triggered without proper credentials. Security watchers are flagging the severity and the breadth of affected devices.

  16. 16
    Themeum WordPress plugins flagged over 33 unpatched vulnerabilitiesโ–ผThemeum: 33 CVEs, max CVSS 10, and 100% unpatched. Trust score C. WordPress sites running these plugins carry real risk.MmastodonTechnologyCybersecurity116 h ago

    WordPress plugin developer Themeum is being flagged for 33 known CVEs with a maximum CVSS score of 10, all reportedly unpatched, earning the vendor a trust score of C. Security commentary warns that sites running its plugins carry real risk and urges administrators to review whether they depend on this software.

  17. 17
    Critical Kiteworks Email Gateway Flaw Tracked as CVE-2026-102149โ—๐Ÿšจ CVE-2026-102149 โ€” CVSS 9.4 CRITICAL Kiteworks Email Protection Gateway did not sufficiently restrict which account a cMmastodonTechnologyCybersecurity06 h ago

    A critical vulnerability, CVE-2026-102149, with a CVSS score of 9.4 has been disclosed in Kiteworks' Email Protection Gateway. The flaw stems from insufficient restrictions on which account a certificate could be assigned to, potentially letting an attacker associate a certificate with another user's account and compromising confidentiality. Security observers are flagging the issue and urging organizations using the gateway to review exposure and apply fixes.

  18. 18
    Fastify vulnerability EUVD-2026-70989 scores 7.5โ–ผ๐Ÿšจ EUVD-2026-70989 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: fastify ๐Ÿข Vendor: fastify ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ fastify vulneMmastodonTechnologyCybersecurity03 h ago

    A medium-high severity vulnerability, EUVD-2026-70989, has been catalogued in Fastify, the popular Node.js web framework. Rated 7.5 under CVSS v3.1, the flaw allows request validation bypass when boolean false schemas are skipped, potentially letting malformed requests through unchecked. The advisory was updated on 30 September 2026, and security teams using Fastify are being urged to review their validation logic and apply patches.

  19. 19
    Critical CVSS 9.8 flaw reported in OAuth SSO pluginโ–ผ๐Ÿšจ CVE-2026-97274 โ€” CVSS 9.8 CRITICAL Unauthenticated Bypass Vulnerability in OAuth Single Sign On โ€“ SSO (OAuth Client) ๐Ÿ”ŽMmastodonTechnologyCybersecurity014 h ago

    A critical vulnerability, CVE-2026-97274, has been disclosed in the OAuth Single Sign On โ€“ SSO (OAuth Client) plugin, carrying a CVSS score of 9.8. The flaw is described as an unauthenticated authentication bypass, meaning attackers would not need credentials to exploit it. Security communities are circulating the advisory as organisations using OAuth-based single sign-on assess their exposure.

  20. 20
    Kiteworks Email Protection Gateway vulnerability logged with moderate severityโ–ผ๐Ÿšจ EUVD-2026-90275 ๐Ÿ“Š Score: 6.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Email Protection Gateway ๐Ÿข Vendor: Kiteworks ๐Ÿ“… Updated: 2026-09MmastodonTechnologyCybersecurity07 h ago

    A new vulnerability, EUVD-2026-90275, has been recorded for Kiteworks' Email Protection Gateway, with a CVSS v3.1 score of 6.5 out of 10. The flaw concerns an authorization check in the large file exchange feature that failed to correctly verify whether the requesting user was entitled to access the resource. The entry was updated on 30 September 2026. Security teams monitoring Kiteworks deployments are expected to review the advisory and patch guidance.

  21. 21
    Critical vulnerability CVE-2026-62308 disclosed in Tugtainerโ–ผ๐Ÿšจ CVE-2026-62308 โ€” CVSS 9.1 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior tMmastodonTechnologyCybersecurity010 h ago

    A critical vulnerability, CVE-2026-62308 with a CVSS score of 9.1, has been disclosed in Tugtainer, a self-hosted application for automating Docker container updates. Versions prior to 1.30.6 allow an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs, a server-side request forgery flaw. Admins running affected versions are urged to update to 1.30.6 or later.

