Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

ZEN SecDB

@secdb@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

ZEN #SecDB Portal is a vulnerability and security intelligence platform built to help security teams identify, prioritize, and respond to threats across their infrastructure - from a single #CVE to a full attack surface.

ZEN SecDB Portal: https://secdb.nttzen.cloud

SecDB Telegram Channel: https://t.me/secdbportal_feed
SecDB Telegram Bot: https://t.me/secdbportal_bot

21 Followers
0 Following
30 Posts
Joined September 22, 2025
Website:
https://secdb.nttzen.cloud
Advisories:
https://secdb.nttzen.cloud/security-advisory
Vulnerabilities:
https://secdb.nttzen.cloud/cve
Sightigs:
https://secdb.nttzen.cloud/sightings
Dashboard:
https://secdb.nttzen.cloud/dashboard
About:
https://secdb.nttzen.cloud/about
Open post
ZEN SecDB @secdb@infosec.exchange
· 2w ago

secdb-cli 0.5.0 🚀

Point it at a repo → discovers every manifest → known vulns as inline diagnostics + SARIF with file & line.

Plain LSP over stdio: Neovim, Kate, Zed, any LSP editor.

https://github.com/giterlizzi/secdb-cli/releases/tag/v0.5.0

#DevSecOps #golang #AppSec #OpenSource
#NTTDATA #ZEN #SecDB

github.com
2
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 4w ago

🚨 [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-75650 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: https://helpx.adobe.com/security/products/magento/apsb26-146.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-75650

⚠️ CVE-2026-81963 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81963)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-81963 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-81963

⚠️ CVE-2026-85880 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85880)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-85880 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85880

⚠️ CVE-2026-86218 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-86218)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/ ; https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-86218

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

secdb.nttzen.cloud
1
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 3mo ago
🚨 DirtyClone (CVE-2026-43503) In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/updates/9a1828d5-6607-419b-b475-622a6c135aae/dirtyclone-vulnerability #nttdata #zen #secdb #infosec #dirtyclone #linux #lpe #cve202643503
secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 3mo ago

🚨 Bad Epoll (CVE-2026-46242) has been identified as a notable vulnerability.

In the Linux kernel, the following vulnerability has been resolved:

eventpoll: fix ep_remove struct eventpoll / struct file UAF

ℹ️ Additional information on ZEN SecDB:

  • BadEpoll: https://secdb.nttzen.cloud/updates/79198418-b310-4e40-80cd-d98ba3da0b2a/bad-epoll-vulnerability

  • CVE details, sightings and advisories: https://secdb.nttzen.cloud/cve/detail/CVE-2026-46242

#InfoSec #BadEpoll #CVE202646242 #Linux #Kernel

#NTTDATA #Zen #SecDB #VulnerabilityIntelligence #Security

secdb.nttzen.cloud

Bad Epoll vulnerability - Updates | ZEN SecDB Portal

0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 3mo ago

🚨 [CISA-2026:0707] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48908 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48908)

  • Name: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: JoomShaper
  • Product: SP Page Builder
  • Notes: https://extensions.joomla.org/extension/sp-page-builder/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48908

⚠️ CVE-2026-55255 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-55255)

  • Name: Langflow Authorization Bypass Through User-Controlled Key Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Langflow
  • Product: Langflow
  • Notes: https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-55255

⚠️ CVE-2026-56290 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56290)

  • Name: Joomlack Page Builder Improper Access Control Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Joomlack
  • Product: Page Builder
  • Notes: https://www.joomlack.fr/en/joomla-extensions/page-builder-ck ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-56290

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260707 #cisa20260707 #cve_2026_48908 #cve_2026_55255 #cve_2026_56290 #cve202648908 #cve202655255 #cve202656290

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago

🚨 [CISA-2026:0710] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-48939 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48939)

  • Name: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: iCagenda
  • Product: iCagenda
  • Notes: https://www.icagenda.com/#download ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48939

⚠️ CVE-2026-56291 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)

  • Name: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Balbooa
  • Product: Forms
  • Notes: https://www.balbooa.com/joomla-forms ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-56291

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260710 #cisa20260710 #cve_2026_48939 #cve_2026_56291 #cve202648939 #cve202656291

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago

📈 CVE Published in last days (2026-07-06 - 2026-07-06) See more at https://secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:

  • Critical: 137
  • High: 558
  • Medium: 580
  • Low: 131
  • None: 157

Status:

  • : 92
  • Analyzed: 371
  • Awaiting Analysis: 94
  • Deferred: 632
  • Modified: 5
  • Received: 230
  • Rejected: 12
  • Undergoing Analysis: 127

CISA KEVs:

  • CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
  • CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)

Top CNAs:

  • GitHub, Inc.: 452
  • Wordfence: 178
  • VulnCheck: 138
  • VulDB: 94
  • N/A: 92
  • MITRE: 58
  • Apache Software Foundation: 56
  • Drupal.org: 46
  • Foxit: 28
  • Chrome: 27

Top Affected Products:

  • UNKNOWN: 1134
  • Apache Camel: 34
  • Foxit Pdf Reader: 28
  • Foxit Pdf Editor: 28
  • Google Chrome: 27
  • Coder: 20
  • Openwebui Open Webui: 15
  • Joomla!: 12
  • N8n: 12
  • Wireshark: 12

Top EPSS Score:

  • CVE-2026-43825 - 8.79 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-43825)
  • CVE-2026-44454 - 2.64 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-44454)
  • CVE-2026-34038 - 2.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34038)
  • CVE-2025-30007 - 2.08 % (https://secdb.nttzen.cloud/cve/detail/CVE-2025-30007)
  • CVE-2026-60102 - 1.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60102)
  • CVE-2026-33264 - 1.65 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-33264)
  • CVE-2026-40047 - 1.57 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-40047)
  • CVE-2026-48316 - 1.40 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48316)
  • CVE-2026-34599 - 1.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34599)
  • CVE-2026-59800 - 1.37 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59800)

#ZEN #SecDB #InfoSec

secdb.nttzen.cloud

Security Dashboard | ZEN SecDB Portal

0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago

🚨 [CISA-2026:0715] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2023-4346 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-4346)

  • Name: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: KNX Association
  • Product: KNX Protocol Connection Authorization Option 1
  • Notes: https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-4346

⚠️ CVE-2026-46817 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-46817)

  • Name: Oracle E-Business Suite Improper Privilege Management Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Oracle
  • Product: E-Business Suite
  • Notes: https://www.oracle.com/security-alerts/cspumay2026.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-46817

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260715 #cisa20260715 #cve_2023_4346 #cve_2026_46817 #cve20234346 #cve202646817

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago

🚨 [CISA-2026:0721] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2021-27137 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-27137)

  • Name: DD-WRT Stack-Based Buffer Overflow Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: DD-WRT
  • Product: DD-WRT
  • Notes: This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://svn.dd-wrt.com/changeset/45724 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-27137

⚠️ CVE-2026-0770 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-0770)

  • Name: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Langflow
  • Product: Langflow
  • Notes: https://github.com/langflow-ai/langflow/releases/tag/v1.9.0 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-0770

⚠️ CVE-2026-60137 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)

  • Name: WordPress Core SQL Injection Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: WordPress
  • Product: Core
  • Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-60137

⚠️ CVE-2026-63030 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)

  • Name: WordPress Core Interpretation Conflict Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: WordPress
  • Product: Core
  • Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-63030

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260721 #cisa20260721 #cve_2021_27137 #cve_2026_0770 #cve_2026_60137 #cve_2026_63030 #cve202127137 #cve20260770 #cve202660137 #cve202663030

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago

🚨 [CISA-2026:0722] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-16232 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)

  • Name: Check Point SmartConsole Improper Authentication Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Check Point
  • Product: SmartConsole
  • Notes: https://support.checkpoint.com/results/sk/sk185169/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-16232

⚠️ CVE-2026-50522 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)

  • Name: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Microsoft
  • Product: SharePoint
  • Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-50522

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260722 #cisa20260722 #cve_2026_16232 #cve_2026_50522 #cve202616232 #cve202650522

secdb.nttzen.cloud
0
0
1
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago
🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability. In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access. ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/1d26eb14-ce27-4846-a8ce-bae087fb1e46/refluxfs-vulnerability #infosec #refluxfs #linux #kernel #xfs #lpe #nttdata #zen #secdb
secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2mo ago

🚨 [CISA-2026:0727] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-68686 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-68686)

  • Name: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
  • Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Known To Be Used in Ransomware Campaigns? Unknown
  • Vendor: Fortinet
  • Product: FortiOS
  • Notes: https://fortiguard.fortinet.com/psirt/FG-IR-25-934 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-68686

