cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-09-11

    CVE-2026-85706: Unauthenticated CVSS 10 Path Traversal in GitLab's Commits API Under Active Probing

    A maximum-severity, unauthenticated path traversal in GitLab's repository commits API lets attackers read arbitrary server files; CISA added it to KEV and honeypots logged probing within hours of the patch.

    active-exploitationcisa-kevpath-traversalauthentication-bypasscicdrce
  • vulnerabilities 2026-09-10

    cPanel CVE-2026-67401: EmailTrack SQL Injection Lets Mail Users Reach Root

    A SQL injection in cPanel & WHM's EmailTrack feature lets any account with mail privileges write arbitrary files and execute code as root — CVSS 9.9, every supported version affected.

    cpanelsql-injectionprivilege-escalationrceshared-hosting
  • vulnerabilities 2026-09-09

    N-able Ships Fourth N-central Hotfix in Five Weeks After CVE-2026-86218 Pre-Auth RCE Hits Production

    CVE-2026-86218, a maximum-severity static code injection flaw in N-able's N-central RMM platform, let unauthenticated attackers run arbitrary code on the server — and CISA confirms it was already exploited before the patch shipped.

    active-exploitationcisa-kevnetwork-appliancecloudprivilege-escalation
  • vulnerabilities 2026-09-09

    Microsoft's September Patch Tuesday Sets a New Record: ~970 Flaws, Two Zero-Days Actively Exploited

    Microsoft's largest Patch Tuesday ever ships fixes for roughly 970 CVEs, including two zero-days already under active attack in the Windows Update Stack and ALPC, plus a trio of CVSS 10.0 cloud-identity bugs in Azure AD B2C, Azure AI Language, and Copilot Studio.

    microsoftpatch-tuesdayzero-dayactive-exploitationprivilege-escalationcloud
  • vulnerabilities 2026-09-08

    MikroTrick: Chained MikroTik RouterOS SSH Bugs Give Unauthenticated Root, 122,500 Devices Exposed

    CERT Polska's MikroTrick chain (CVE-2026-67276 + CVE-2026-86060) lets attackers bypass SSH authentication and escalate to full admin on MikroTik RouterOS — exploited in the wild since September 2, before patches shipped.

    active-exploitationauthentication-bypassnetwork-appliancezero-dayprivilege-escalation
  • vulnerabilities 2026-09-08

    Dell Secure Connect Gateway: Five Chained Flaws Take an Unauthenticated Request to Root

    Dell patched five chainable flaws in Secure Connect Gateway, including a token-replay auth bypass and a Docker-socket privilege escalation, that together let an unauthenticated network attacker reach root on the host.

    authentication-bypassprivilege-escalationcontainer-escapercenetwork-appliance
  • vulnerabilities 2026-09-07

    Two Critical Command Injection Flaws in Advantech WISE-6610 Industrial Gateways (CVE-2026-79697, CVE-2026-79698)

    Two CVSS 9.9 command injection bugs in Advantech's WISE-6610 cellular IoT gateway let an attacker with access to the admin web UI run arbitrary OS commands as root, with public exploit code already circulating.

    command-injectionnetwork-applianceiotot-securitycritical-infrastructure
  • vulnerabilities 2026-09-07

    StyleSmuggler: Unpatched Magento/Adobe Commerce Zero-Day Gives Unauthenticated RCE, No Fix Yet

    Sansec disclosed StyleSmuggler, an unauthenticated remote code execution chain hitting all current Magento and Adobe Commerce builds, under active attack since September 4 with no CVE and no patch.

    zero-dayrceactive-exploitationsupply-chainauthentication-bypass
  • vulnerabilities 2026-09-06

    CVE-2026-9586: Unauthenticated SQLi-to-RCE in Sangoma Switchvox Under Active Exploitation

    An unauthenticated SQL injection in Sangoma Switchvox's phone-provisioning endpoint escalates to root command execution and is now being used in the wild to plant reverse shells on internet-exposed VoIP servers.

    active-exploitationcisa-kevnetwork-appliancecommand-injectionzero-day
  • deep dive 2026-09-06 11 min read

    The WannaCry Bugs Never Left: Windows' Core Network Stack Just Had Its Worst Year Since EternalBlue

    Netlogon, DNS Client, DHCP Server, DNS Server — four unauthenticated, network-reachable, CVSS-9.8-class memory corruption bugs in Windows' core infrastructure services in five months. This is not four unlucky patch cycles. It's a pattern, and most vulnerability-management programs are triaging it wrong.

    windowsactive-directorypatch-tuesdayrcevulnerability-managementtrend-analysis
  • vulnerabilities 2026-09-06

