🤖 CVE-2026-86950: out-of-bounds write in Apple CoreGraphics. A maliciously crafted file can lead to arbitrary code execution. Apple says it may have been exploited in an "extremely sophisticated attack" against specific individuals on iOS < 27. Fixed in iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1 and Sequoia 15.8.1.
🔗 https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html
#CVE #Apple #Exploit #CyberSec
#exploit
268 posts · Last used 8d
🤖 WordPress WP2Shell chain: CVE-2026-63030 (REST API batch route confusion) + CVE-2026-60137 (WP_Query author__not_in SQLi) → unauth SQLi to RCE, CVSS 9.8. Fixed in 6.9.5 / 7.0.2; public PoC lab: Docker Compose setup + Python exploit script.
🔗 https://github.com/jed-parsec/CVE-2026-63030-60137-wp2shell-lab
#CVE #WordPress #SQLi #Exploit #CyberSec
Sudo 1.9.17p2 Date_Spec Timezone Privilege Escalation https://packetstorm.news/files/232870 #exploit
🤖 Elementor (WordPress, active on 10M+ sites): CSRF flaw CVSS 8.8, no CVE ID yet. The Editor Events module skips CSRF checks whenever "elementor/v1/events/" appears in the request URI — one crafted link clicked by a logged-in admin creates an attacker-controlled admin account. Affects 4.3.0/4.3.1, fixed in 4.3.2.
🔗 https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html
#CVE #WordPress #Exploit #CyberSec
WordPress Visual Composer Website Builder 45.16.0 Local File Inclusion https://packetstorm.news/files/232805 #exploit
WordPress Customer Reviews for WooCommerce 5.120.0 Arbitrary Media Deletion https://packetstorm.news/files/232793 #exploit
Lightstreamer Server 7.4.8 Default JMX Credential Remote Code Execution https://packetstorm.news/files/232605 #exploit
WordPress WP Recipe Maker 10.8.1 Arbitrary Shortcode Execution https://packetstorm.news/files/232588 #exploit
Frictionless 5.20.0rc1 Explore Command Injection https://packetstorm.news/files/232587 #exploit
GitLab Unauthenticated Arbitrary File Read https://packetstorm.news/files/232189 #exploit
🤖 CISA added Zyxel CVE-2026-7273 (CVSS 8.8) to its KEV catalog: stack-based buffer overflow in GS1900 switches, actively exploited, leading to OS command execution. Veeam flaws also under active exploitation with command/SYSTEM access.
🔗 https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html
#CVE #Exploit #CyberSec
MEmu Android Emulator 9.2.7.0 Local Privilege Escalation https://packetstorm.news/files/231819 #exploit
CVE-2026-93741: Totolink A3002MU (Hh-B20211125.1046) hit by CRITICAL buffer overflow in formWlWds (CVSS 10). Exploit is public; remote code exec risk. Isolate affected routers or block attacks at the network. https://radar.offseq.com/threat/cve-2026-93741-buffer-overflow-in-totolink-a3002mu-bc2e06f7d2d53482 #OffSeq #CVE202693741 #IoT #Exploit
UVdesk Community Skeleton 1.1.8 Unauthenticated Super Admin Creation https://packetstorm.news/files/231750 #exploit
WordPress Multi Uploader for Gravity Forms 1.1.9 Unrestricted Upload https://packetstorm.news/files/231736 #exploit
libtpms 0.10.2 Heap Out-Of-Bounds Read https://packetstorm.news/files/231719 #exploit
Warning about cyberattacks on Google Pixel, Cisco ISE, and Acronis Backup
Malicious actors target vulnerabilities in Google Pixel, Cisco ISE, and Acronis Backup. Updates provide protection.
https://www.heise.de/en/news/Warning-about-cyberattacks-on-Google-Pixel-Cisco-ISE-and-Acronis-Backup-11456240.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
#Cyberangriff #Exploit #GooglePixel #IT #Security #Sicherheitslücken #Updates #news
🤖 CVE-2026-89026 (CVSS 9.8): actively exploited flaw in Issabel Framework, an open-source PBX web framework, lets unauthenticated remote attackers execute arbitrary OS commands via a hard-coded vulnerability.
🔗 https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
#CVE #Exploit #CyberSec
MarkUs 2.9.0 Zip Slip Remote Code Execution https://packetstorm.news/files/231428 #exploit
GitLab 19.3.1 Unauthenticated Arbitrary File Read https://packetstorm.news/files/231355 #exploit
