Cyber Security
Live feeds from CISA Known Exploited Vulnerabilities, NVD CVE database, and Hacker News security stream.
CISA KEV — Known Exploited Vulnerabilities
- ExploitedCISA KEV • 16h ago
CVE-2026-53266 — Linux Kernel: Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
- ExploitedCISA KEV • 16h ago
CVE-2025-39964 — Linux Kernel: Linux Kernel Race Condition Vulnerability
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
- ExploitedCISA KEV • 2d ago
CVE-2026-87886 — Acronis Backup: Acronis Backup Incorrect Default Permissions Vulnerability
Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
- ExploitedCISA KEV • 2d ago
CVE-2026-76460 — Cisco Identity Services Engine: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
- ExploitedCISA KEV • 2d ago
CVE-2026-58704 — Google Pixel: Google Pixel Improper Authorization Vulnerability
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
- ExploitedCISA KEV • 4d ago
CVE-2026-76461 — Cisco Secure Email Gateway: Cisco Secure Email Gateway SQL Injection Vulnerability
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
- ExploitedCISA KEV • 7d ago
CVE-2026-85706 — GitLab Community Edition and Enterprise Edition: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
- ExploitedCISA KEV • 7d ago
CVE-2026-42018 — JFrog Artifactory: JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
- ExploitedCISA KEV • 7d ago
CVE-2026-42016 — JFrog Artifactory: JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
- ExploitedCISA KEV • 7d ago
CVE-2026-84869 — ConnectWise ScreenConnect: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.
- ExploitedCISA KEV • 8d ago
CVE-2026-67277 — MikroTik RouterOS: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
- ExploitedCISA KEV • 8d ago
CVE-2026-86060 — MikroTik RouterOS: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation.
- ExploitedCISA KEV • 9d ago
CVE-2026-20079 — Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
- ExploitedCISA KEV • 9d ago
CVE-2026-87491 — Google Chromium V8: Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
- ExploitedCISA KEV • 9d ago
CVE-2025-25249 — Fortinet Multiple Products: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
- ExploitedCISA KEV • 9d ago
CVE-2026-19490 — Citrix NetScaler: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.
- ExploitedCISA KEV • 10d ago
CVE-2026-85880 — Microsoft Windows: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
- ExploitedCISA KEV • 10d ago
CVE-2026-86218 — N-able N-central: N-able N-central Static Code Injection Vulnerability
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
- ExploitedCISA KEV • 10d ago
CVE-2026-81963 — Microsoft Windows: Microsoft Windows Link Following Vulnerability
Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
- ExploitedCISA KEV • 10d ago
CVE-2026-75650 — Adobe Commerce and Magento: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
- ExploitedCISA KEV • 14d ago
CVE-2026-85046 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
- ExploitedCISA KEV • 16d ago
CVE-2026-83549 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
- ExploitedCISA KEV • 16d ago
CVE-2026-83548 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
- ExploitedCISA KEV • 16d ago
CVE-2026-9586 — Sangoma Switchvox: Sangoma Switchvox SQL Injection Vulnerability
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Hacker News — Security Stream
No stories.
GitHub Security Advisories — Latest
- CVE-2026-77608GitHub Advisory • 6m ago
Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)
#### Failure mode The `value` parameter was reflected back into rendered output and error messaging paths without enough output-context encoding. #### Remediation - The form value is escaped before it is placed back i
- CVE-2026-77606GitHub Advisory • 8m ago
Semantic MediaWiki has reflected XSS in Special:Ask plain table headers
#### Failure mode When `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. User-controlled `mainlabel` content could therefore become executable HTML. #### Remediation - `TableResultPrinter
- CVE-2025-61682GitHub Advisory • 42m ago
Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes
### Summary The SemanticMediaWiki extension inserts the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. ### Details In `ext.smw.js`, the `data-subtab` attribute of
- CVE-2025-53837GitHub Advisory • 1h ago
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
### Impact Any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write
- CVE-2026-77615GitHub Advisory • 3h ago
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text
## Summary The Opencast Paella player renders caption cue text into `innerHTML` without escaping. The captions canvas clears `_captionsContainer.innerHTML` and then appends each active cue with `_captionsContainer.inner
- CVE-2026-77281GitHub Advisory • 3h ago
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
# Caddy v2.11.3 — Three vulnerabilities in handler/placeholder layer **Tested against:** `caddy:2.11.3` (official Docker image, SHA verified at runtime) **Reproduction environment:** Docker Desktop 4.73.1 / Engine 29.4.
- CVE-2026-72819GitHub Advisory • 20h ago
Grav CMS vulnerable to remote code execution via .zip file upload
### Summary A logged-in user can run any command on the server. A settings field can fill itself by calling one of Grav's built-in routines, and a safety check is supposed to allow only harmless ones. The check only rec
- CVE-2026-75837GitHub Advisory • 20h ago
Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
## Summary The core Flex group blueprint `system/blueprints/user/group.yaml` (access field, lines 48-55) omits the `security@: admin.super` field guard that its sibling account blueprint carries (`account.yaml:131/138/15
- CVE-2026-75834GitHub Advisory • 20h ago
Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate
## Vulnerability Details **Component**: getgrav/grav core **File**: `system/src/Grav/Common/Security.php` **Function**: `detectXss()` (all six entries in the `$patterns` array use the PCRE `u` modifier), invoked from `G
- CVE-2026-75827GitHub Advisory • 20h ago
Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write
## Affected versions and vulnerable location - Confirmed on grav core at `78ebfc1` (tag 2.0.13). - Sinks: - `system/src/Grav/Common/Data/Blueprint.php:455-458` `call_user_func_array($o, $params)` (bare-function dynami
- CVE-2026-75828GitHub Advisory • 20h ago
Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
## Affected versions and vulnerable location - Confirmed on grav core at `78ebfc1` (tag 2.0.13). - Detector: `system/src/Grav/Common/Security.php:290`, the `on_events` regex, run via `patternMatches()` (`:315-330`). - T
- CVE-2026-74907GitHub Advisory • 20h ago
Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
**Verified against:** `getgrav/grav` devel branch, `GRAV_VERSION = "2.0.15"`, file `index.php ## Title Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`
- CVE-2026-72695GitHub Advisory • 20h ago
Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
# Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion ## Summary A path traversal vulnerability in `MediaUploadTrait::deleteFile()` allows an authenticated user with media management permiss
- CVE-2026-86003GitHub Advisory • 20h ago
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
### Summary CoreDNS accepted [RFC 2136](https://datatracker.ietf.org/doc/html/rfc2136) UPDATE messages over DoH, DoH3, DoQ, and DNS-over-gRPC, then allowed the `proxy`/`forward` plugin to send them unchanged to an upstr
- CVE-2026-86000GitHub Advisory • 20h ago
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
## Summary soupsieve compiles CSS selector strings with a set of hand-written regular expressions. The shared `IDENTIFIER` sub-pattern (also embedded in `VALUE`, and therefore in attribute selectors) places two adjacent