  22. 22
    Fastify vulnerability allows authentication bypass via malformed URLsโ–ผ๐Ÿšจ EUVD-2026-70988 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: fastify ๐Ÿข Vendor: fastify ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ fastify vulneMmastodonTechnologyCybersecurity03 h ago

    A newly catalogued vulnerability, EUVD-2026-70988, affects the Fastify web framework, rated 7.5 out of 10 on the CVSS v3.1 scale. The flaw allows authentication bypass when malformed URLs reach encapsulated not-found handlers, meaning requests intended to be blocked could slip through route protections. Fastify is a widely used Node.js framework, so developers running exposed services are being urged to review the advisory and update to a patched version.

  23. 23
    Critical flaw in Digiwin EasyFlow .NET exposes plaintext passwordsโ—๐Ÿšจ CVE-2026-102458 โ€” CVSS 9.3 CRITICAL EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. UnaMmastodonTechnologyCybersecurity018 h ago

    A critical vulnerability, CVE-2026-102458 with a CVSS score of 9.3, has been disclosed in EasyFlow .NET, enterprise software developed by Taiwanese vendor Digiwin. The flaw is a missing authentication issue: unauthenticated remote attackers can use a specific API to obtain other users' plaintext passwords. Security watchers are sharing details and urging affected organisations to review exposure and patch quickly.

  24. 24
    Kiteworks Core deserialization flaw logged as high-severity vulnerabilityโ–ผ๐Ÿšจ EUVD-2026-90276 ๐Ÿ“Š Score: 8.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: core ๐Ÿข Vendor: Kiteworks ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ Kiteworks CoreMmastodonTechnologyCybersecurity07 h ago

    Kiteworks Core versions before 9.5.0 are affected by a deserialization of untrusted data vulnerability, tracked as EUVD-2026-90276 with a CVSS v3.1 score of 8.1. Under certain conditions, the flaw could allow attackers to send crafted data that is deserialized unsafely, potentially leading to code execution. The advisory was updated on September 30, 2026, and users are advised to upgrade to version 9.5.0 or later.

  25. 25
    Security audit flags 57 vulnerabilities in Vim editorโ–ผVim: 57 CVEs, max CVSS 9.2, 52% unpatched. Top flaws: heap overflow (CWE-122), code injection (CWE-94). Plugins widen thMmastodonTechnologyCybersecurity021 h ago

    A new security analysis reports 57 CVEs in the Vim text editor, with a maximum severity score of 9.2 and roughly 52% still unpatched. The most serious flaws are heap overflows and code injection bugs, and the report warns that third-party plugins expand the attack surface. Security practitioners are urging users to audit their Vim configurations and update promptly.

  26. 26
    Critical unauthenticated PHP object injection flaw flagged in Booking Activitiesโ–ผ๐Ÿšจ CVE-2026-97248 โ€” CVSS 9.8 CRITICAL Unauthenticated PHP Object Injection in Booking Activities ๐Ÿ”Ž Details: https:// stemMmastodonTechnologyCybersecurity014 h ago

    Security researchers are warning about CVE-2026-97248, a critical vulnerability in the Booking Activities plugin rated 9.8 on the CVSS scale. The flaw is an unauthenticated PHP object injection issue, meaning remote attackers could potentially exploit it without any credentials. Details are being circulated in infosec communities as administrators are urged to check their installations and patch promptly.

  27. 27
    Critical vulnerability disclosed in Docker update tool Tugtainerโ–ผ๐Ÿšจ CVE-2026-55494 โ€” CVSS 9.8 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior tMmastodonTechnologyCybersecurity010 h ago

    A critical flaw, CVE-2026-55494 with a CVSS score of 9.8, has been disclosed in Tugtainer, a self-hosted application for automating Docker container updates. Versions before 1.30.4 expose unauthenticated access to Docker management APIs when the AGENT_SECRET setting is not configured. Self-hosting and security communities are urging users to update immediately, warning that unpatched instances could let attackers take control of containers.

  28. 28
    Microsoft patches high-severity Visual Studio heap overflow flawโ–ผ๐Ÿšจ EUVD-2026-73170 ๐Ÿ“Š Score: 8.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: .NET 10.0, Microsoft Visual Studio 2022 version 17.14, MicrosofMmastodonTechnologyCybersecurity01 d ago

    Microsoft's Visual Studio 2022 version 17.14, .NET 10.0 and .NET Framework 4.8 are affected by a vulnerability tracked as EUVD-2026-73170, rated 8.8 out of 10 on the CVSS v3.1 scale. The flaw is a heap-based buffer overflow in Visual Studio, and the advisory was published on 8 September 2026 with an update issued on 29 September 2026. Security trackers are flagging the high severity rating, urging developers using affected Microsoft products to check whether they need to update.

