MikeTrendsTrends right now

search

CVSS

Trends

  1. 1
    Oracle PeopleSoft flaw mass-exploited by ShinyHuntersโ—๐Ÿค– Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8, unauthenticated RCE) is being mass-exploited again by ShinyHunters. AttackMmastodonTechnologyCybersecurity26 d ago

    Attackers are mass-exploiting a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, rated CVSS 9.8 as an unauthenticated remote code execution flaw. The ShinyHunters group is reportedly using URL-encoding tricks to bypass WAF rules before deploying web shells. Google has warned of global targeting across multiple sectors, and renewed exploitation waves are drawing fresh attention from security teams.

  2. 2
    Citrix patches two actively exploited NetScaler zero-daysโ—๐Ÿšจ CVE-2026-88771 & CVE-2026-88772: Citrix has patched two exploited NetScaler zero-days (CVSS 9.5). Update to 14.1-73.37MmastodonTechnologyCybersecurity26 d ago

    Citrix has released fixes for two NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated critical at CVSS 9.5 and both reportedly already exploited in the wild. Administrators are urged to update to NetScaler 14.1-73.37 or 13.1-64.23 and to check their systems for signs of compromise. Security teams worldwide are discussing the patch as urgent.

  3. 3
    D-Link DIR-895L routers hit by unpatched critical flawโ–ผD-Link DIR-895L routers hit by CVE-2026-100740, a CVSS 9.9 vulnerability. No patch coming: the series reached end-of-lifMmastodonTechnologyCybersecurity15 d ago

    A critical vulnerability, CVE-2026-100740 with a CVSS score of 9.9, has been reported in D-Link DIR-895L routers. The company will not release a fix because the product line reached end-of-life in 2019. Security watchers are warning that affected devices remain exposed, with no vendor support available, and are urging users of the model to consider replacement or mitigation.

  4. 4
    Critical Capacitor vulnerability CVE-2026-103922 rated CVSS 9.3โ—Critical Capacitor vulnerability CVE-2026-103922 (CVSS 9.3) affects a package with 5.5M weekly downloads. Update to a paMmastodonTechnologyMobile21 d ago

    A critical vulnerability tracked as CVE-2026-103922, with a CVSS score of 9.3, has been disclosed in Capacitor, the Ionic framework package with around 5.5 million weekly downloads used to build Android and iOS apps. Security researchers urge developers to update to a patched release immediately, warning that affected apps could be at serious risk until remediated.

  5. 5
    Cross-site scripting flaw found in Greek Open eClass platformโ–ผ๐Ÿšจ EUVD-2024-55777 ๐Ÿ“Š Score: 5.4/10 (CVSS v3.1) ๐Ÿ“… Published: 2026-09-29 | Updated: 2026-09-30 ๐Ÿ“ Cross Site Scripting vulneMmastodonTechnologyCybersecurity03 d ago

    A cross-site scripting vulnerability, tracked as EUVD-2024-55777, has been disclosed in the Greek Universities Network (GUnet) Open eClass Platform version 3.15. The flaw, rated 5.4 out of 10 on the CVSS v3.1 scale, could let a remote attacker execute arbitrary code through user name fields. The advisory was published on 29 September and updated the following day.

  6. 6
    Three unpatched critical flaws disclosed in LightLLMโ–ผ๐Ÿšจ LightLLM Mass Disclosure โ€” 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) โ€” unauthenticated RCE, router profiler RPyC CVEMmastodonTechnologyAI43 d ago

    Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.

  7. 7
    Medium-severity vulnerability flagged in Burst Statistics WordPress pluginโ–ผ๐Ÿšจ EUVD-2026-91950 ๐Ÿ“Š Score: 4.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Burst Statistics โ€“ Simple WordPress Analytics (Google AnalyticsMmastodonTechnologyCybersecurity014 h ago

    A new vulnerability listing, EUVD-2026-91950, has been published for the Burst Statistics WordPress analytics plugin by vendor burstbv, an alternative to Google Analytics. The flaw carries a CVSS v3.1 score of 4.3 out of 10, indicating moderate severity. Administrators running the plugin on WordPress sites are advised to check for updates and patch promptly.