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260727 #cisa20260727 #cve_2025_68686 #cve202568686

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 6d ago

📈 CVE Published in last 30 days (2026-09-01 - 2026-09-01)
See more at https://secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1417
- High: 5956
- Medium: 4625
- Low: 927
- None: 1743

Status:
- : 93
- Analyzed: 3418
- Awaiting Analysis: 2780
- Deferred: 5097
- Modified: 128
- Received: 2835
- Rejected: 130
- Undergoing Analysis: 187

CISA KEVs:
- CISA-2026:0902 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
- CISA-2026:0904 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)
- CISA-2026:0921 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0921)
- CISA-2026:0922 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0922)
- CISA-2026:0924 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0924)
- CISA-2026:0925 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0925)
- CISA-2026:0927 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0927)
- CISA-2026:0929 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0929)
- CISA-2026:0930 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0930)

Top CNAs:
- kernel.org: 2117
- VulnCheck: 1638
- GitHub, Inc.: 1424
- Microsoft Corporation: 1000
- VulDB: 900
- Oracle: 634
- WPScan: 552
- MITRE: 497
- Chrome: 467
- Wordfence: 408

Top Affected Products:
- UNKNOWN: 11109
- Microsoft Windows Server 2025: 648
- Microsoft Windows Server 2022: 611
- Microsoft Windows 11 24h2: 600
- Microsoft Windows 11 26h1: 600
- Microsoft Windows 11 25h2: 599
- Microsoft Windows Server 2019: 586
- Microsoft Windows 10 1809: 582
- Microsoft Windows 11 23h2: 574
- Microsoft Windows 10 21h2: 541

Top EPSS Score:
- CVE-2026-85706 - 91.43 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85706)
- CVE-2026-85046 - 48.88 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85046)
- CVE-2026-76461 - 28.27 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76461)
- CVE-2026-87902 - 19.76 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-87902)
- CVE-2026-93616 - 19.65 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-93616)
- CVE-2026-76460 - 14.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76460)
- CVE-2026-86218 - 12.93 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-86218)
- CVE-2026-83549 - 10.76 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83549)
- CVE-2026-83548 - 8.76 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83548)
- CVE-2026-85102 - 7.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85102)

#ZEN #SecDB #InfoSec

secdb.nttzen.cloud

Security Dashboard | ZEN SecDB Portal

0
0
1
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 1w ago

🚨 [CISA-2026:0930] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0930)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-76504 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76504)
- Name: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Catalyst SD-WAN Manager
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-76504

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260930 #cisa20260930 #cve_2026_76504 #cve202676504

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 1w ago

🚨 [CISA-2026:0929] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0929)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-86950 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-86950)
- Name: Apple Multiple Products Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apple
- Product: Multiple Products
- Notes: https://support.apple.com/en-us/149226 ; https://support.apple.com/en-us/149228 ; https://support.apple.com/en-us/149229 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-86950

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260929 #cisa20260929 #cve_2026_86950 #cve202686950

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 1w ago

📈 CVE Published in last 7 days (2026-09-21 - 2026-09-21)
See more at https://secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1006
- Medium: 862
- Low: 165
- None: 705

Status:
- : 140
- Analyzed: 78
- Awaiting Analysis: 583
- Deferred: 892
- Received: 1124
- Rejected: 46
- Undergoing Analysis: 99

CISA KEVs:
- CISA-2026:0921 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0921)
- CISA-2026:0922 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0922)
- CISA-2026:0924 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0924)
- CISA-2026:0925 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0925)
- CISA-2026:0927 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0927)

Top CNAs:
- kernel.org: 607
- GitHub, Inc.: 480
- VulnCheck: 400
- VulDB: 153
- N/A: 140
- MITRE: 125
- WPScan: 121
- IBM Corporation: 101
- Wordfence: 88
- Red Hat, Inc.: 78

Top Affected Products:
- UNKNOWN: 2747
- Adobe Campaign: 17
- Zohocorp Manageengine Opmanager: 11
- Rti Connext Professional: 11
- Adobe Connect: 9
- Adobe Connect for Mobile: 9
- Jishenghua Jsherp: 9
- Dell Policy Manager for Secure Connect Gateway: 8
- Altera Trusted Firmware: 7
- Adobe Bridge: 7

