CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.5
WIEDZA Z SIECI
Podatności
CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.5
CVE-2026-88771 · Citrix NetScaler Improper Input Validation Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 6.9
CVE-2026-67279 · Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.8
CVE-2026-65660 · Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.1
CVE-2026-87902 · WordPress Core Remote File Inclusion Vulnerability
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 10.0
CVE-2026-5430 · WSO2 Multiple Products Path Traversal Vulnerability
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.1
CVE-2026-71362 · Adobe Commerce and Magento Incorrect Authorization Vulnerability
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.5
CVE-2026-93952 · Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.3
CVE-2026-94127 · F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.8
CVE-2026-93616 · Check Point Multiple Products Path Traversal Vulnerability
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.8
CVE-2026-85102 · Check Point Multiple Products Improper Certificate Validation Vulnerability
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 8.1
CVE-2026-83621 · ntopng is a web-based network traffic monitoring application.
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList for any authenticated user. The list_name, list_enabled, url, and list_update parameters allow a non-admin user to redirect threat-intelligence downloads to attacker-controlled content, disable blocklists, or prevent scheduled updates. The changes are persisted through Redis and reloaded without a lower-level authorization guard, undermining the integrity and availability of ntopng's threat-intelligence monitoring. This issue is fixed in version 6.7.260717.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 9.9
CVE-2026-79920 · Ajenti is a Linux & BSD modular server admin panel.
Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management authorization. InstallPlugin and UnInstallPlugin construct a pip package specification from unvalidated name and version fields, and the task worker invokes pip while running as root. A low-privileged user can therefore select or manipulate a package installed with root privileges and can install, remove, or upgrade plugins without administrative permission, resulting in root code execution and full host compromise. This issue is fixed in version 2.2.16.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 6.9
CVE-2026-77582 · Tinyauth is an authentication and authorization server.
Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_controller.go loginHandler and internal/middleware/context_middleware.go basicAuth return quickly after internal/service/auth_service.go reports a missing user, while an existing user causes bcrypt password verification work. Repeated measurements can therefore disclose valid usernames and support targeted credential attacks. This issue is fixed in version 5.1.0.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 5.3
CVE-2026-77561 · Tinyauth is an authentication and authorization server.
Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a global login lockdown. internal/controller/user_controller.go loginHandler passes each attacker-controlled identifier to internal/service/auth_service.go RecordLoginAttempt, which invokes lockdownMode after the map reaches its cap. IsAccountLocked checks that global state before validating unrelated accounts, causing valid users to receive HTTP 429 until auth.loginTimeout expires, approximately 300 seconds by default. The attack can be repeated, but existing authenticated sessions are not invalidated. This issue is fixed in version 5.1.0.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 8.1
CVE-2026-77560 · Tinyauth is an authentication and authorization server.
Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to bypass per-app access controls with a differently cased hostname. The lookup in internal/service/access_controls_service.go through lookupStaticACLs and GetAccessControls, and the Docker-label fallback in internal/service/docker_service.go through GetLabels, can miss the configured app and return an empty access-control object. internal/controller/proxy_controller.go proxyHandler then treats the empty user, group, OAuth, LDAP, and IP restrictions as permissive and returns an authenticated result for an app that should exclude the user. Unauthenticated users remain subject to login, and global login-time allowlists are not bypassed. This issue is fixed in version 5.1.2.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 7.7
CVE-2026-76898 · draw.io is a configurable diagramming and whiteboarding application.
draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/online/Utils.java checks IPv6 Unique Local Addresses in Utils.sanitizeUrl() by comparing the text prefixes fc00:: and fd00::, but the JDK returns the expanded address form, so the fc00::/7 range, including the AWS metadata range fd00:ec2::/32, is not blocked. An unauthenticated request to /embed2.js?fetch= can therefore make src/main/java/com/mxgraph/online/EmbedServlet2.java fetch an IPv6 ULA internal resource and reflect the response to the requester. Utils.validatedAddress() uses the same private-address check for the separate ProxyServlet path, which requires ENABLE_DRAWIO_PROXY=1. The primary /embed2.js path requires no proxy feature flag or DNS rebinding, and it can disclose cloud metadata credentials or data from other IPv6-reachable internal services. This issue is fixed in version 30.3.8.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 3.7
CVE-2026-63416 · draw.io is a configurable diagramming and whiteboarding application.
draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/online/ExportProxyServlet.java uses request.getPathInfo() to build a proxyPath and appends it directly to EXPORT_URL without rejecting dot segments or confirming that the normalized destination remains under the configured export path. An unauthenticated request containing traversal segments can therefore address unintended routes on the internal export server, and the servlet forwards all request headers and the request body to that destination, allowing arbitrary header injection. Depending on the export service configuration, exploitation can expose administration, debugging, health, or configuration endpoints and can permit unintended internal actions. This issue is fixed in version 30.2.7.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 4.2
CVE-2026-63373 · draw.io is a configurable diagramming and whiteboarding application.
draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler in src/main/java/com/mxgraph/online/AbsAuth.java skips comparison of stateToken and cookieToken whenever IS_GAE is false, which affects self-hosted Docker and WAR deployments. An attacker can provide an authorization code for the attacker's cloud-storage identity and induce a victim to visit a callback URL, causing the victim's draw.io session to become authenticated as the attacker identity without a valid state binding. The shared handler affects Google Drive, OneDrive, GitHub, GitLab, and Dropbox integrations. The victim can then unknowingly perform cloud-storage actions under the attacker's identity, causing session integrity loss and misattribution, but the identity binding does not itself grant access to existing victim cloud files. This issue is fixed in version 30.2.7.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 6.8