  8. 8
    Critical LightLLM flaw exposes AI servers to remote code executionโ—๐Ÿšจ CVE-2026-103041 โ€” CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cacheMmastodonTechnologyCybersecurity03 d ago

    A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.

  9. 9
    WordPress app builder plugin hit by stored XSS flawโ–ผ๐Ÿšจ EUVD-2026-91951 ๐Ÿ“Š Score: 5.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: WPMobile.App โ€“ Android and iOS App Builder ๐Ÿข Vendor: amauric ๐Ÿ“…MmastodonTechnologyCybersecurity014 h ago

    A medium-severity vulnerability, tracked as EUVD-2026-91951 with a CVSS score of 5.4, has been disclosed in the WPMobile.App โ€“ Android and iOS App Builder WordPress plugin by vendor amauric. The flaw is a stored cross-site scripting issue reachable via the REQUEST_URI parameter, meaning attackers could inject malicious scripts that persist and run in visitors' browsers. Administrators running the plugin are advised to check for an updated version.

  10. 10
    OpenTelemetry JavaScript instrumentation libraries flagged in new vulnerability advisoryโ–ผ๐Ÿšจ EUVD-2026-91788 ๐Ÿ“Š Score: 5.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: instrumentation-cassandra-driver, instrumentation-pg, instrumenMmastodonTechnologyCybersecurity01 d ago

    A medium-severity vulnerability, EUVD-2026-91788, has been catalogued affecting several OpenTelemetry JavaScript Contrib instrumentation packages, including instrumentation-cassandra-driver, instrumentation-pg and instrumentation-tedious. The flaw carries a CVSS v3.1 score of 5.8 out of 10 and was updated on 2 October 2026. Security teams monitoring dependencies in Node.js applications are likely reviewing whether their projects use the affected OpenTelemetry packages.

  11. 11
    Newly published flaw hits AVEZ Electronics learning platformโ–ผ๐Ÿšจ EUVD-2026-91567 ๐Ÿ“Š Score: 6.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Learning Management System (LMS) ๐Ÿข Vendor: AVEZ Electronics ComMmastodonTechnologyCybersecurity01 d ago

    A medium-severity missing authorization vulnerability, tracked as EUVD-2026-91567 and scored 6.5 out of 10 under CVSS v3.1, has been published for the Learning Management System from Turkish vendor AVEZ Electronics Communication Training and Consultancy Trade Inc. The advisory was updated on 2 October 2026. Missing authorization flaws can let users perform actions without proper permissions, so administrators of the LMS are being urged to review the advisory and apply any available fixes.

  12. 12
    Kilo Code vulnerability lets local attackers run codeโ–ผ๐Ÿšจ EUVD-2026-89423 ๐Ÿ“Š Score: 8.4/10 (CVSS v3.1) ๐Ÿ“… Published: 2026-09-29 | Updated: 2026-09-30 ๐Ÿ“ An issue in Kilo Code befoMmastodonTechnologyCybersecurity03 d ago

    A high-severity flaw tracked as EUVD-2026-89423 affects Kilo Code versions before v7.4.1, scoring 8.4 out of 10 under CVSS v3.1. The issue, published on 29 September 2026 and updated a day later, allows a local attacker to execute arbitrary code through the permission or allow-everything endpoint. Users are urged to update to v7.4.1 or later.

  13. 13
    WPC Product Options plugin hit by stored XSS flawโ–ผ๐Ÿšจ EUVD-2026-91952 ๐Ÿ“Š Score: 7.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: WPC Product Options for WooCommerce ๐Ÿข Vendor: WPClever ๐Ÿ“… UpdateMmastodonTechnologyCybersecurity014 h ago

    A stored cross-site scripting vulnerability, tracked as EUVD-2026-91952 and rated 7.2 out of 10 on the CVSS v3.1 scale, has been disclosed in the WPC Product Options for WooCommerce WordPress plugin from vendor WPClever. The flaw involves injection through wpcpo-* array keys submitted via multipart requests, meaning attackers could persist malicious scripts on product pages and target site visitors or administrators. The advisory record was updated on 3 October 2026.