  29. 29
    Google Chrome patches critical memory flawโ–ผ๐Ÿšจ EUVD-2026-89143 ๐Ÿ“Š Score: 9.6/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Chrome ๐Ÿข Vendor: Google ๐Ÿ“… Published: 2026-09-29 | Updated: 2026MmastodonTechnologyCybersecurity122 h ago

    A critical vulnerability, EUVD-2026-89143, has been disclosed in Google Chrome with a CVSS score of 9.6. The flaw involves non-heap memory handling in the browser's Fonts component and could allow a remote attacker, working alongside social engineering, to potentially compromise systems. The fix is included in Chrome 154.0.8037.57, published 29 September 2026 and updated the following day. Security watchers are flagging the severity rating and urging users to update their browsers promptly.

  30. 30
    Critical CVSS 10 flaw CVE-2026-71379 allows unauthenticated data exportโ—๐Ÿšจ CVE-2026-71379 โ€” CVSS 10 CRITICAL The file export endpoint allows any unauthenticated attacker to export arbitrary datMmastodonTechnologyCybersecurity01 d ago

    A vulnerability tracked as CVE-2026-71379, rated CVSS 10, is drawing attention in the cybersecurity community. The flaw lies in a file export endpoint that lets any unauthenticated attacker export arbitrary database tables via a crafted POST request. Security feeds are flagging it as maximum-severity, urging organizations to check whether their systems are affected and patch promptly.

  31. 31
    Critical Zimbra flaw CVE-2026-73570 actively exploitedโ—๐Ÿค– CVE-2026-73570 (CVSS 8.9): unauthenticated OS command injection in Zimbra Collaboration Suite via its SNMP service, noMmastodonTechnologyCybersecurity21 h ago

    A critical vulnerability, CVE-2026-73570 with a CVSS score of 8.9, in Zimbra Collaboration Suite allowed unauthenticated attackers to run operating system commands through its SNMP service. According to Microsoft Security Research, attackers exploited the flaw to deploy web shells and steal mailbox credentials. A patch has been released, and security teams are urged to update affected servers promptly.

  32. 32
    IBM patches high-severity code execution flaw in DataStageโ–ผ๐Ÿšจ EUVD-2026-89197 ๐Ÿ“Š Score: 8.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: DataStage on Cloud Pak for Data ๐Ÿข Vendor: IBM ๐Ÿ“… Updated: 2026-0MmastodonTechnologyCybersecurity01 d ago

    A new vulnerability, tracked as EUVD-2026-89197, has been disclosed in IBM DataStage on Cloud Pak for Data 5.4.0.0. Rated 8.8 out of 10 on the CVSS v3.1 scale, the flaw could let a remote authenticated attacker execute arbitrary code because of improper path validation. Security teams monitoring IBM products are flagging the advisory as organisations assess whether their deployments are affected and await a fix.

  33. 33
    Medium-severity vulnerability found in Naichen ThinkCMFโ–ผ๐Ÿšจ EUVD-2026-89477 ๐Ÿ“Š Score: 5.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: ThinkCMF, ThinkCMF, ThinkCMF (+5 more) ๐Ÿข Vendor: Naichen ๐Ÿ“… UpdaMmastodonTechnologyCybersecurity01 d ago

    A security vulnerability, tracked as EUVD-2026-89477, has been identified in Naichen's ThinkCMF content management framework in versions up to 8.0.7. The flaw carries a CVSS v3.1 score of 5.1 out of 10, marking it as moderate severity. The advisory was updated on 29 September 2026, and multiple ThinkCMF product entries are listed as affected. Details of the vulnerable function remain limited in the published notice.

  34. 34
    Critical insecure deserialization flaw reported in Digiwin EasyFlow .NETโ—๐Ÿšจ CVE-2026-102455 โ€” CVSS 9.3 CRITICAL EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. UMmastodonTechnologyCybersecurity018 h ago

    A critical vulnerability, tracked as CVE-2026-102455 with a CVSS score of 9.3, has been reported in EasyFlow .NET, software developed by Taiwanese vendor Digiwin. According to the advisory, unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content, exploiting insecure deserialization. Organizations running the software are being urged to review the details and apply fixes promptly.

