CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 142 matching records.
AUTO-POLL // 2026-08-16 05:35 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-07-06 19:20 UTC
Vendor Research
TIER 1

Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cis…

Vulnerabilities CVE-2026-20181CVE-2026-20190
P20
2026-07-06 12:00 UTC
Vendor Research
TIER 1

Cisco Catalyst Center Arbitrary File Read Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at…

Vulnerabilities CVE-2026-20191
P5
2026-07-02 20:52 UTC
Vendor Research
TIER 1

ClamAV Vulnerabilities Affecting Cisco Products: July 2026

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Notes: The Security Impact Rating (SIR) for these vulnerabilities is High for Windows-based platforms only because those platforms run the ClamAV…

LinuxMicrosoftVulnerabilities CVE-2026-20213CVE-2026-20214CVE-2026-20215CVE-2026-20216CVE-2026-20217CVE-2026-20243CVE-2026-20244
P5
2026-07-01 16:01 UTC
Vendor Research
TIER 1

Cisco Advance Notification for Publication of July 1, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

On July 1, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE-ID Security Impact Rating CVSS Base Score Cisco Catalyst Center Arbitrary File Read Vulnerability CVE-2026-20191 High 7.5 ClamAV Vulnerabilities Affecting Cisco Products: July 2026 CVE-2026-20216CVE-2026-20213CVE-2026-20214CVE-2026-20215CVE-2026-20217CVE-2026-20243CVE-2026-20244 High 7.5 To fully remediate the vulnerabilities that were disclosed on July 1, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the…

DFIRVulnerabilities CVE-2026-20191
P5
2026-07-01 15:10 UTC
Vendor Research
TIER 1

Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevat…

Vulnerabilities CVE-2026-20230
P5
2026-06-25 14:31 UTC
Vendor Research
TIER 1

Cisco Finesse Remote File Inclusion Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of the affected device could exploit this vulnerability by persuading a user to click a crafted link that contains the affected device address. A successful exploit could allow the attacker to conduct b…

Vulnerabilities CVE-2026-20175
P5
2026-06-24 11:00 UTC
Vendor Research
TIER 2

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data. Throughout the intrusion, to maintain operational security and avoid det…

Initial AccessMicrosoftNetwork SecurityThreat ActorsVulnerabilities CVE-2026-20127CVE-2026-20182CVE-2026-20245
P40
2026-06-22 15:04 UTC
Vendor Research
TIER 1

Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerabilities

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful expl…

Vulnerabilities CVE-2026-20055CVE-2026-20109
P5
2026-06-18 17:59 UTC
Vendor Research
TIER 2

Build your own vulnerability harness

Cloudflare Security · Dan Jones · indexed 2026-08-16 02:02 UTC

We break down the technical architecture behind our multi-stage vulnerability discovery harness and automated triage loop. Learn how we manage state controls, squash false positives through adversarial review, and route around LLM context limits.

AI SecurityVulnerabilities
P0
2026-06-18 05:23 UTC
Vendor Research
TIER 2

Oracle June 2026 Critical Security Patch Update Addresses 243 CVEs (CVE-2026-35273)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

Oracle addresses 243 CVEs in its June 2026 Critical Security Patch Update with 245 patches, including 122 critical updates.Key TakeawaysThe June 2026 Critical Security Patch Update (CSPU) contains fixes for 243 unique CVEs in 245 security updates122 issues (49.8% of all patches) were assigned a critical severity ratingOracle Fusion Middleware received the highest number of patches at 106, accounting for 43.3% of all patchesBackgroundOn June 16, Oracle released its Critical Security Patch Update (CSPU) for June 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle tha…

Threat IntelligenceVulnerabilities CVE-2026-35273
P65
2026-06-17 16:09 UTC
Vendor Research
TIER 1

iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution

Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC

iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution A .NET deserialization vulnerability exists in iba ibaPDA and ibaDatCoordinator. An unauthenticated remote attacker can exploit it to achieve remote code execution.The ibaPDA Server service (ibaPDAService.exe) listens on TCP port 9170 by default. Clients communicate with the server using GenuineChannels, which uses .NET Remoting. Messages sent to the server are deserialized using BinaryFormatter. GenuineChannels uses Zyan.SafeDeserializationHelpers.dll to filter BinaryFormatter payloads, but the filter only blocks a sma…

Vulnerabilities
P15
2026-06-17 16:00 UTC
Vendor Research
TIER 1

Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using certain commands at the CLI. A successful exploit could allow the attacker to elevate privileges to root. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following lin…

Vulnerabilities CVE-2026-20246
P15
2026-06-17 16:00 UTC
Vendor Research
TIER 1

Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to insufficient input validation in the configuration template engine of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system in limited areas of the file system. This vulnerability affects …

Vulnerabilities CVE-2026-20220
P5
2026-06-17 16:00 UTC
Vendor Research
TIER 1

Cisco Webex App Open Redirect Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to improper input validation of URL parameters in an HTTP request. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to click a crafted URL. A successful exploit could have allowed the attacker to redirect a user to a malicious website. Cisco…

Vulnerabilities CVE-2026-20178
P5
2026-06-16 17:39 UTC
Vendor Research
TIER 1

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could al…

Vulnerabilities CVE-2026-20127
P15
2026-06-16 17:39 UTC
Vendor Research
TIER 1

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The Indicators of Compromise section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN v…

Vulnerabilities CVE-2026-20182
P15
2026-06-15 22:00 UTC
Vendor Research
TIER 1

Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This f…

Vulnerabilities CVE-2026-20262
P5
2026-06-11 14:00 UTC
Vendor Research
TIER 2

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity p…

AppleCloud SecurityData BreachesLinuxMicrosoftThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-35273
P45
2026-06-10 11:55 UTC
Government
TIER 1

2026-008: Critical vulnerabilities in Ivanti Sentry

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.