  14. 14
    Low-severity directory traversal flaw patched in Trivy scannerโ–ผ๐Ÿšจ EUVD-2026-91789 ๐Ÿ“Š Score: 2.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: trivy ๐Ÿข Vendor: aquasec ๐Ÿ“… Updated: 2026-10-02 ๐Ÿ“ Trivy before 0.MmastodonTechnologyCybersecurity01 d ago

    A new vulnerability listing, EUVD-2026-91789, describes a directory traversal issue in Aqua Security's Trivy vulnerability scanner. Versions before 0.71.0 allow path traversal in Terraform filesystem functions that access pathnames above the scan root, with risk arising in misconfiguration scanning. The flaw carries a CVSS v3.1 score of 2.5, indicating low severity, and the advisory was updated on 2 October 2026. Users are advised to upgrade to 0.71.0 or later.

  15. 15
    High-severity infinite loop flaw reported in Apache Thrift Python bindingsโ–ผ๐Ÿšจ EUVD-2026-91568 ๐Ÿ“Š Score: 8.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Thrift ๐Ÿข Vendor: Apache Software Foundation ๐Ÿ“… Updated: 2MmastodonTechnologyCybersecurity01 d ago

    A vulnerability tracked as EUVD-2026-91568 has been disclosed in Apache Thrift, the Apache Software Foundation's cross-language RPC framework. The flaw, an infinite loop with an unreachable exit condition in the Python bindings, carries a CVSS v3.1 score of 8.2. Details on affected versions remain incomplete pending an update from the vendor.

  16. 16
    High-severity SQL injection flaw reported in UTMStackโ–ผ๐Ÿšจ EUVD-2026-91790 ๐Ÿ“Š Score: 8.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: UTMStack ๐Ÿข Vendor: UTMStack ๐Ÿ“… Updated: 2026-10-02 ๐Ÿ“ UTMStack beMmastodonTechnologyCybersecurity01 d ago

    A newly catalogued vulnerability, EUVD-2026-91790, affects UTMStack versions before 11.2.16. The flaw is a SQL injection in the UtmAssetGroupService.searchQueryBuilder() component, allowing authenticated attackers to inject arbitrary SQL commands. The issue carries a CVSS v3.1 severity score of 8.7 out of 10, placing it in the high-severity range. The advisory record was updated on 2 October 2026, and users are expected to patch to version 11.2.16 or later.

  17. 17
    New vulnerability disclosed in Dynamic Web Lab Team Manager pluginโ–ผ๐Ÿšจ EUVD-2025-30618 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Team Manager ๐Ÿข Vendor: Dynamic Web Lab ๐Ÿ“… Published: 2025-09-22MmastodonTechnologyCybersecurity01 d ago

    A medium-severity vulnerability, tracked as EUVD-2025-30618, was published on 22 September 2025 affecting the Team Manager plugin for WordPress by vendor Dynamic Web Lab. The flaw, scored 5.3 out of 10 under CVSS v3.1, is a missing authorization issue that could let attackers exploit incorrectly configured access controls. An update to the entry was recorded on 2 October 2026.

  18. 18
    Two memory flaws found in CTranslate2 inference engineโ–ผ๐Ÿšจ CTranslate2 CVE-2026-102566 & CVE-2026-102567 The inference engine behind Whisper & OpenNMT has two memory flaws in itMmastodonTechnologyCybersecurity13 d ago

    Security researchers have disclosed two vulnerabilities in CTranslate2, the machine learning inference engine used by Whisper and OpenNMT. CVE-2026-102566, rated CVSS 7.8, is a heap buffer overflow in the model loader that could allow arbitrary code execution, while CVE-2026-102567, rated 6.1, is an out-of-bounds read enabling memory disclosure or crashes. Developers running speech recognition or translation services are being urged to patch.