  35. 35
    High-severity vulnerability disclosed in MobilityDBโ–ผ๐Ÿšจ EUVD-2026-89198 ๐Ÿ“Š Score: 7.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: MobilityDB, MobilityDB, MobilityDB ๐Ÿข Vendor: MobilityDB ๐Ÿ“… UpdatMmastodonTechnologyCybersecurity01 d ago

    A security advisory, EUVD-2026-89198, flags an out-of-bounds read vulnerability in MobilityDB version 1.3.0 and earlier, located in the MEOS binary and library WKB deserialization logic. The flaw carries a CVSS v3.1 score of 7.1, marking it as high severity. The advisory was updated on 2026-09-29, and users of the open-source moving-object database extension are being urged to check for patched releases.

  36. 36
    High-severity command injection flaw fixed in Renovateโ–ผ๐Ÿšจ EUVD-2024-55728 ๐Ÿ“Š Score: 8.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: renovate ๐Ÿข Vendor: renovatebot ๐Ÿ“… Published: 2026-08-19 | UpdateMmastodonTechnologyCybersecurity01 d ago

    A high-severity vulnerability, EUVD-2024-55728, was published for Renovate, the popular open-source dependency update tool maintained by renovatebot. Versions 37.158.0 before 37.199.0 contain a command injection flaw in the helmv3 manager's registryAliases handling, rated 8.4 out of 10 on the CVSS v3.1 scale. Users are being urged to update to a patched release, as the bug could allow attackers to execute arbitrary commands through manipulated registry alias values.

  37. 37
    Critical unauthenticated SQL injection flaw reported in Books Galleryโ—๐Ÿšจ CVE-2026-96822 โ€” CVSS 9.3 CRITICAL Unauthenticated SQL Injection in Books Gallery ๐Ÿ”Ž Details: https:// stemshop.top/cveMmastodonTechnologyCybersecurity014 h ago

    Security researchers have flagged CVE-2026-96822, a critical vulnerability in the Books Gallery application, rated CVSS 9.3. The flaw is described as an unauthenticated SQL injection, meaning attackers need no credentials to exploit it remotely. Details and mitigation guidance are being circulated on security channels, with administrators urged to patch or isolate affected deployments quickly.

  38. 38
    Critical CVE-2026-70356 flagged in TMS file upload endpointโ—๐Ÿšจ CVE-2026-70356 โ€” CVSS 9.4 CRITICAL The TMS file upload endpoint fails to enforce server-side file type restrictions, aMmastodonTechnologyCybersecurity01 d ago

    A new critical vulnerability, CVE-2026-70356 with a CVSS score of 9.4, has been disclosed affecting a TMS file upload endpoint. The flaw allows attackers to bypass server-side file type restrictions and upload malicious PHP files that can then be executed on the web server. Security researchers are sharing details of the bug, urging administrators to review and patch affected systems.

  39. 39
    Critical Apache PLC4X vulnerability CVE-2026-102508 disclosedโ—๐Ÿšจ CVE-2026-102508 โ€” CVSS 9.2 CRITICAL Improper Verification of Cryptographic Signature and Improper Certificate ValidatiMmastodonTechnologyCybersecurity018 h ago

    A critical vulnerability, CVE-2026-102508 with a CVSS score of 9.2, has been disclosed in the OPC UA driver of Apache PLC4X (PLC4J). The flaw involves improper cryptographic signature verification and certificate validation, allowing a network attacker positioned between client and server to impersonate the OPC UA server. Security watchers are urging industrial users of the library to patch promptly.

  40. 40
    Medium-severity FTP flaw disclosed in Eclipse NetX Duoโ–ผ๐Ÿšจ EUVD-2026-89199 ๐Ÿ“Š Score: 6.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: NetX Duo ๐Ÿข Vendor: Eclipse Foundation ๐Ÿ“… Updated: 2026-09-29 ๐Ÿ“ FMmastodonTechnologyCybersecurity01 d ago

    A medium-severity vulnerability, EUVD-2026-89199, has been catalogued in Eclipse Foundation's NetX Duo embedded network stack. Rated 6.0 out of 10 under CVSS v3.1, the flaw lies in the FTP component, where passive data connections are not bound to the authenticated control peer, potentially allowing session mixing. The entry was updated on 29 September 2026 via the EU vulnerability database maintained by ENISA.