Top EPSS Score:
- CVE-2026-93616 - 19.65 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-93616)
- CVE-2026-87902 - 18.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-87902)
- CVE-2026-74849 - 4.61 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-74849)
- CVE-2026-76978 - 3.72 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76978)
- CVE-2026-15027 - 3.16 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15027)
- CVE-2026-43641 - 3.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-43641)
- CVE-2026-94097 - 2.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-94097)
- CVE-2026-19599 - 2.86 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19599)
- CVE-2026-85542 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85542)
- CVE-2026-94098 - 2.38 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-94098)

#ZEN #SecDB #InfoSec

secdb.nttzen.cloud

Security Dashboard | ZEN SecDB Portal

0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 1w ago

🚨 [CISA-2026:0927] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0927)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-88771 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-88771)
- Name: Citrix NetScaler Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778 ; https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 ; https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-88772

⚠️ CVE-2026-88772 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-88772)
- Name: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: Running the provided IOCs in the NetScaler console may help identify indicators of exploitation. Customers must conduct forensic triage as directed by BOD 26‑04 and follow Citrix’s published guidance for mitigations. For more information, please see: https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778 ; https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 ; https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-88772

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260927 #cisa20260927 #cve_2026_88771 #cve_2026_88772 #cve202688771 #cve202688772

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 1w ago

🚨 [CISA-2026:0925] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0925)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-65660 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65660)
- Name: Microsoft SharePoint Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SharePoint
- Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-65660

⚠️ CVE-2026-67279 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-67279)
- Name: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: https://mikrotik.com/supportsec/september-2026-vulnerability/?utm_source=chatgpt.com ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-67279

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260925 #cisa20260925 #cve_2026_65660 #cve_2026_67279 #cve202665660 #cve202667279

secdb.nttzen.cloud
0
0
1
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 1w ago

🚨 [CISA-2026:0924] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0924)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-5430 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5430)
- Name: WSO2 Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WSO2
- Product: Multiple Products
- Notes: https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/ ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-5430

⚠️ CVE-2026-71362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-71362)
- Name: Adobe Commerce and Magento Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: https://helpx.adobe.com/security/products/magento/apsb26-92.html ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-71362

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260924 #cisa20260924 #cve_2026_5430 #cve_2026_71362 #cve20265430 #cve202671362

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2w ago

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0922)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85102)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: https://support.checkpoint.com/results/sk/sk1000117 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85102

⚠️ CVE-2026-93616 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-93616)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: https://support.checkpoint.com/results/sk/sk1000171/ ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-93616

⚠️ CVE-2026-93952 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-93952)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-93952

⚠️ CVE-2026-94127 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-94127)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: https://my.f5.com/manage/s/article/K000162605 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-94127

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2w ago

🚨 [CISA-2026:0921] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0921)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-7273 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-7273)
- Name: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Zyxel
- Product: GS1900 Series Switches
- Notes: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-7273

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260921 #cisa20260921 #cve_2026_7273 #cve20267273

secdb.nttzen.cloud
0
0
1
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2w ago

📈 CVE Published in last 7 days (2026-09-14 - 2026-09-14)
See more at https://secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 478
- High: 2067
- Medium: 1314
- Low: 307
- None: 680

Status:
- : 35
- Analyzed: 339
- Awaiting Analysis: 1126
- Deferred: 1117
- Modified: 32
- Received: 1943
- Rejected: 28
- Undergoing Analysis: 226

CISA KEVs:
- CISA-2026:0914 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)
- CISA-2026:0916 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)
- CISA-2026:0918 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)

Top CNAs:
- kernel.org: 878
- Oracle: 634
- GitHub, Inc.: 587
- VulnCheck: 434
- Apple Inc.: 246
- VulDB: 243
- IBM Corporation: 174
- WPScan: 151
- Wordfence: 128
- MITRE: 106

Top Affected Products:
- UNKNOWN: 3691
- Apple Macos: 214
- Apple Iphone Os: 132
- Apple Ipados: 132
- Apple Visionos: 95
- Apple Watchos: 81
- Apple Tvos: 78
- Oracle Hyperion Financial Management: 70
- Google Android: 47
- Google Chrome: 46

Top EPSS Score:
- CVE-2026-76698 - 4.11 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76698)
- CVE-2026-89308 - 2.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89308)
- CVE-2026-90702 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90702)
- CVE-2026-90703 - 2.80 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90703)
- CVE-2026-92398 - 2.47 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92398)
- CVE-2026-92397 - 2.30 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-92397)
- CVE-2026-27560 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27560)
- CVE-2026-27561 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27561)
- CVE-2026-27562 - 2.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27562)
- CVE-2026-90847 - 2.18 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-90847)