  19. 19
    High-severity vulnerability disclosed in Apache Thrift Lua bindingsโ–ผ๐Ÿšจ EUVD-2026-91569 ๐Ÿ“Š Score: 8.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Thrift ๐Ÿข Vendor: Apache Software Foundation ๐Ÿ“… Updated: 2MmastodonTechnologyCybersecurity01 d ago

    A high-severity vulnerability, EUVD-2026-91569, has been catalogued affecting the Lua bindings of Apache Thrift, the cross-language RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.2 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling combined with inefficient algorithmic complexity, which could allow denial-of-service conditions. The advisory was updated on 2 October 2026.

  20. 20
    RaspAP hit with three unpatched CVE disclosuresโ–ผ๐Ÿšจ RaspAP Mass Disclosure โ€” 3 CVEs, no patch CVE-2026-101860 (CVSS 8.8) โ€” privilege escalation via sudoers manipulation โ†’MmastodonTechnologyCybersecurity24 d ago

    Security researchers have disclosed three vulnerabilities in RaspAP, the popular router software for Raspberry Pi, with no patches available. The most severe, CVE-2026-101860 with a CVSS score of 8.8, allows privilege escalation to root via sudoers manipulation. Two further flaws, CVE-2026-101859 (5.4) and CVE-2026-101858 (4.7), involve OS command injection, including through the OpenVPN handler and WiFiManager SSID handling.

  21. 21
    High-severity SQL injection flaw reported in HAVELSAN Sef chatbotโ–ผ๐Ÿšจ EUVD-2026-91329 ๐Ÿ“Š Score: 8.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Sef - AI Chatbot Platform ๐Ÿข Vendor: Havelsan Inc. ๐Ÿ“… Updated: 20MmastodonTechnologyCybersecurity01 d ago

    A SQL injection vulnerability, tracked as EUVD-2026-91329, has been disclosed in the Sef AI Chatbot Platform developed by Turkish defence and IT company HAVELSAN. The flaw carries a CVSS v3.1 score of 8.8, placing it in the high-severity range. SQL injection bugs of this kind can let attackers manipulate database queries, potentially exposing or altering sensitive data.

  22. 22
    GitLab patches critical CVSS 9.9 AI Gateway vulnerabilityโ—๐Ÿšจ GitLab AI Gateway vulnerability: CVE-2026-90970 GitLab has patched a critical **CVSS 9.9** vulnerability in its AI GatMmastodonTechnologyCybersecurity19 h ago

    GitLab has patched a critical vulnerability, CVE-2026-90970, rated CVSS 9.9, in its AI Gateway. The flaw allows an authenticated attacker to escape the prompt-template sandbox and execute arbitrary commands on self-hosted deployments. Security professionals are urging administrators to apply the update quickly and check whether their installations are affected.

  23. 23
    GitLab patches critical AI Gateway flaw allowing command executionโ—๐Ÿค– GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform accessMmastodonTechnologyCybersecurity118 h ago

    GitLab has released fixes for CVE-2026-90970, a critical vulnerability (CVSS 9.9) in its AI Gateway. An authenticated user with access to the Duo Agent Platform can run commands on the gateway. Only self-hosted gateway deployments are affected. Patches are available in versions 19.2.4, 19.3.2 and 19.4.1, and administrators are urged to update immediately.

  24. 24
    CPython vulnerability EUVD-2026-89183 disclosed with moderate severityโ–ผ๐Ÿšจ EUVD-2026-89183 ๐Ÿ“Š Score: 5.9/10 (CVSS v3.1) ๐Ÿ“ฆ Product: CPython ๐Ÿข Vendor: Python Software Foundation ๐Ÿ“… Updated: 2026-09MmastodonTechnologyCybersecurity04 d ago

    A vulnerability tracked as EUVD-2026-89183 has been disclosed in CPython, the reference implementation of the Python language maintained by the Python Software Foundation. The flaw concerns cleanup of tempfile.TemporaryDirectory, where a race condition could let an attacker who can modify the directory tree during cleanup swap in a directory in place of the intended one. It is rated 5.9 out of 10 on the CVSS v3.1 scale, a moderate severity score.

