CVE-2026-47367 and other: Improper Input Validation vulnerabilities in Ubiquiti UniFi OS, 9.9 rating ๐ฅ
Several improper input validation and other weaknesses allow low-privileged attacker to execute command injection and possible to compromise network.
๐https://t.co/RJD7WXY1tY
CVE-2026-47759 - CVE-2026-47762: Four XSS vulnerabilities in TinyMCE, 8.7 rating ๐ฅ
Four recently disclosed Cross-Site Scripting (XSS) vulnerabilities allow remote attacker to inject malicious scripts into web pages.
๐ https://t.co/yisWM0nWHt
CVE-2026-44494: Full Man-in-the-Middle via Prototype Pollution Gadget in Axios, 8.7 rating ๐ฅ
The Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows an attacker intercept, read, and modify all outgoing HTTP requests including authentication credentials.
๐ https://t.co/H9coZmNucE
๐ Attackers no longer need custom malware.
Legitimate Remote Monitoring & Management (RMM) tools like AnyDesk, ScreenConnect, TeamViewer, Atera, and others are increasingly being weaponized for initial access, persistence, and ransomware operations.
https://t.co/e8Ibb9Wfo4
CVE-2026-47783 & CVE-2026-47784: Two SASL vulnerabilities in Memcached, 8.1 rating ๐ฅ
Two new vulnerabilities Memcached allow an attacker to enumerate valid usernames on the system and guess their passwords because password and username data for SASL password database authentication has a timing side channel.
๐ https://t.co/OE9j7NlJFj
CVE-2026-34908, CVE-2026-34909 & CVE-2026-34910: Vulnerabilities in Ubiquiti UniFi OS, 10.0 rating ๐ฅ๐ฅ๐ฅ
Three new vulnerabilities in Ubiquiti UniFi OS allow an network attacker to make unauthorized changes, access files and execute arbitrary command. It may cause to full device compromise.
๐ https://t.co/N82DoduEXg
CVE-2026-46354: Token theft in Coder, 9.1 rating ๐ฅ
New vulnerability in Coder allows an attacker on any Azure VM to steal an agent session token, and with the stolen token get access to Git SSH private key, OAuth access tokens or workspace secrets.
๐ https://t.co/xMMA6BKw9w
Totally new 0-day RCE vulnerability in NGINX. Again ๐ฑ
New zero-day RCE vulnerability named nginx-poolslip targets the latest mainline release 1.31.0.
๐ https://t.co/nfPduafrOE
Introducing nginx-poolslip, a fresh RCE for the the latest nginx release 1.31.0.
nginx-rift has been patched, but our security agent Vega has found a new 0 day.
We will release the full technical writeup with ASLR bypass 30 days after the patch on https://t.co/LAhOC5UHrp.
Discovering Data Exposure with Netlas
A practical walkthrough of how security researchers can use Netlas to identify exposed / leaked sensitive data.
โ Methods for finding leaked data
โ Common exposure patterns
โ Real-world search techniques
https://t.co/gTbBP8o1SC
๐ Netlas v1.8 is live
Private Scanner now supports Scanner Locations!
Run scans from different countries to see infrastructure from multiple geographic perspectives.
๐ Details: https://t.co/sWhzQlFYO4
CVE-2026-44789, CVE-2026-44790 & CVE-2026-44791: 3 new vulnerabilities in n8n, 9.4 rating ๐ฅ
Recently disclosed vulnerabilities in n8n allow an attacker to read arbitrary files from the server, achieve global prototype pollution and bypass the patch for previous vulnerability (CVE-2026-42232).
๐ https://t.co/msIU7eVNWK
CVE-2026-42945: 18-Year-Old vulnerability in NGINX, 9.2 rating ๐ฅ
Heap buffer overflow vulnerability in NGINX Plus and NGINX Open Source allows an unauthenticated attacker to lead NGINX worker process to restart by sending crafted HTTP requests. Additionally, in some cases code execution is possible. This vulnerability is already being actively exploited in the wild!
๐ https://t.co/MfEG7oaIx2
CVE-2026-42897: Microsoft Exchange Server spoofing vulnerability, 8.1 rating ๐ฅ
New spoofing vulnerability in on-premise Microsoft Exchange Server hits OWA and allows an unauthorized attacker to execute malicious code by sending a specially crafted email to a user. This vulnerability is already being actively exploited in the wild!
๐ https://t.co/5PCkSgE4XD
CVE-2026-44194 & CVE-2026-45158: Two RCE vulnerabilities in OPNsense, 9.1 rating ๐ฅ
Two vulnerabilities in OPNsense allows an authenticated attacker to execute arbitrary code as root on the firewall host via User management system (CVE-2026-44194) and DHCP Config (CVE-2026-45158). PoC already available!
๐ https://t.co/oPPTESLZry
CVE-2026-43640: Missing authentication in JetBrains TeamCity, 8.2 rating ๐ฅ
Vulnerability in JetBrains TeamCity allows an authenticated user to expose server API to unauthorized access.
๐ https://t.co/81wssJHGuu
CVE-2026-29202 & CVE-2026-29203: Two vulnerabilities in cPanel, 8.8 rating ๐ฅ
The first vulnerability in cPanel allows an attacker to execute arbitrary commands directly on the server via Perl injection (CVE-2026-29202). The second one (CVE-2026-29203) leads to denial of service and possible privilege escalation.
๐ https://t.co/MAR942W9Yy
CVE-2026-23870: DoS in React Server Components, 7.5 rating ๐ฅ
DoS vulnerability in React Server Components allows an attacker to disable the web application by exhausting server resources. This vulnerability requires a specific architectural setup to be exploited.
๐ https://t.co/iNBWmQ5i4t