#ZEN #SecDB #InfoSec

secdb.nttzen.cloud

Security Dashboard | ZEN SecDB Portal

0
0
1
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 2w ago

🚨 [CISA-2026:0918] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0918)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-39964 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-39964)
- Name: Linux Kernel Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce; https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9; https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8; https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84; https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d; https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042; https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-39964

⚠️ CVE-2026-53266 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53266)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87; https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b; https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0; https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b; https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093; https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d; https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5; https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53266

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260918 #cisa20260918 #cve_2025_39964 #cve_2026_53266 #cve202539964 #cve202653266

secdb.nttzen.cloud
0
0
1
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 3w ago

🚨 [CISA-2026:0916] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0916)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-58704 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-58704)
- Name: Google Pixel Improper Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Pixel
- Notes: https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-58704

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260916 #cisa20260916 #cve_2026_58704 #cve202658704

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 3w ago

🚨 ZcopyReaper (CVE-2026-43502) has been identified as a notable vulnerability.

In the Linux kernel, the following vulnerability has been resolved:

net/rds: handle zerocopy send cleanup before the message is queued

A zerocopy send can fail after user pages have been pinned but before
the message is attached to the sending socket.

The purge path currently infers zerocopy state from rm->m_rs, so an
unqueued message can be cleaned up as if it owned normal payload pages.
However, zerocopy ownership is really determined by the presence of
op_mmp_znotifier, regardless of whether the message has reached the
socket queue.

Capture op_mmp_znotifier up front in rds_message_purge() and use it as
the cleanup discriminator. If the message is already associated with a
socket, keep the existing completion path. Otherwise, drop the pinned
page accounting directly and release the notifier before putting the
payload pages.

This keeps early send failure cleanup consistent with the zerocopy
lifetime rules without changing the normal queued completion path.

ℹ️ Additional information on ZEN SecDB 👉 https://secdb.nttzen.cloud/cve/detail/CVE-2026-43502

#Infosec #ZcopyReaper #Linux #Kernel #LPE #CVE202643502
#NTTData #ZEN #SecDB

secdb.nttzen.cloud
0
0
1
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 3w ago

🚨 [CISA-2026:0914] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0914)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-76461 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-76461)
- Name: Cisco Secure Email Gateway SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Email Gateway
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-76461

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260914 #cisa20260914 #cve_2026_76461 #cve202676461

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 3w ago

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at https://secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0908)
- CISA-2026:0909 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)
- CISA-2026:0910 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)
- CISA-2026:0911 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81467)
- CVE-2026-17176 - 3.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17176)
- CVE-2026-79697 - 3.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-79697)
- CVE-2026-78488 - 3.25 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-78488)
- CVE-2026-65638 - 3.20 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65638)
- CVE-2026-89010 - 2.85 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-89010)
- CVE-2026-81468 - 2.28 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-81468)
- CVE-2026-12744 - 2.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12744)
- CVE-2026-75650 - 2.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-75650)
- CVE-2026-12745 - 2.09 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-12745)

#ZEN #SecDB #InfoSec

secdb.nttzen.cloud

Security Dashboard | ZEN SecDB Portal

0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 3w ago

🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0911)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-42016 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42016)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016

⚠️ CVE-2026-42018 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-42018)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42018

⚠️ CVE-2026-84869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-84869)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-84869

⚠️ CVE-2026-85706 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85706)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85706

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706

secdb.nttzen.cloud
0
0
0
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 3w ago

🚨 [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0910)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-67277 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-67277)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: https://mikrotik.com/supportsec/september-2026-vulnerability/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-67277

⚠️ CVE-2026-86060 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-86060)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-86060

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260910 #cisa20260910 #cve_2026_67277 #cve_2026_86060 #cve202667277 #cve202686060

secdb.nttzen.cloud
0
0
1
0
Open post
ZEN SecDB @secdb@infosec.exchange
· 3w ago

🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0909)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-25249 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-25249)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: https://fortiguard.fortinet.com/psirt/FG-IR-25-084 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-25249

⚠️ CVE-2026-19490 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-19490)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-19490

⚠️ CVE-2026-20079 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20079)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20079

⚠️ CVE-2026-87491 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-87491)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-87491

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

secdb.nttzen.cloud
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 19:54:33 UTC