  25. 25
    YesWiki hit by nine vulnerabilities including SQL injection flawโ—๐Ÿšจ YesWiki 9 CVEs โ€” CVE-2026-104457 (CVSS 8.6) unauthenticated SQL injection dumps admin password hashes. No login requirMmastodonTechnologyCybersecurity19 h ago

    Nine security vulnerabilities have been disclosed in YesWiki, a French open-source wiki platform. The most severe, CVE-2026-104457 with a CVSS score of 8.6, is an unauthenticated SQL injection that can dump administrator password hashes without any login. Other reported flaws include three SSRF issues, blind and second-order SQL injection, CSRF and page overwrite. Fixes are available in YesWiki 4.6.7, and users are urged to patch immediately.

  26. 26
    Medium-Severity Flaw Reported in FluentForm WordPress Pluginโ–ผ๐Ÿšจ EUVD-2026-90761 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: FluentForm ๐Ÿข Vendor: WP ManageNinja LLC ๐Ÿ“… Updated: 2026-10-01 ๐Ÿ“MmastodonTechnologyCybersecurity02 d ago

    A vulnerability tracked as EUVD-2026-90761 has been published affecting FluentForm, the WordPress form plugin by WP ManageNinja LLC. The issue is classified as an Incorrect Behavior Order flaw with a CVSS v3.1 score of 5.3 out of 10, and can reportedly allow removal of important client functionality. Details were updated on 1 October 2026. Administrators running FluentForm are likely to check whether their installed version is affected and apply any available patch.

  27. 27
    ArgusMonitor Driver Vulnerability Flagged With Medium Severityโ–ผ๐Ÿšจ EUVD-2026-89424 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“… Published: 2026-09-29 | Updated: 2026-09-30 ๐Ÿ“ Improper Access Control inMmastodonTechnologyCybersecurity03 d ago

    A newly tracked vulnerability, EUVD-2026-89424, describes improper access control in the ArgusMonitor.sys driver used by Argotronic eGbR's hardware monitoring tool ArgusMonitor, affecting version 7.4.02 and earlier. With a CVSS v3.1 score of 5.3, the flaw reportedly allows local, low-privileged users to bypass device handle access restrictions. Published on 29 September and updated the next day, it is drawing attention from security watchers tracking Windows driver weaknesses.

  28. 28
    High-severity unquoted service path flaw reported in Remote Mouseโ—๐Ÿšจ EUVD-2026-3018 ๐Ÿ“Š Score: 8.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Remote Mouse ๐Ÿข Vendor: Remotemouse ๐Ÿ“… Published: 2026-01-15 | UpdMmastodonTechnologyCybersecurity02 d ago

    A vulnerability tracked as EUVD-2026-3018 has been published for Remote Mouse, the remote-control app by vendor Remotemouse. Version 4.002 contains an unquoted service path vulnerability, rated 8.5 out of 10 on the CVSS v3.1 scale, which can let a local attacker execute arbitrary code with elevated privileges. The entry was published on 15 January 2026 and updated on 1 October 2026. Users are advised to watch for a patched release from the vendor.

  29. 29
    High-severity XML flaw flagged in Apache Camel Quarkusโ–ผ๐Ÿšจ EUVD-2026-90762 ๐Ÿ“Š Score: 8.6/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Camel Quarkus, Apache Camel Quarkus ๐Ÿข Vendor: Apache SofMmastodonTechnologyCybersecurity02 d ago

    A vulnerability tracked as EUVD-2026-90762 has been recorded for Apache Camel Quarkus, the Apache Software Foundation's Quarkus extensions for Camel. The flaw, rated 8.6 out of 10 under CVSS v3.1, involves improper restriction of XML external entity references in the XSLT support extension (camel-quarkus-support-xalan). Such issues can allow attackers to read files or make requests from affected systems. The record was updated on 1 October 2026, and security teams are being urged to check whether their deployments use the affected extension.

