| medium |
CVE-2026-16046 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on wr… |
vulnerability |
nvd |
CVE-2026-16046 |
ransomware |
2026-08-17 |
| medium |
CVE-2026-16045 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauth… |
vulnerability |
nvd |
CVE-2026-16045 |
|
2026-08-17 |
| medium |
CVE-2026-16044 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving… |
vulnerability |
nvd |
CVE-2026-16044 |
|
2026-08-17 |
| medium |
CVE-2026-15754 — Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint f… |
vulnerability |
nvd |
CVE-2026-15754 |
|
2026-08-17 |
| unknown |
CVE-2026-13202 — A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue a… |
vulnerability |
nvd |
CVE-2026-13202 |
|
2026-08-17 |
| medium |
CVE-2026-10527 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile Schem… |
vulnerability |
nvd |
CVE-2026-10527 |
|
2026-08-17 |
| critical |
Projextor: Abusing Electron in Trojanized Productivity Applications |
threat-intel |
otx |
e7bc36c7345b3894…, b648ec0880e9f542… |
javascript execution, trojanized software, impersonation websites, desktop capture, projextor, productivity applications, tamperedchef, electron framework |
2026-08-17 |
| critical |
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2 |
threat-intel |
otx |
45.158.196.184, 45.158.196.23 | 20675a659c338f72… |
github c2, backdoor, clickfix, oyster, initial access broker, lactrodectus, rust-based, dll sideloading, c2looper, ransomware, botnet |
2026-08-17 |
| medium |
Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor |
threat-intel |
otx |
38.60.244.141 | daeac66441b88ba2…, b9622eb982f7c8b9… |
vhd file, quic protocol, cloudflare workers, china-nexus, quicagent, operation quicsilver, go backdoor, myanmar diplomats, botnet |
2026-08-17 |
| medium |
CVE-2026-59911 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into L… |
vulnerability |
nvd |
CVE-2026-59911 |
|
2026-08-17 |
| high |
CVE-2026-56685 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elemen… |
vulnerability |
nvd |
CVE-2026-56685, CVE-2026-56686, CVE-2026-59910 |
|
2026-08-17 |
| high |
CVE-2026-56090 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerab… |
vulnerability |
nvd |
CVE-2026-56090 |
|
2026-08-17 |
| high |
CVE-2026-56089 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privil… |
vulnerability |
nvd |
CVE-2026-56089, CVE-2026-59909 |
|
2026-08-17 |
| high |
CVE-2026-19693 — extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and nev… |
vulnerability |
nvd |
CVE-2026-19693 |
|
2026-08-17 |
| high |
CVE-2026-16471 — Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Fun… |
vulnerability |
nvd |
CVE-2026-16471 |
|
2026-08-17 |
| high |
CVE-2026-16139 — In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zon… |
vulnerability |
nvd |
CVE-2026-16139 |
rce |
2026-08-17 |
| high |
CVE-2026-16138 — In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of… |
vulnerability |
nvd |
CVE-2026-16138 |
|
2026-08-17 |
| high |
CVE-2026-16137 — In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credential… |
vulnerability |
nvd |
CVE-2026-16137 |
|
2026-08-17 |
| high |
CVE-2026-15218 — A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. Th… |
vulnerability |
nvd |
CVE-2026-15218 |
rce |
2026-08-17 |
| critical |
CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| unknown |
CVE-2026-62886 .NET Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-17 |
| unknown |
CVE-2026-58612 PowerShell Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-17 |
| critical |
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| critical |
CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| critical |
CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| critical |
CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| unknown |
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover |
news |
general-news |
|
|
2026-08-17 |
| critical |
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More |
news |
general-news |
|
zeroday, supply-chain |
2026-08-17 |
| medium |
CVE-2026-75010 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin… |
vulnerability |
nvd |
CVE-2026-75010 |
|
2026-08-17 |
| medium |
CVE-2026-75007 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to inj… |
vulnerability |
nvd |
CVE-2026-75007 |
|
2026-08-17 |
| medium |
CVE-2026-75006 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS)… |
vulnerability |
nvd |
CVE-2026-75006 |
|
2026-08-17 |
| medium |
CVE-2026-75004 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to… |
vulnerability |
nvd |
CVE-2026-75004 |
|
2026-08-17 |
| medium |
CVE-2026-75003 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute… |
vulnerability |
nvd |
CVE-2026-75003 |
|
2026-08-17 |
| high |
CVE-2026-75002 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desyn… |
vulnerability |
nvd |
CVE-2026-75002 |
|
2026-08-17 |
| medium |
CVE-2026-75000 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG… |
vulnerability |
nvd |
CVE-2026-75000 |
|
2026-08-17 |
| medium |
CVE-2026-74999 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subj… |
vulnerability |
nvd |
CVE-2026-74999 |
|
2026-08-17 |
| high |
CVE-2026-74998 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style S… |
vulnerability |
nvd |
CVE-2026-74998 |
|
2026-08-17 |
| high |
CVE-2026-74997 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk pl… |
vulnerability |
nvd |
CVE-2026-74997 |
rce |
2026-08-17 |
| low |
CVE-2026-70412 — Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a… |
vulnerability |
nvd |
CVE-2026-70412 |
|
2026-08-17 |
| unknown |
CVE-2026-18674 — On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attribu… |
vulnerability |
nvd |
CVE-2026-18674 |
|
2026-08-17 |
| high |
CVE-2026-16467 — Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing F… |
vulnerability |
nvd |
CVE-2026-16467 |
|
2026-08-17 |
| critical |
CVE-2026-14564 — Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consul… |
vulnerability |
nvd |
CVE-2026-14564 |
|
2026-08-17 |
| critical |
CVE-2026-74843 — A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerabilit… |
vulnerability |
nvd |
CVE-2026-74843 |
|
2026-08-17 |
| unknown |
CVE-2026-40126 — OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be… |
vulnerability |
nvd |
CVE-2026-40126 |
|
2026-08-17 |
| critical |
CVE-2026-74901 — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where… |
vulnerability |
nvd |
CVE-2026-74901 |
|
2026-08-17 |
| critical |
CVE-2026-74900 — openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsula… |
vulnerability |
nvd |
CVE-2026-74900 |
|
2026-08-17 |
| critical |
CVE-2026-74899 — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecut… |
vulnerability |
nvd |
CVE-2026-74899 |
|
2026-08-17 |
| critical |
CVE-2026-74896 — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPattern… |
vulnerability |
nvd |
CVE-2026-74896 |
|
2026-08-17 |
| critical |
CVE-2026-74895 — openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isol… |
vulnerability |
nvd |
CVE-2026-74895 |
|
2026-08-17 |
| critical |
CVE-2026-74894 — openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token… |
vulnerability |
nvd |
CVE-2026-74894 |
|
2026-08-17 |