Posts of last 24 hours
В систему можно было зайти «с ноги» и запустить что угодно.
https://www.securitylab.ru/news/575577.php
A vulnerability was found in OpenWrt LuCI up to 1.2.4-3. It has been classified as problematic. This vulnerability affects unknown code of the component luci-app-adblock-fast. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-68583. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/385356
A vulnerability was found in ArcadeData ArcadeDB up to 26.7.2 and classified as critical. This affects the function getSecurity.createUser of the component JavaScript Trigger Context. Executing a manipulation can lead to improper privilege management.
The identification of this vulnerability is CVE-2026-67356. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/385355
A vulnerability has been found in FreeRDP up to 3.28.x and classified as critical. Affected by this issue is some unknown functionality of the component Audio Input Redirection. Performing a manipulation of the argument FramesPerPacket results in integer overflow.
This vulnerability was named CVE-2026-68580. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
https://vuldb.com/vuln/385354
A vulnerability, which was classified as problematic, was found in FreeRDP up to 3.28.x. Affected by this vulnerability is the function CliprdrStream_Read of the file client/Windows/wf_cliprdr.c of the component Windows Clipboard Client. Such manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2026-68579. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
https://vuldb.com/vuln/385353
A vulnerability, which was classified as critical, has been found in ArcadeData ArcadeDB up to 26.7.2. Affected is an unknown function of the component MCP HTTP Transport. This manipulation causes permission issues.
This vulnerability is handled as CVE-2026-68578. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/385352
A vulnerability classified as problematic was found in better-auth up to 1.3.9. This impacts an unknown function of the component Passkey Deletion. The manipulation results in authorization bypass.
This vulnerability is known as CVE-2025-71400. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/385351
CVE-2025-71399 | better-auth Better Auth up to 1.4.4 Router privileges management (EUVD-2025-210590)
A vulnerability classified as critical has been found in better-auth Better Auth up to 1.4.4. This affects an unknown function of the component Router. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2025-71399. It is possible to initiate the attack remotely. There is no exploit available.
https://vuldb.com/vuln/385350
A vulnerability described as problematic has been identified in go-vikunja vikunja up to 2.3.0. The impacted element is an unknown function of the file /api/v1/projects/{project}/views/{view}/tasks of the component Task Collection Endpoint. Executing a manipulation can lead to authorization bypass.
This vulnerability appears as CVE-2026-68582. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/385349
AI systems moved from experimental risk to confirmed attacker, a Cisco firewall zero-day was actively exploited in the wild, and a critical VMware authentication bypass put enterprise virtualization infrastructure at risk. Below is a roundup of the week’s most significant vulnerabilities, breaches, and security research. Critical VMware Authentication Bypass Flaws Broadcom issued advisory VMSA-2026-0006 covering […]
The post Weekly Cyber Security Newsletter– Claude Hacked 3 Companies, Cisco 0-Day, Word Copilot and VMware Flaw +20 Stories appeared first on Cyber Security News.
https://cybersecuritynews.com/cyber-security-newsletter-august/