Cloud SecurityVulnerabilities
P15
2026-06-10 06:47 UTC
Government
TIER 1

2026-007: Critical Vulnerability in Windows Netlogon

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors. It is strongly recommended updating affected Windows servers as soon as possible.

MicrosoftThreat ActorsVulnerabilities
P10
2026-06-09 14:19 UTC
Vendor Research
TIER 2

Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

32Critical166Important0Moderate0LowMicrosoft addresses 198 CVEs in the largest Patch Tuesday release, including three zero-days.Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs that were already addressed by Microsoft via servicing and do not require additional customer action to resolve as well as 2 CVEs that were disclosed by other CNAs (CVE-2025-10263 and CVE-2026-8863). This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CV…

Cloud SecurityLinuxMicrosoftMobile SecurityVulnerabilities CVE-2025-10263CVE-2026-33825CVE-2026-41091CVE-2026-42909CVE-2026-42913CVE-2026-42985CVE-2026-42992CVE-2026-42993CVE-2026-44799CVE-2026-44801CVE-2026-47289CVE-2026-47653CVE-2026-47654CVE-2026-48563CVE-2026-49160CVE-2026-50507CVE-2026-8863
P95
2026-06-09 06:00 UTC
Vendor Research
TIER 2

Defend against frontier cyber models: Cloudflare's architecture as customer zero

Cloudflare Security · Rohit Chenna Reddy · indexed 2026-08-16 02:02 UTC

In our post about Project Glasswing, we made the argument that the architecture around a vulnerability matters more than the speed of the patch. Here we walk through what that architecture looks like, the threats it defends against, and how we run it ourselves as Cloudflare's customer zero.

Vulnerabilities
P0
2026-06-03 16:00 UTC
Vendor Research
TIER 1

Cisco Webex Meetings Cross-Site Scripting Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed. This vulnerability existed because of insufficient validation of user input. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to follow a malicious link. A successful exploit could have allowed the attacker to execute arbitrary script code in the brow…

Vulnerabilities CVE-2026-20233
P5
2026-06-02 18:38 UTC
Vendor Research
TIER 1

SolarWinds Web Help Desk Unauthenticated File Upload

Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC

SolarWinds Web Help Desk Unauthenticated File Upload SolarWinds Web Help Desk contains an unauthenticated file upload vulnerability. A remote attacker can submit arbitrary file uploads to the affected host without authentication, allowing the attacker to consume all available disk space on the volume hosting the application and induce a denial-of-service condition. Ben Smith Tue, 06/02/2026 - 14:38

Vulnerabilities
P0
2026-05-29 14:19 UTC
Vendor Research
TIER 1

Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse

Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC

Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered a 1-click open redirection technique in Amazon Cognito that can be triggered by abusing the OAuth error-handling mechanism. The vulnerability stems from AWS's OAuth implementation validation sequence: if validation fails due to an unsupported scope, mismatched PKCE parameters, or an unsupported response type, the error handling processes the failure and automatically issues an HTTP redirect to an attacker-controlled redirect_uri. Because the identity platform evaluates th…

AppleCloud SecurityMalwarePhishingSecurity ResearchVulnerabilities
P0
2026-05-25 14:00 UTC
Vendor Research
TIER 2

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform, with the goal of infecting users visiting the site. This vulnerability stems from the use of identi…

AppleDFIRMalwareMicrosoftThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-5426
P55
2026-05-20 16:00 UTC
Vendor Research
TIER 1

Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect parsing of a transitive BGP attribute. An attacker could exploit this vulnerability by sending a crafted BGP update through an established BGP peer session. If the update propagates to an affected device, it could cause the device to drop the BGP session and …

Network SecurityVulnerabilities CVE-2026-20171
P5
2026-05-20 16:00 UTC
Vendor Research
TIER 1

Cisco Secure Workload Unauthorized API Access Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin …

Vulnerabilities CVE-2026-20223
P5
2026-05-20 16:00 UTC
Vendor Research
TIER 1

Cisco ThousandEyes Virtual Appliance Authenticated Remote Code Execution Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could exploit this vulnerability by uploading a crafted certificate to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrativ…

Vulnerabilities CVE-2026-20199
P20
2026-05-20 16:00 UTC
Vendor Research
TIER 1

Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEyes Enterprise Agent, and no customer action is needed. This vulnerability was due to insufficient input validation of command arguments that are supplied by the user. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by authenticating to the ThousandEy…

Credential ExposureVulnerabilities CVE-2026-20206
P5
2345