{"date_iso":"2026-08-26","date_human":"Wednesday, August 26, 2026","generated_utc":"2026-08-26 13:58 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations","link":"https://cybersecuritynews.com/mirage2fa-phishing-kit-bypasses-mfa-to-hijack-microsoft-365-sessions-targeting-3500-organizations/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","Malwarebytes Labs","Rapid7 Blog","The Hacker News","Zero Day Initiative"],"coverage":7,"cve_ids":["CVE-2026-63520"],"summary":"Researchers tie the LinX Coders phishing-as-a-service toolkit to 9,332 compromise events across 94 countries, with 63.7% of victims in the United States and stolen session cookies accounting for more than half of all\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjU-eNiofA16lfgGSpoEjiiAphYNAE2wceLqfErJo2meC8spjY5wHfY2H6NUYchm17cpeZDVNu77yEOO8nTVdGmNX6-lnwH9JYAD_BcFWZw-bNICrP4WNeNY0lEsMjl1hO4WPTeZ4FaNiWtyW_yqgk5RZbaDjQbeshKs-gBcFEXopOEZ3RuJJn1c15hcdg/s1600/Insignary%20Launches%20Clarity%20On-Demand%20SBOMs,%20No%20Annual%20Commitment%20Required%20Toronto,%20Canada,%20July%2015th,%202026,%20CyberNewswire%20Enterprise-grade%20binary%20software%20verification%20for%20one%20proj%20-%202026-08-26T124424.61.webp","description":"Researchers tie the LinX Coders phishing-as-a-service toolkit to 9,332 compromise events across 94 countries, with 63.7% of victims in the United States and stolen session cookies accounting for more than half of all outcomes. A phishing-as-a-service (PhaaS) toolkit tracked as Mirage2FA has been linked to the potential compromise of 4,532 Microsoft 365 accounts in a campaign that targeted 3,518 organizations, according to new research published by threat intelligence analysts ShiFu and raptur3 at ANY.RUN. The kit does not drop malware. Instead, it uses browser-executed HTML, XHTML, and SVG\u2026","related":[{"title":"Microsoft tests new privacy controls for Windows 11 desktop apps","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-tests-new-privacy-controls-for-windows-11-desktop-apps/","source":"Bleeping Computer","date_rel":"24m ago"},{"title":"Microsoft PowerToys adds Alt+Tab-style switching for an app's windows","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-powertoys-adds-alt-plustab-style-switching-for-an-apps-windows/","source":"Bleeping Computer","date_rel":"22h ago"},{"title":"Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows","link":"https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html","source":"The Hacker News","date_rel":"25 Aug"},{"title":"Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)","link":"https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520","source":"Rapid7 Blog","date_rel":"24 Aug"},{"title":"Fake Microsoft security scans trick victims into uninstalling their antivirus","link":"https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus","source":"Malwarebytes Labs","date_rel":"24 Aug"},{"title":"Doubloon Dredger Abuses Notion to Harvest Authentication Tokens","link":"https://www.infosecurity-magazine.com/news/doubloon-dredger-notion/","source":"Infosecurity Magazine","date_rel":"24 Aug"}]},{"title":"SonicWall NetExtender Vulnerabilities Allow an Attacker to Write Arbitrary Files as Root","link":"https://cybersecuritynews.com/sonicwall-netextender-vulnerabilities/","reason":"Linux","category":"News","sources":["Cyber Security News","Infosecurity Magazine","SecurityWeek","The Hacker News","Zero Day Initiative"],"coverage":5,"cve_ids":[],"summary":"SonicWall has disclosed two security vulnerabilities in its NetExtender Linux client, including a critical path traversal flaw that could allow an attacker to write arbitrary files with root privileges. The issues\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/SonicWall-NetExtender-vulnerabilities-allows-an-attacker-to-write-arbitrary-file-as-root.webp","description":"SonicWall has disclosed two security vulnerabilities in its NetExtender Linux client, including a critical path traversal flaw that could allow an attacker to write arbitrary files with root privileges. The issues affect NetExtender Linux Client versions 10.3.5 and earlier; the fixed release is version 10.3.6 and later. Tracked as CVE-2026-66152, the more severe vulnerability received a CVSS score of 8.8. SonicWall said the issue lies in how the Linux client handles an OPSWAT tarball. A remote attacker could exploit path traversal sequences to place files outside the intended extraction\u2026","related":[{"title":"Linux Foundation Introduces TRACE Standard for AI Runtime Evidence","link":"https://www.infosecurity-magazine.com/news/linux-foundation-trace-standard-ai/","source":"Infosecurity Magazine","date_rel":"3h ago"},{"title":"Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation","link":"https://www.securityweek.com/linux-foundation-to-govern-trace-an-open-standard-for-ai-runtime-attestation/","source":"SecurityWeek","date_rel":"20h ago"},{"title":"UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit","link":"https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html","source":"The Hacker News","date_rel":"24 Aug"},{"title":"ZDI-26-609: Linux Kernel