    PostGREShell (CVE-2026-6471): A 12-Year-Old PostgreSQL Flaw Turns Replication Access Into Root RCE

    A missing-authorization bug in PostgreSQL logical decoding, present since version 9.4 in 2014, lets any account with REPLICATION privilege load an arbitrary library and execute code as the database server's OS user.

    rceprivilege-escalationcloudlinux
  • vulnerabilities 2026-09-05

    Cisco Nexus 9000 CVE-2026-20212: Unauthenticated Root RCE on Silicon One Data Center Switches

    A CVSS 9.8 flaw lets unauthenticated attackers execute code as root on Cisco Nexus 9000 switches with Silicon One ASICs by reaching two hard-coded, unrestricted TCP ports.

    cisconetwork-appliancercecisa-kevcritical-infrastructure
  • vulnerabilities 2026-09-05

    CVE-2026-49869: Kestra OSS Auth-Bypass Lets Unauthenticated Attackers Get Root RCE, CISA Sets Today as Federal Deadline

    A suffix-match flaw in Kestra OSS's AuthenticationFilter lets anyone skip Basic Auth entirely and reach unauthenticated remote code execution as root, CVSS 10.0, now on CISA's KEV list.

    cveauthentication-bypassrcecisa-kevactive-exploitationprivilege-escalation
  • vulnerabilities 2026-09-04

    HPE Aruba AOS-CX: Two Independent Unauthenticated RCE Paths in the Same Switch OS (CVE-2026-73749, CVE-2026-73782)

    HPE's September security bulletin for ArubaOS-CX patches 24 flaws, including two unrelated bugs that each let an unauthenticated attacker fully compromise a switch with a single crafted packet.

    rcenetwork-appliancebuffer-overflowcritical-infrastructure
  • vulnerabilities 2026-09-04

    FalconFlank: Unpatched Local Privilege Escalation Zero-Day in CrowdStrike Falcon Sensor, PoC Public

    A public PoC dubbed FalconFlank abuses CrowdStrike Falcon Sensor's malicious-macro remediation to escalate a local user to SYSTEM on fully patched Windows 11 and Server 2025. No CVE, no vendor fix yet — only a workaround.

    zero-dayprivilege-escalationwindowsendpoint-securityactive-exploitation
  • vulnerabilities 2026-09-03

    CVE-2026-83548 & CVE-2026-83549: SonicWall SMA1000 Hit by Third Zero-Day Chain of 2026, CVSS 10.0 SSRF to Root RCE

    SonicWall SMA1000 appliances are under active exploitation via a chained SSRF and OS command injection pair, CVE-2026-83548 and CVE-2026-83549, the product line's third zero-day incident this year.

    active-exploitationcisa-kevnetwork-appliancevpnzero-dayssrf
  • vulnerabilities 2026-09-02

    CVE-2026-82329: Critical JFrog Artifactory Auth Bypass Under Active Exploitation for Admin Tokens

    Attackers are exploiting CVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, to mint themselves administrator tokens and enumerate credentials on internet-facing build-artifact repositories.

    active-exploitationauthentication-bypasssupply-chaincloudcisa-kev
  • vulnerabilities 2026-09-02

    CVE-2026-0768: Unauthenticated Root RCE in Langflow's Validate Endpoint Under Mass Exploitation

    CVE-2026-0768, an unauthenticated code-injection RCE in Langflow's custom component validator, is under active mass exploitation — VulnCheck honeypots logged 360 attacks since August 29 hunting for AWS and OpenAI keys.

    active-exploitationrceai-infrastructurecredential-theftzero-day
  • vulnerabilities 2026-09-01

    Rhysida Breaches Berlin State Government Network, Claims 5.79 TB Including Water-Infrastructure Vulnerability Data

    Rhysida claims 5.79 TB and 1.44 million files from Berlin's state government network, including water-supply vulnerability assessments and plaintext credentials, after a week-long gap between detection and network isolation.

    ransomwaredouble-extortiondata-breachgovernmentnetwork-segmentation
  • vulnerabilities 2026-09-01

    Fire Ant Expands From VMware Hypervisors to Cisco IOS XR Routers and TACACS Servers

    China-nexus actor Fire Ant has moved beyond VMware ESXi hosts to implant Cisco IOS XR routers and TACACS+ authentication servers, using purpose-built tooling to hijack GRE tunnels, hide commands from admins, and intercept credentials at the network's control plane.

    aptnetwork-appliancelinuxcredential-theftciscochina-nexus
← newer1234567891011121314151617181920older →
© 2026 Max Clinton rss