  30. 30
    Fastify vulnerability EUVD-2026-70998 rated 7.5 publishedโ–ผ๐Ÿšจ EUVD-2026-70998 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: fastify ๐Ÿข Vendor: fastify ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ fastify vulneMmastodonTechnologyCybersecurity02 d ago

    A new vulnerability, EUVD-2026-70998, has been recorded for Fastify, the popular Node.js web framework. The flaw, rated 7.5 out of 10 on CVSS v3.1, allows a header validation bypass caused by incomplete schema case normalization. The entry in the European vulnerability database was updated on 30 September 2026. Security teams using Fastify are expected to review the advisory and check whether their deployments are affected.

  31. 31
    Critical RCE vulnerability disclosed in LightLLMโ—๐Ÿšจ CVE-2026-103040 โ€” CVSS 9.3 CRITICAL LightLLM through 1.2.0 contains a remote code execution vulnerability in the routeMmastodonTechnologyCybersecurity03 d ago

    A critical remote code execution flaw, tracked as CVE-2026-103040 with a CVSS score of 9.3, has been disclosed in LightLLM through version 1.2.0. The vulnerability sits in the router profiler service when launched with the --enable_profiling flag, which exposes an unauthenticated RPyC server with pickle deserialization enabled, letting attackers run arbitrary code. Security teams are being urged to check whether their deployments are affected.

  32. 32
    Dell patches two CVSS 10.0 flaws in Kubernetes storage softwareโ—๐Ÿค– Dell patches two max-severity (CVSS 10.0) flaws in Container Storage Modules (CSM) Authorization v2.4.0, which connectMmastodonTechnologyCybersecurity11 d ago

    Dell has released Container Storage Modules Authorization v2.4.0 to fix two maximum-severity flaws, both rated CVSS 10.0, in the software that connects Dell storage arrays to Kubernetes clusters. The bugs stem from missing authentication, allowing unauthenticated remote attackers to retrieve backend admin credentials across all tenants. Security teams running Dell storage with Kubernetes are urged to update immediately, as the flaws expose sensitive credentials without requiring valid accounts.

  33. 33
    High-severity vulnerability disclosed in Capgo update serviceโ–ผ๐Ÿšจ EUVD-2026-87707 ๐Ÿ“Š Score: 8.6/10 (CVSS v3.1) ๐Ÿ“ฆ Product: capgo.app ๐Ÿข Vendor: Cap-go ๐Ÿ“… Published: 2026-09-26 | Updated: 2MmastodonTechnologyCybersecurity03 d ago

    A security advisory published as EUVD-2026-87707 describes a vulnerability in Capgo, the over-the-air update service for Capacitor apps, rated 8.6 out of 10 on the CVSS scale. Versions up to 12.261.0 reportedly contain an incomplete access-control fix for the public.sso_providers table, meaning earlier mitigation efforts did not fully close the flaw. The advisory was published on 26 September 2026 and updated on 30 September, prompting developers who rely on Capgo to check whether they need to update.

  34. 34
    New security vulnerability disclosed in Red Hat Enterprise Linux productsโ–ผ๐Ÿšจ EUVD-2023-24169 ๐Ÿ“Š Score: 7.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat VMmastodonTechnologyCybersecurity02 d ago

    A vulnerability tracked as EUVD-2023-24169 has been published affecting several Red Hat products, including Red Hat Enterprise Linux 8.6 and 8.8 Extended Update Support and Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. The flaw carries a CVSS v3.1 severity score of 7.0 out of 10, placing it in the high-severity range. Administrators running the affected versions are being advised to review the advisory and apply patches.