Net Scheduler Packet Classifier Use-After-Free Local Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-609/","source":"Zero Day Initiative","date_rel":"24 Aug"},{"title":"ZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-608/","source":"Zero Day Initiative","date_rel":"24 Aug"}]},{"title":"Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware","link":"https://cybersecuritynews.com/hackers-use-fake-claude/","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security","The Hacker News","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-59127","CVE-2026-62728","CVE-2026-62747"],"summary":"Cybercriminals are using a counterfeit Claude desktop application to compromise Windows systems, disable key security checks, and install remote-access malware. The campaign turns a familiar AI software search into a\u2026","source":"Cyber Security News","date_rel":"15m ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Use-Fake-Claude-Desktop-App-to-Disable-Defender-and-Install-Remote-Access-Malware.webp","description":"Cybercriminals are using a counterfeit Claude desktop application to compromise Windows systems, disable key security checks, and install remote-access malware. The campaign turns a familiar AI software search into a route for credential theft and long-term access. It also shows how trusted-looking download pages can make a dangerous file appear routine. For organizations, the campaign creates risk beyond one endpoint because stolen credentials may open the door to email, cloud services, and internal systems. The attack begins with malicious search advertisements that steer victims toward\u2026","related":[{"title":"Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor","link":"https://cybersecuritynews.com/iran-linked-hackers-abuse-developer-tool/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode","link":"https://thehackernews.com/2026/08/newly-sleepwalker-backdoor-waits-for.html","source":"The Hacker News","date_rel":"5h ago"},{"title":"CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62747","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62728","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-59127 Windows Installer Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59127","source":"Microsoft Security","date_rel":"22h ago"},{"title":"You don't want this Sleepwalker backdoor on your Windows machine","link":"https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/5292021","source":"The Register Security","date_rel":"24 Aug"}]},{"title":"WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android","link":"https://thehackernews.com/2026/08/whatsapp-adds-multiple-passkeys-for.html","reason":"Android","category":"News","sources":["Dark Reading","Malwarebytes Labs","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjqyjfLJEnp8xcmcz9iVBOKykdcxx36J8KgONSwImU9YSYuvWD_uzKDaGkJre9D_8P1XLdE8vPHqNyBUKOvjYPLJj_oZ1T-pfUxdOm-bZTtaz4LC2eVcuFloJTtEE7IWVnOaVJIEtFUoPKfOn9xeBASQG7e7X2-wA7P-hwGIzqP7G_-Ot2BOpj-OSO0tUBh/s1600/whatsapp.jpg","description":"Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,","related":[{"title":"Beware of fake Indeed interview apps used to install spyware","link":"https://www.malwarebytes.com/blog/scams/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware","source":"Malwarebytes Labs","date_rel":"4h ago"},{"title":"WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update","link":"https://www.securityweek.com/whatsapp-adds-multiple-passkeys-and-stronger-2sv-in-account-security-update/","source":"SecurityWeek","date_rel":"23h ago"},{"title":"ToxicPanda Banking Trojan Matures Into Enterprise Threat","link":"https://www.darkreading.com/mobile-security/toxicpanda-banking-trojan-matures-enterprise-threat","source":"Dark Reading","date_rel":"24 Aug"},{"title":"ToxicPanda 2.0 can take over your Android phone and banking apps","link":"https://www.malwarebytes.com/blog/mobile/2026/08/toxicpanda-2-0-can-take-over-your-android-phone-and-banking-apps","source":"Malwarebytes Labs","date_rel":"24 Aug"}]},{"title":"WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks","link":"https://cybersecuritynews.com/translatepress-wordpress-plugin-vulnerability/","reason":"Wordpress","category":"News","sources":["Bleeping Computer","Cyber Security News","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-15981","CVE-2026-19632","CVE-2026-61979"],"summary":"A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected websites. The flaw, tracked as CVE-2026-19632, affects\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/WordPress-Plugin-Vulnerability-Exposes-400000-Sites-to-Account-Takeover-Attacks.webp","description":"A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected websites. The flaw, tracked as CVE-2026-19632, affects TranslatePress versions up to 3.3.1 and has been fixed in version 3.3.2. TranslatePress is a multilingual WordPress plugin with more than 400,000 active installations. Wordfence assigned the vulnerability a CVSS score of 9.8, classifying it as critical. Security researcher momopon1415 responsibly reported the issue through the Wordfence Bug Bounty Program and