offseq@infosec.exchange
@offseq@infosec.exchange
Topics
-
⚠️ CRITICAL: CVE-2026-6271 in shahinurislam Career Section plugin (≤1.7) lets unauthenticated attackers upload dangerous files — risk of remote code execution.
Uncategorized
1
-
🚨 Fortinet & Ivanti released CRITICAL patches for RCE & info disclosure vulnerabilities, some exploitable without auth.
Uncategorized
1
-
🚨 CRITICAL: CVE-2026-32661 stack buffer overflow in Canon GUARDIANWALL MailSuite (v1.4.00 – 2.4.26).
Uncategorized
1
-
🔴 CVE-2026-8072 (CRITICAL, 9.2): Ingeteam Ingecon Sun EMS Board uses weak hashing for SAT access credentials, risking privilege escalation.
Uncategorized
1
-
🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks.
Uncategorized
1
-
HIGH severity alert: CVE-2026-8234 stack buffer overflow in EFM ipTIME A8004T (v14.18.2) — remote, unauthenticated exploit possible.
Uncategorized
1
-
🛡️ CVE-2026-7330: HIGH severity stored XSS in thedark Auto Affiliate Links (≤6.8.8) lets unauthenticated attackers inject scripts via AJAX endpoint.
Uncategorized
1
-
🛡️ CVE-2026-35428 (CRITICAL, CVSS 9.6) affects Microsoft Azure Cloud Shell via command injection (CWE-77).
Uncategorized
1
-
🚨 CRITICAL: CVE-2026-42880 in Argo CD (v3.2.0 – 3.2.10, 3.3.0 – 3.3.8) allows attackers with read-only access to extract plaintext Kubernetes Secrets via the ServerSideDiff endpoint.
Uncategorized
1
-
🔎 CVE-2026-41202: CRITICAL path traversal in ci4ms (<0.31.5.0) lets authenticated users upload ZIPs for remote code execution.
Uncategorized
1
-
-
🚨 CRITICAL: CVE-2026-42779 in Apache MINA (2.1.0 – 2.1.11 & 2.2.0 – 2.2.6) enables remote code execution via deserialization of untrusted data.
Uncategorized
1
-
⚠️ CVE-2026-5402: HIGH severity heap buffer overflow in Wireshark 4.6.0 – 4.6.4 TLS dissector.
Uncategorized
1
-
Chrome 147 & Firefox 150.0.1 ship critical security updates: use-after-free & memory corruption bugs could allow code execution or info leaks.
Uncategorized
1
-
⚠️ CRITICAL: CVE-2026-3854 lets users with push access run arbitrary code on GitHub backend servers.
Uncategorized
1
-
💥 CVE-2026-7155: CRITICAL OS command injection in Totolink A8000RU (7.1cu.643_b20200521).
Uncategorized
1
-
-
🚨 CRITICAL SQL Injection (CVE-2026-6887) in BorG SPM 2007: unauthenticated remote attackers can manipulate databases.
Uncategorized
1
-
🚨 CRITICAL RCE issue tied to Google Antigravity is attracting cybercriminals using its reputation to spread malware.
Uncategorized
1
-
🚨 HIGH severity alert: Quantum Networks QN-I-470 routers (6.1.1.B1) have a CLI OS command injection (CVE-2026-41036).
Uncategorized
1