  35. 35
    Critical missing-authentication flaw reported in PTZOptics camerasโ–ผ๐Ÿšจ CVE-2026-75969 โ€” CVSS 9.1 CRITICAL Missing authentication for critical function vulnerability for all PTZOptics cameraMmastodonTechnologyCybersecurity03 d ago

    A new critical vulnerability, tracked as CVE-2026-75969 with a CVSS score of 9.1, has been disclosed affecting all PTZOptics cameras and the Firmware Upgrade Tool's Firmware Update modules. The flaw is a missing authentication issue in the firmware update mechanism, meaning critical functions could be triggered without proper credentials. Security watchers are flagging the severity and the breadth of affected devices.

  36. 36
    Themeum WordPress plugins flagged over 33 unpatched vulnerabilitiesโ–ผThemeum: 33 CVEs, max CVSS 10, and 100% unpatched. Trust score C. WordPress sites running these plugins carry real risk.MmastodonTechnologyCybersecurity13 d ago

    WordPress plugin developer Themeum is being flagged for 33 known CVEs with a maximum CVSS score of 10, all reportedly unpatched, earning the vendor a trust score of C. Security commentary warns that sites running its plugins carry real risk and urges administrators to review whether they depend on this software.

  37. 37
    Critical Kiteworks Email Gateway Flaw Tracked as CVE-2026-102149โ—๐Ÿšจ CVE-2026-102149 โ€” CVSS 9.4 CRITICAL Kiteworks Email Protection Gateway did not sufficiently restrict which account a cMmastodonTechnologyCybersecurity03 d ago

    A critical vulnerability, CVE-2026-102149, with a CVSS score of 9.4 has been disclosed in Kiteworks' Email Protection Gateway. The flaw stems from insufficient restrictions on which account a certificate could be assigned to, potentially letting an attacker associate a certificate with another user's account and compromising confidentiality. Security observers are flagging the issue and urging organizations using the gateway to review exposure and apply fixes.

  38. 38
    Fastify vulnerability EUVD-2026-70989 scores 7.5โ–ผ๐Ÿšจ EUVD-2026-70989 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: fastify ๐Ÿข Vendor: fastify ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ fastify vulneMmastodonTechnologyCybersecurity02 d ago

    A medium-high severity vulnerability, EUVD-2026-70989, has been catalogued in Fastify, the popular Node.js web framework. Rated 7.5 under CVSS v3.1, the flaw allows request validation bypass when boolean false schemas are skipped, potentially letting malformed requests through unchecked. The advisory was updated on 30 September 2026, and security teams using Fastify are being urged to review their validation logic and apply patches.

  39. 39
    Critical vulnerability flagged in CISA's Malcolm network toolโ—๐Ÿšจ EUVD-2026-76738 ๐Ÿ“Š Score: 9.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Malcolm ๐Ÿข Vendor: CISA ๐Ÿ“… Published: 2026-09-11 | Updated: 2026-MmastodonTechnologyCybersecurity01 d ago

    A high-severity vulnerability, EUVD-2026-76738, has been published for Malcolm, the open-source network traffic analysis toolkit distributed by CISA. The flaw, scored 9.2 out of 10 on the CVSS v3.1 scale, stems from an example environment-configuration file for a bundled inventory-management component that ships with a fixed, publicly known administrative password. The advisory was published on 11 September 2026 and updated on 2 October 2026.

  40. 40
    Critical CVSS 9.8 flaw reported in OAuth SSO pluginโ–ผ๐Ÿšจ CVE-2026-97274 โ€” CVSS 9.8 CRITICAL Unauthenticated Bypass Vulnerability in OAuth Single Sign On โ€“ SSO (OAuth Client) ๐Ÿ”ŽMmastodonTechnologyCybersecurity03 d ago

    A critical vulnerability, CVE-2026-97274, has been disclosed in the OAuth Single Sign On โ€“ SSO (OAuth Client) plugin, carrying a CVSS score of 9.8. The flaw is described as an unauthenticated authentication bypass, meaning attackers would not need credentials to exploit it. Security communities are circulating the advisory as organisations using OAuth-based single sign-on assess their exposure.