received a $975\u2026","related":[{"title":"WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities","link":"https://www.securityweek.com/wordpress-websites-targeted-via-miniorange-plugin-vulnerabilities/","source":"SecurityWeek","date_rel":"22h ago"},{"title":"Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access","link":"https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html","source":"The Hacker News","date_rel":"25 Aug"},{"title":"Hackers target WordPress sites in miniOrange auth bypass attacks","link":"https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/","source":"Bleeping Computer","date_rel":"24 Aug"}]},{"title":"You could've applied all 1,449 Oracle patches and still been hit by this attack","link":"https://www.theregister.com/security/2026/08/25/you-couldve-applied-all-1449-oracle-patches-and-still-been-hit-by-this-attack/5292335","reason":"Oracle","category":"News","sources":["CCCS Alerts & Advisories","CISA Alerts & Advisories","The Hacker News","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-21962"],"summary":"In late July, Oracle released a mammoth security patch dump with 1,449 patches, in a perhaps unprecedented bad day for database admins. None of them, it turns out, would have prevented the credential theft on an Oracle\u2026","source":"The Register Security","date_rel":"20h ago","thumbnail":"https://image.theregister.com/?imageId=234063&width=800","description":"In late July, Oracle released a mammoth security patch dump with 1,449 patches, in a perhaps unprecedented bad day for database admins. None of them, it turns out, would have prevented the credential theft on an Oracle database server described by security platform Huntress. \u201cEven if it had been fully patched, everything working, it still would have happened,\u201d said Craig Savage, cybersecurity lead at Oracle third-party support vendor Spinnaker Support, referring to the attack. In July, Huntress was alerted to credential theft activity, according to a post from the security company. The attack\u2026","related":[{"title":"CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw","link":"https://www.theregister.com/security/2026/08/25/cisa-slaps-its-tightest-three-day-patching-deadline-on-perfect-10-oracle-flaw/5292107","source":"The Register Security","date_rel":"25 Aug"},{"title":"Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data","link":"https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html","source":"The Hacker News","date_rel":"25 Aug"},{"title":"Oracle security advisory \u2013 January 2026 quarterly rollup (AV26-042) \u2013 Update 2","link":"https://cyber.gc.ca/en/alerts-advisories/oracle-security-advisory-january-2026-quarterly-rollup-av26-042","source":"CCCS Alerts & Advisories","date_rel":"24 Aug"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"24 Aug"}]},{"title":"Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes","link":"https://thehackernews.com/2026/08/fake-apple-support-ai-calls-target.html","reason":"Apple","category":"News","sources":["Bleeping Computer","The Hacker News","Zero Day Initiative"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZ7ibePn1YRPkAC27RIrMl_O-41pR7ieF0Mkpr8WUTkzCddWjpttUiIrXWI3CYGukgNR8eoppnOFUYjzSbEm66XiK4ttGge7-KicMnSf49N5L-wKXyf4NIzWi1Yi5JbKQXPYpmtWfZfMADrNswG9-ZfOOE9LjWwUFl7twHmvEskgU9iXPR5AGEQ4hUETo/s1600/iphone-passcode.jpg","description":"Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across","related":[{"title":"AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes","link":"https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/","source":"Bleeping Computer","date_rel":"16h ago"},{"title":"ZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-610/","source":"Zero Day Initiative","date_rel":"24 Aug"}]},{"title":"Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs","link":"https://risky.biz/RB850/","reason":"Siemens","category":"Podcast","sources":["CISA Alerts & Advisories","CISA ICS Advisories","Risky Business"],"coverage":3,"cve_ids":[],"summary":"On this week\u2019s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK\u2019s NCSC, to talk through the week\u2019s news, including: Iranian hackers take down a small-scale power\u2026","source":"Risky Business","date_rel":"10h ago","thumbnail":"","description":"On this week\u2019s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK\u2019s NCSC, to talk through the week\u2019s news, including: Iranian hackers take down a small-scale power generator in the UK Siemens PLCs in critical US sectors are also being targeted\u2026 We\u2019re stumped on who could be behind that one, too. Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet Prompt injection isn\u2019t going away LLMs are deceiving us meat sacks and it\u2019s a worry Much, much more\u2026 This week\u2019s show is brought to you by Okta. VP\u2026","related":[{"title":"Siemens SIMATIC IoT2050 Advanced","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03","source":"CISA Alerts & Advisories","date_rel":"25 Aug"},{"title":"Siemens SIMATIC IoT2050 Advanced","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03","source":"CISA ICS Advisories","date_rel":"25 Aug"}]},{"title":"CISA Warns of Exploited Gitea Vulnerability","link":"https://www.securityweek.com/cisa-warns-of-exploited-gitea-vulnerability/","reason":"CVE-2026-60004","category":"News","sources":["CISA Alerts & Advisories","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2026-60004"],"summary":"CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1.","source":"SecurityWeek","date_rel":"7h ago","thumbnail":"","description":"","related":[{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"25 Aug"}]},{"title":"Crooks push Mac malware through fake OpenAI Codex ads","link":"https://www.theregister.com/security/2026/08/25/crooks-push-mac-malware-through-fake-openai-codex-ads/5291899","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Cybercrims are using fake OpenAI Codex download pages to trick Mac developers into running malware disguised as installation commands. Researchers at Cato Networks uncovered the campaign after spotting sponsored Google\u2026","source":"The Register Security","date_rel":"25 Aug","thumbnail":"https://image.theregister.com/?imageId=251976&width=800","description":"Cybercrims are using fake OpenAI Codex download pages to trick Mac developers into running malware disguised as installation commands. Researchers at Cato Networks uncovered the campaign after spotting sponsored Google search results targeting people looking to download Codex for macOS. The ads direct would-be users to a convincing-looking download page hosted on Google Sites, complete with the familiar OpenAI branding. There is, however, no Codex waiting at the other end. Instead of serving up an installer, the fake site tells Mac users to open Terminal, paste in a supplied command, and run\u2026","related":[{"title":"Google security advisory (AV26-844)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-844","source":"CCCS Alerts & Advisories","date_rel":"24 Aug"},{"title":"Fake Codex Download Uses Google Sites to Deliver macOS Malware","link":"https://www.infosecurity-magazine.com/news/fake-codex-download-google-sites/","source":"Infosecurity Magazine","date_rel":"24 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-76193","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitra\u2026","cwe":"CWE-918","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76193"},{"id":"CVE-2026-76195","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An att\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76195"},{"id":"CVE-2026-76197","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An att\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76197"},{"id":"CVE-2026-79911","vendor":"TOTOLINK","product":"N600R","severity":"CRITICAL","score":10.0,"description":"A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostn\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-79911"},{"id":"CVE-2026-65083","vendor":"NVIDIA","product":"OpenShell","severity":"CRITICAL","score":9.9,"description":"NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation \u2026","cwe":"CWE-184","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65083"},{"id":"CVE-2026-65093","vendor":"NVIDIA","product":"OpenShell","severity":"CRITICAL","score":9.9,"description":"NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosur\u2026","cwe":"CWE-427","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65093"},{"id":"CVE-2026-63586","vendor":"Weidmueller Interface","product":"IE-SR-2TX-WL","severity":"CRITICAL","score":9.8,"description":"The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string exec\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":0.0052,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63586"},{"id":"CVE-2026-78568","vendor":"WordPress","product":"Total Donations","severity":"CRITICAL","score":9.8,"description":"The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  T\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.003,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78568"},{"id":"CVE-2026-78570","vendor":"WordPress","product":"Total Donations","severity":"CRITICAL","score":9.8,"description":"The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of an adminsitrator.","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78570"},{"id":"CVE-2026-49845","vendor":"Apache","product":"Apache Hive","severity":"CRITICAL","score":9.8,"description":"SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (includ\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-49845"}],"vendor_spikes":[{"vendor":"Google","count":327,"critical_count":0},{"vendor":"Adobe","count":38,"critical_count":3},{"vendor":"NVIDIA","count":28,"critical_count":2},{"vendor":"Microsoft","count":24,"critical_count":1},{"vendor":"TYPO3","count":23,"critical_count":0},{"vendor":"WordPress","count":19,"critical_count":2},{"vendor":"Unknown","count":19,"critical_count":1},{"vendor":"Drupal","count":17,"critical_count":0},{"vendor":"lin-snow","count":15,"critical_count":0},{"vendor":"AcademySoftwareFoundation","count":15,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":14,"new_cve_count":706,"has_news_data":true,"has_cve_data":true}